USN-2374-1: Linux kernel vulnerabilities
Ben Hawkes reported some off by one errors for report descriptors in the Linux kernel's HID stack. A physically proximate attacker could exploit these flaws to cause a denial of service (out-of-bounds write) via a specially crafted device. (CVE-2014-3184) Several bounds check flaws allowing for buffer overflows were discovered in the Linux kernel's Whiteheat USB serial driver. A physically proximate attacker could exploit these flaws to cause a denial of service (system crash) via a specially crafted device. (CVE-2014-3185) A flaw was discovered in the Linux kernel's UDF filesystem (used on some CD-ROMs and DVDs) when processing indirect ICBs. An attacker who can cause CD, DVD or image file with a specially crafted inode to be mounted can cause a denial of service (infinite loop or stack consumption). (CVE-2014-6410)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-2374-1?
USN-2374-1 addresses critical off-by-one errors in the Linux kernel's HID stack that can lead to denial of service.
How do I fix USN-2374-1?
To fix USN-2374-1, upgrade the affected packages to the recommended version 2.6.32-67.134 or later.
What systems are affected by USN-2374-1?
USN-2374-1 affects Ubuntu 10.04 systems using specific versions of the linux-image packages.
What type of attack can USN-2374-1 be exploited for?
USN-2374-1 can be exploited by physically proximate attackers to execute out-of-bounds writes, causing denial of service.
What are the consequences of not addressing USN-2374-1?
Failure to address USN-2374-1 may leave your system vulnerable to crashes or attacks that compromise stability.