USN-2415-1: Linux kernel vulnerability
Don Bailey discovered a flaw in the LZO decompress algorithm used by the Linux kernel. An attacker could exploit this flaw to cause a denial of service (memory corruption or OOPS). (CVE-2014-4608) Andy Lutomirski discovered that the Linux kernel was not checking the CAPSYSADMIN when remounting filesystems to read-only. A local user could exploit this flaw to cause a denial of service (loss of writability). (CVE-2014-7975)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-2415-1?
USN-2415-1 is classified as a denial of service vulnerability that can lead to memory corruption or system crashes.
How do I fix USN-2415-1?
To fix USN-2415-1, update to the linux-image package version 2.6.32-68.135 or newer.
What systems are affected by USN-2415-1?
USN-2415-1 affects Ubuntu 10.04 systems running specific versions of the linux-image package.
What is the cause of the USN-2415-1 vulnerability?
The USN-2415-1 vulnerability is caused by flaws in the LZO decompress algorithm used in the Linux kernel.
Can USN-2415-1 lead to remote code execution?
No, USN-2415-1 primarily leads to denial of service but does not allow for remote code execution.