First published: Wed Jun 10 2015(Updated: )
Xiong Zhou discovered a bug in the way the EXT4 filesystem handles fallocate zero range functionality when the page size is greater than the block size. A local attacker could exploit this flaw to cause a denial of service (system crash). (CVE-2015-0275) Wen Xu discovered a use-after-free flaw in the Linux kernel's ipv4 ping support. A local user could exploit this flaw to cause a denial of service (system crash) or gain administrative privileges on the system. (CVE-2015-3636) A memory corruption flaw was discovered in the Linux kernel's scsi subsystem. A local attacker could potentially exploit this flaw to cause a denial of service (system crash). (CVE-2015-4036)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/linux-image-3.19.0-20-powerpc-smp | <3.19.0-20.20 | 3.19.0-20.20 |
Ubuntu gir1.2-packagekitglib-1.0 | =15.04 | |
All of | ||
ubuntu/linux-image-3.19.0-20-powerpc-e500mc | <3.19.0-20.20 | 3.19.0-20.20 |
Ubuntu gir1.2-packagekitglib-1.0 | =15.04 | |
All of | ||
ubuntu/linux-image-3.19.0-20-generic-lpae | <3.19.0-20.20 | 3.19.0-20.20 |
Ubuntu gir1.2-packagekitglib-1.0 | =15.04 | |
All of | ||
ubuntu/linux-image-3.19.0-20-generic | <3.19.0-20.20 | 3.19.0-20.20 |
Ubuntu gir1.2-packagekitglib-1.0 | =15.04 | |
All of | ||
ubuntu/linux-image-3.19.0-20-powerpc64-smp | <3.19.0-20.20 | 3.19.0-20.20 |
Ubuntu gir1.2-packagekitglib-1.0 | =15.04 | |
All of | ||
ubuntu/linux-image-3.19.0-20-lowlatency | <3.19.0-20.20 | 3.19.0-20.20 |
Ubuntu gir1.2-packagekitglib-1.0 | =15.04 | |
All of | ||
ubuntu/linux-image-3.19.0-20-powerpc64-emb | <3.19.0-20.20 | 3.19.0-20.20 |
Ubuntu gir1.2-packagekitglib-1.0 | =15.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-2638-1 is significant as it can lead to denial of service through a system crash.
To fix USN-2638-1, you should upgrade to the patched version of Linux kernel 3.19.0-20.20.
USN-2638-1 affects Ubuntu 15.04 with specific Linux image packages.
CVE-2015-0275 can be exploited by a local attacker to cause a denial of service.
No, the vulnerability in USN-2638-1 requires local access for exploitation.