USN-2584-1: Linux kernel (EC2) vulnerability
Published Apr 30, 2015
·Updated
A race condition between chown() and execve() was discovered in the Linux kernel. A local attacker could exploit this race by using chown on a setuid-user-binary to gain administrative privileges.
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/linux-image-2.6.32-377-ec2<2.6.32-377.94
2.6.32-377.94
Ubuntu Ubuntu=10.04
Event History
Apr 30, 2015
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-2584-1?
The severity of USN-2584-1 is critical due to the potential for local attackers to gain administrative privileges.
2
How do I fix USN-2584-1?
To fix USN-2584-1, update the Linux kernel to version 2.6.32-377.94 or later.
3
What causes the vulnerability in USN-2584-1?
USN-2584-1 is caused by a race condition between the chown() and execve() functions in the Linux kernel.
4
Who is affected by USN-2584-1?
USN-2584-1 affects users of Ubuntu 10.04 with the linux-image-2.6.32-377-ec2 package.
5
Can USN-2584-1 be exploited remotely?
No, USN-2584-1 can only be exploited locally by an attacker with access to the system.