USN-2601-1: Linux kernel vulnerability
Published May 5, 2015
·Updated
A race condition between chown() and execve() was discovered in the Linux kernel. A local attacker could exploit this race by using chown on a setuid-user-binary to gain administrative privileges.
Affected Software
14 affected componentsFixes available
All of the following
ubuntu/linux-image-3.19.0-16-lowlatency<3.19.0-16.16
3.19.0-16.16
Ubuntu Ubuntu=15.04
All of the following
ubuntu/linux-image-3.19.0-16-powerpc64-smp<3.19.0-16.16
3.19.0-16.16
Ubuntu Ubuntu=15.04
All of the following
ubuntu/linux-image-3.19.0-16-generic<3.19.0-16.16
3.19.0-16.16
Ubuntu Ubuntu=15.04
All of the following
ubuntu/linux-image-3.19.0-16-powerpc-smp<3.19.0-16.16
3.19.0-16.16
Ubuntu Ubuntu=15.04
All of the following
ubuntu/linux-image-3.19.0-16-powerpc-e500mc<3.19.0-16.16
3.19.0-16.16
Ubuntu Ubuntu=15.04
All of the following
ubuntu/linux-image-3.19.0-16-generic-lpae<3.19.0-16.16
3.19.0-16.16
Ubuntu Ubuntu=15.04
All of the following
ubuntu/linux-image-3.19.0-16-powerpc64-emb<3.19.0-16.16
3.19.0-16.16
Ubuntu Ubuntu=15.04
Event History
May 5, 2015
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-2601-1?
The severity of USN-2601-1 is rated as high due to the potential for a local attacker to gain administrative privileges.
2
How do I fix USN-2601-1?
To fix USN-2601-1, you must upgrade your Linux kernel to the version 3.19.0-16.16 or later.
3
Which Ubuntu versions are affected by USN-2601-1?
USN-2601-1 affects Ubuntu version 15.04.
4
What is the vulnerability related to USN-2601-1?
USN-2601-1 is related to a race condition between chown() and execve() in the Linux kernel.
5
Can USN-2601-1 be exploited remotely?
No, USN-2601-1 cannot be exploited remotely as it requires local access to the system.