USN-1912-1: Linux kernel vulnerabilities
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom driver. A local user can exploit this leak to obtain sensitive information from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164) A flaw was discovered in the Linux kernel when an IPv6 socket is used to connect to an IPv4 destination. An unprivileged local user could exploit this flaw to cause a denial of service (system crash). (CVE-2013-2232) An information leak was discovered in the IPSec keysocket implementation in the Linux kernel. An local user could exploit this flaw to examine potentially sensitive information in kernel memory. (CVE-2013-2234) An information leak was discovered in the Linux kernel when reading broadcast messages from the notifypolicy interface of the IPSec keysocket. A local user could exploit this flaw to examine potentially sensitive information in kernel memory. (CVE-2013-2237) Kees Cook discovered a format string vulnerability in the Linux kernel's disk block layer. A local user with administrator privileges could exploit this flaw to gain kernel privileges. (CVE-2013-2851)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-1912-1?
USN-1912-1 has a medium severity due to the potential for information leakage from kernel memory.
How do I fix USN-1912-1?
To fix USN-1912-1, update to the patched version of the Linux kernel which is 2.6.32-50.112.
Who is affected by USN-1912-1?
Users running Ubuntu 10.04 with specific versions of the Linux kernel packages are affected by USN-1912-1.
What type of vulnerability is USN-1912-1?
USN-1912-1 is an information leak vulnerability found in the Linux kernel's CD-ROM driver.
Can an attacker remotely exploit USN-1912-1?
No, USN-1912-1 requires local access for an attacker to exploit the information leak.