USN-2115-1: Linux kernel (OMAP4) vulnerabilities
Vasily Kulikov reported a flaw in the Linux kernel's implementation of ptrace. An unprivileged local user could exploit this flaw to obtain sensitive information from kernel memory. (CVE-2013-2929) A flaw in the handling of memory regions of the kernel virtual machine (KVM) subsystem was discovered. A local user with the ability to assign a device could exploit this flaw to cause a denial of service (memory consumption). (CVE-2013-4592) Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's debugfs filesystem. An administrative local user could exploit this flaw to cause a denial of service (OOPS). (CVE-2013-6378) Nico Golde and Fabian Yamaguchi reported a flaw in the driver for Adaptec AACRAID scsi raid devices in the Linux kernel. A local user could use this flaw to cause a denial of service or possibly other unspecified impact. (CVE-2013-6380)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-2115-1?
The severity of USN-2115-1 is rated as important due to the potential for an unprivileged user to access sensitive kernel memory.
How do I fix USN-2115-1?
To fix USN-2115-1, users should upgrade to the patched version of the linux-image-3.5.0-238-omap4 package.
Which versions of Ubuntu are affected by USN-2115-1?
USN-2115-1 affects Ubuntu 12.10 with the vulnerable kernel version prior to 3.5.0-238.54.
Who reported the vulnerability associated with USN-2115-1?
The vulnerability associated with USN-2115-1 was reported by Vasily Kulikov.
What type of vulnerability is described in USN-2115-1?
USN-2115-1 describes a local privilege escalation vulnerability in the Linux kernel's ptrace implementation.