USN-2637-1: Linux kernel vulnerabilities
Xiong Zhou discovered a bug in the way the EXT4 filesystem handles fallocate zero range functionality when the page size is greater than the block size. A local attacker could exploit this flaw to cause a denial of service (system crash). (CVE-2015-0275) Wen Xu discovered a use-after-free flaw in the Linux kernel's ipv4 ping support. A local user could exploit this flaw to cause a denial of service (system crash) or gain administrative privileges on the system. (CVE-2015-3636)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-2637-1?
USN-2637-1 has a high severity level due to the potential for denial of service leading to system crashes.
How do I fix USN-2637-1?
To fix USN-2637-1, update your system to the recommended linux-image package version 3.16.0-39.53 or later.
What products are affected by USN-2637-1?
USN-2637-1 affects Ubuntu 14.10 on various linux-image packages including lowlatency, generic, and powerpc.
Can USN-2637-1 be exploited remotely?
No, USN-2637-1 requires local access for exploitation and does not pose a remote attack vector.
What does USN-2637-1 address specifically?
USN-2637-1 addresses a bug in the EXT4 filesystem related to the fallocate zero range functionality.