First published: Thu Feb 26 2015(Updated: )
A race condition was discovered in the Linux kernel's key ring. A local user could cause a denial of service (memory corruption or panic) or possibly have unspecified impact via the keyctl commands. (CVE-2014-9529) A memory leak was discovered in the ISO 9660 CDROM file system when parsing rock ridge ER records. A local user could exploit this flaw to obtain sensitive information from kernel memory via a crafted iso9660 image. (CVE-2014-9584)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/linux-image-2.6.32-376-ec2 | <2.6.32-376.93 | 2.6.32-376.93 |
Ubuntu gir1.2-packagekitglib-1.0 | =10.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-2512-1 ranges from a denial of service to potential memory corruption or panic.
To fix USN-2512-1, upgrade your system to linux-image-2.6.32-376-ec2 version 2.6.32-376.93 or later.
USN-2512-1 affects Ubuntu 10.04 running the specified kernel version.
USN-2512-1 addresses a race condition in the Linux kernel's key ring and a memory leak in the ISO 9660 CDROM file system.
Yes, the vulnerabilities in USN-2512-1 could lead to denial of service or other unspecified impacts if exploited.