USN-2583-1: Linux kernel vulnerability
Published Apr 30, 2015
·Updated
A race condition between chown() and execve() was discovered in the Linux kernel. A local attacker could exploit this race by using chown on a setuid-user-binary to gain administrative privileges.
Affected Software
28 affected componentsFixes available
All of the following
ubuntu/linux-image-2.6.32-74-powerpc<2.6.32-74.142
2.6.32-74.142
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-2.6.32-74-386<2.6.32-74.142
2.6.32-74.142
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-2.6.32-74-sparc64<2.6.32-74.142
2.6.32-74.142
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-2.6.32-74-generic-pae<2.6.32-74.142
2.6.32-74.142
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-2.6.32-74-preempt<2.6.32-74.142
2.6.32-74.142
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-2.6.32-74-lpia<2.6.32-74.142
2.6.32-74.142
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-2.6.32-74-sparc64-smp<2.6.32-74.142
2.6.32-74.142
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-2.6.32-74-powerpc64-smp<2.6.32-74.142
2.6.32-74.142
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-2.6.32-74-versatile<2.6.32-74.142
2.6.32-74.142
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-2.6.32-74-generic<2.6.32-74.142
2.6.32-74.142
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-2.6.32-74-ia64<2.6.32-74.142
2.6.32-74.142
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-2.6.32-74-server<2.6.32-74.142
2.6.32-74.142
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-2.6.32-74-powerpc-smp<2.6.32-74.142
2.6.32-74.142
Ubuntu Ubuntu=10.04
All of the following
ubuntu/linux-image-2.6.32-74-virtual<2.6.32-74.142
2.6.32-74.142
Ubuntu Ubuntu=10.04
Event History
Apr 30, 2015
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-2583-1?
USN-2583-1 has a high severity due to the potential for local attackers to gain administrative privileges.
2
How do I fix USN-2583-1?
To fix USN-2583-1, you should upgrade to the linux-image package version 2.6.32-74.142 or later.
3
Which systems are affected by USN-2583-1?
USN-2583-1 affects Ubuntu 10.04 systems running specific linux-image packages.
4
What does the vulnerability in USN-2583-1 allow an attacker to do?
The vulnerability allows a local attacker to exploit a race condition to gain administrative privileges.
5
Is there a workaround for USN-2583-1?
There is no specific workaround; the recommended action is to apply the security update.