USN-2264-1: Linux kernel vulnerabilities
Salva Peiró discovered an information leak in the Linux kernel's media- device driver. A local attacker could exploit this flaw to obtain sensitive information from kernel memory. (CVE-2014-1739) A bounds check error was discovered in the socket filter subsystem of the Linux kernel. A local user could exploit this flaw to cause a denial of service (system crash) via crafted BPF instructions. (CVE-2014-3144) A remainder calculation error was discovered in the socket filter subsystem of the Linux kernel. A local user could exploit this flaw to cause a denial of service (system crash) via crafted BPF instructions. (CVE-2014-3145)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-2264-1?
The severity of USN-2264-1 is classified as important due to the potential information leak from kernel memory.
How do I fix USN-2264-1?
To fix USN-2264-1, upgrade to linux-image-3.11.0-24.41 or later for the affected Ubuntu 13.10 systems.
What are the risks associated with USN-2264-1?
The risks associated with USN-2264-1 include the possibility of local attackers gaining access to sensitive kernel memory information.
Which versions of Ubuntu are impacted by USN-2264-1?
USN-2264-1 impacts Ubuntu 13.10 systems using the linux-image-3.11.0-24-generic-lpae or linux-image-3.11.0-24-generic packages.
Is there a workaround for USN-2264-1?
There is no specific workaround for USN-2264-1, so it is recommended to apply the necessary updates to mitigate the vulnerability.