USN-1996-1: Linux kernel vulnerability
Published Oct 22, 2013
·Updated
Dan Carpenter discovered an information leak in the HP Smart Array and Compaq SMART2 disk-array driver in the Linux kernel. A local user could exploit this flaw to obtain sensitive information from kernel memory.
Affected Software
10 affected componentsFixes available
All of the following
ubuntu/linux-image-3.5.0-42-powerpc64-smp<3.5.0-42.65
3.5.0-42.65
Ubuntu Ubuntu=12.10
All of the following
ubuntu/linux-image-3.5.0-42-highbank<3.5.0-42.65
3.5.0-42.65
Ubuntu Ubuntu=12.10
All of the following
ubuntu/linux-image-3.5.0-42-omap<3.5.0-42.65
3.5.0-42.65
Ubuntu Ubuntu=12.10
All of the following
ubuntu/linux-image-3.5.0-42-powerpc-smp<3.5.0-42.65
3.5.0-42.65
Ubuntu Ubuntu=12.10
All of the following
ubuntu/linux-image-3.5.0-42-generic<3.5.0-42.65
3.5.0-42.65
Ubuntu Ubuntu=12.10
Event History
Oct 22, 2013
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-1996-1?
The severity of USN-1996-1 is considered to be moderate due to the potential for information leakage from kernel memory.
2
How do I fix USN-1996-1?
To fix USN-1996-1, upgrade to the patched version 3.5.0-42.65 of the affected packages for Ubuntu 12.10.
3
What causes the vulnerability in USN-1996-1?
The vulnerability in USN-1996-1 is caused by an information leak in the HP Smart Array and Compaq SMART2 disk-array driver within the Linux kernel.
4
Who discovered the vulnerability USN-1996-1?
The vulnerability USN-1996-1 was discovered by Dan Carpenter.
5
What versions of Ubuntu are affected by USN-1996-1?
USN-1996-1 affects Ubuntu 12.10 with specific kernel package versions prior to 3.5.0-42.65.