First published: Mon Jul 29 2013(Updated: )
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom driver. A local user can exploit this leak to obtain sensitive information from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164) A flaw was discovered in the Linux kernel when an IPv6 socket is used to connect to an IPv4 destination. An unprivileged local user could exploit this flaw to cause a denial of service (system crash). (CVE-2013-2232) An information leak was discovered in the IPSec key_socket implementation in the Linux kernel. An local user could exploit this flaw to examine potentially sensitive information in kernel memory. (CVE-2013-2234) An information leak was discovered in the Linux kernel when reading broadcast messages from the notify_policy interface of the IPSec key_socket. A local user could exploit this flaw to examine potentially sensitive information in kernel memory. (CVE-2013-2237) Kees Cook discovered a format string vulnerability in the Linux kernel's disk block layer. A local user with administrator privileges could exploit this flaw to gain kernel privileges. (CVE-2013-2851)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/linux-image-2.6.32-50-versatile | <2.6.32-50.112 | 2.6.32-50.112 |
Ubuntu 22.04 LTS | =10.04 | |
All of | ||
ubuntu/linux-image-2.6.32-50-sparc64-smp | <2.6.32-50.112 | 2.6.32-50.112 |
Ubuntu 22.04 LTS | =10.04 | |
All of | ||
ubuntu/linux-image-2.6.32-50-generic | <2.6.32-50.112 | 2.6.32-50.112 |
Ubuntu 22.04 LTS | =10.04 | |
All of | ||
ubuntu/linux-image-2.6.32-50-powerpc | <2.6.32-50.112 | 2.6.32-50.112 |
Ubuntu 22.04 LTS | =10.04 | |
All of | ||
ubuntu/linux-image-2.6.32-50-preempt | <2.6.32-50.112 | 2.6.32-50.112 |
Ubuntu 22.04 LTS | =10.04 | |
All of | ||
ubuntu/linux-image-2.6.32-50-generic-pae | <2.6.32-50.112 | 2.6.32-50.112 |
Ubuntu 22.04 LTS | =10.04 | |
All of | ||
ubuntu/linux-image-2.6.32-50-virtual | <2.6.32-50.112 | 2.6.32-50.112 |
Ubuntu 22.04 LTS | =10.04 | |
All of | ||
ubuntu/linux-image-2.6.32-50-386 | <2.6.32-50.112 | 2.6.32-50.112 |
Ubuntu 22.04 LTS | =10.04 | |
All of | ||
ubuntu/linux-image-2.6.32-50-lpia | <2.6.32-50.112 | 2.6.32-50.112 |
Ubuntu 22.04 LTS | =10.04 | |
All of | ||
ubuntu/linux-image-2.6.32-50-ia64 | <2.6.32-50.112 | 2.6.32-50.112 |
Ubuntu 22.04 LTS | =10.04 | |
All of | ||
ubuntu/linux-image-2.6.32-50-server | <2.6.32-50.112 | 2.6.32-50.112 |
Ubuntu 22.04 LTS | =10.04 | |
All of | ||
ubuntu/linux-image-2.6.32-50-powerpc64-smp | <2.6.32-50.112 | 2.6.32-50.112 |
Ubuntu 22.04 LTS | =10.04 | |
All of | ||
ubuntu/linux-image-2.6.32-50-powerpc-smp | <2.6.32-50.112 | 2.6.32-50.112 |
Ubuntu 22.04 LTS | =10.04 | |
All of | ||
ubuntu/linux-image-2.6.32-50-sparc64 | <2.6.32-50.112 | 2.6.32-50.112 |
Ubuntu 22.04 LTS | =10.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
USN-1912-1 has a medium severity due to the potential for information leakage from kernel memory.
To fix USN-1912-1, update to the patched version of the Linux kernel which is 2.6.32-50.112.
Users running Ubuntu 10.04 with specific versions of the Linux kernel packages are affected by USN-1912-1.
USN-1912-1 is an information leak vulnerability found in the Linux kernel's CD-ROM driver.
No, USN-1912-1 requires local access for an attacker to exploit the information leak.