First published: Fri Nov 08 2013(Updated: )
A denial of service flaw was discovered in the Btrfs file system in the Linux kernel. A local user could cause a denial of service by creating a large number of files with names that have the same CRC32 hash value. (CVE-2012-5374) A denial of service flaw was discovered in the Btrfs file system in the Linux kernel. A local user could cause a denial of service (prevent file creation) for a victim, by creating a file with a specific CRC32C hash value in a directory important to the victim. (CVE-2012-5375) Dan Carpenter discovered an information leak in the HP Smart Array and Compaq SMART2 disk-array driver in the Linux kernel. A local user could exploit this flaw to obtain sensitive information from kernel memory. (CVE-2013-2147)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/linux-image-3.2.0-56-generic-pae | <3.2.0-56.86 | 3.2.0-56.86 |
Ubuntu 22.04 LTS | =12.04 | |
All of | ||
ubuntu/linux-image-3.2.0-56-omap | <3.2.0-56.86 | 3.2.0-56.86 |
Ubuntu 22.04 LTS | =12.04 | |
All of | ||
ubuntu/linux-image-3.2.0-56-powerpc-smp | <3.2.0-56.86 | 3.2.0-56.86 |
Ubuntu 22.04 LTS | =12.04 | |
All of | ||
ubuntu/linux-image-3.2.0-56-powerpc64-smp | <3.2.0-56.86 | 3.2.0-56.86 |
Ubuntu 22.04 LTS | =12.04 | |
All of | ||
ubuntu/linux-image-3.2.0-56-generic | <3.2.0-56.86 | 3.2.0-56.86 |
Ubuntu 22.04 LTS | =12.04 | |
All of | ||
ubuntu/linux-image-3.2.0-56-highbank | <3.2.0-56.86 | 3.2.0-56.86 |
Ubuntu 22.04 LTS | =12.04 | |
All of | ||
ubuntu/linux-image-3.2.0-56-virtual | <3.2.0-56.86 | 3.2.0-56.86 |
Ubuntu 22.04 LTS | =12.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-2017-1 is classified as a denial of service vulnerability affecting the Btrfs file system in the Linux kernel.
To fix USN-2017-1, update your Linux kernel to version 3.2.0-56.86 or higher.
USN-2017-1 affects Ubuntu 12.04 systems running the Linux kernel packages such as linux-image-3.2.0-56-generic.
No, USN-2017-1 is a local denial of service vulnerability, meaning only local users can exploit it.
The root cause of USN-2017-1 is a flaw in the Btrfs file system that allows local users to create a large number of files with duplicate CRC32 hash values, leading to denial of service.