USN-2116-1: Linux kernel (OMAP4) vulnerabilities
Vasily Kulikov reported a flaw in the Linux kernel's implementation of ptrace. An unprivileged local user could exploit this flaw to obtain sensitive information from kernel memory. (CVE-2013-2929) A flaw in the handling of memory regions of the kernel virtual machine (KVM) subsystem was discovered. A local user with the ability to assign a device could exploit this flaw to cause a denial of service (memory consumption). (CVE-2013-4592) Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's debugfs filesystem. An administrative local user could exploit this flaw to cause a denial of service (OOPS). (CVE-2013-6378) Nico Golde and Fabian Yamaguchi reported a flaw in the driver for Adaptec AACRAID scsi raid devices in the Linux kernel. A local user could use this flaw to cause a denial of service or possibly other unspecified impact. (CVE-2013-6380)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-2116-1?
The severity of USN-2116-1 is considered high due to the potential for unprivileged local users to access sensitive kernel memory information.
How do I fix USN-2116-1?
To fix USN-2116-1, update your system to include the linux-image-3.5.0-238.54 package for Ubuntu 13.10.
Who reported the flaw in USN-2116-1?
The flaw in USN-2116-1 was reported by Vasily Kulikov.
What components are affected by USN-2116-1?
USN-2116-1 affects the Linux kernel's implementation of ptrace within the Ubuntu operating system.
What is CVE-2013-2929 related to USN-2116-1?
CVE-2013-2929 is the identifier for the vulnerability described in USN-2116-1, which allows unprivileged users to exploit kernel memory.