USN-2528-1: Linux kernel vulnerability
It was discovered that the Linux kernel's Infiniband subsystem did not properly sanitize its input parameters while registering memory regions from userspace. A local user could exploit this flaw to cause a denial of service (system crash) or to potentially gain administrative privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-2528-1?
The severity of USN-2528-1 is high due to the potential for denial of service or privilege escalation.
How do I fix USN-2528-1?
To fix USN-2528-1, you should upgrade to the kernel version 3.13.0-46.79 or later.
What systems are affected by USN-2528-1?
USN-2528-1 affects Ubuntu 14.04 with specific kernel packages including linux-image-3.13.0-46-generic.
Can USN-2528-1 be exploited remotely?
No, USN-2528-1 requires local user access to exploit the vulnerability.
What are the potential impacts of USN-2528-1?
The potential impacts of USN-2528-1 include system crashes and the possibility for local users to gain administrative privileges.