USN-2512-1: Linux kernel (EC2) vulnerabilities
A race condition was discovered in the Linux kernel's key ring. A local user could cause a denial of service (memory corruption or panic) or possibly have unspecified impact via the keyctl commands. (CVE-2014-9529) A memory leak was discovered in the ISO 9660 CDROM file system when parsing rock ridge ER records. A local user could exploit this flaw to obtain sensitive information from kernel memory via a crafted iso9660 image. (CVE-2014-9584)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-2512-1?
The severity of USN-2512-1 ranges from a denial of service to potential memory corruption or panic.
How do I fix USN-2512-1?
To fix USN-2512-1, upgrade your system to linux-image-2.6.32-376-ec2 version 2.6.32-376.93 or later.
What systems are affected by USN-2512-1?
USN-2512-1 affects Ubuntu 10.04 running the specified kernel version.
What issues does USN-2512-1 address?
USN-2512-1 addresses a race condition in the Linux kernel's key ring and a memory leak in the ISO 9660 CDROM file system.
Can USN-2512-1 lead to security risks?
Yes, the vulnerabilities in USN-2512-1 could lead to denial of service or other unspecified impacts if exploited.