First published: Tue Feb 18 2014(Updated: )
Vasily Kulikov reported a flaw in the Linux kernel's implementation of ptrace. An unprivileged local user could exploit this flaw to obtain sensitive information from kernel memory. (CVE-2013-2929) A flaw in the handling of memory regions of the kernel virtual machine (KVM) subsystem was discovered. A local user with the ability to assign a device could exploit this flaw to cause a denial of service (memory consumption). (CVE-2013-4592) Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's debugfs filesystem. An administrative local user could exploit this flaw to cause a denial of service (OOPS). (CVE-2013-6378) Nico Golde and Fabian Yamaguchi reported a flaw in the driver for Adaptec AACRAID scsi raid devices in the Linux kernel. A local user could use this flaw to cause a denial of service or possibly other unspecified impact. (CVE-2013-6380)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/linux-image-3.5.0-46-highbank | <3.5.0-46.70 | 3.5.0-46.70 |
Ubuntu gir1.2-packagekitglib-1.0 | =12.10 | |
All of | ||
ubuntu/linux-image-3.5.0-46-omap | <3.5.0-46.70 | 3.5.0-46.70 |
Ubuntu gir1.2-packagekitglib-1.0 | =12.10 | |
All of | ||
ubuntu/linux-image-3.5.0-46-generic | <3.5.0-46.70 | 3.5.0-46.70 |
Ubuntu gir1.2-packagekitglib-1.0 | =12.10 | |
All of | ||
ubuntu/linux-image-3.5.0-46-powerpc-smp | <3.5.0-46.70 | 3.5.0-46.70 |
Ubuntu gir1.2-packagekitglib-1.0 | =12.10 | |
All of | ||
ubuntu/linux-image-3.5.0-46-powerpc64-smp | <3.5.0-46.70 | 3.5.0-46.70 |
Ubuntu gir1.2-packagekitglib-1.0 | =12.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-2114-1 is critical due to its potential to allow unprivileged local users to access sensitive kernel memory.
To fix USN-2114-1, upgrade to linux-image-3.5.0-46.70 or later on affected Ubuntu 12.10 systems.
The vulnerability USN-2114-1 was reported by Vasily Kulikov.
USN-2114-1 affects Ubuntu version 12.10 running specific kernel images including linux-image-3.5.0-46-highbank.
Due to USN-2114-1, an unprivileged local user could potentially leak sensitive information from kernel memory.