USN-2640-1: Linux kernel vulnerability
Published Jun 15, 2015
·Updated
Philip Pettersson discovered a privilege escalation when using overlayfs mounts inside of user namespaces. A local user could exploit this flaw to gain administrative privileges on the system.
Affected Software
14 affected componentsFixes available
All of the following
ubuntu/linux-image-3.2.0-86-generic-pae<3.2.0-86.123
3.2.0-86.123
Ubuntu Ubuntu=12.04
All of the following
ubuntu/linux-image-3.2.0-86-powerpc64-smp<3.2.0-86.123
3.2.0-86.123
Ubuntu Ubuntu=12.04
All of the following
ubuntu/linux-image-3.2.0-86-generic<3.2.0-86.123
3.2.0-86.123
Ubuntu Ubuntu=12.04
All of the following
ubuntu/linux-image-3.2.0-86-virtual<3.2.0-86.123
3.2.0-86.123
Ubuntu Ubuntu=12.04
All of the following
ubuntu/linux-image-3.2.0-86-omap<3.2.0-86.123
3.2.0-86.123
Ubuntu Ubuntu=12.04
All of the following
ubuntu/linux-image-3.2.0-86-powerpc-smp<3.2.0-86.123
3.2.0-86.123
Ubuntu Ubuntu=12.04
All of the following
ubuntu/linux-image-3.2.0-86-highbank<3.2.0-86.123
3.2.0-86.123
Ubuntu Ubuntu=12.04
Event History
Jun 15, 2015
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-2640-1?
The severity of USN-2640-1 is classified as critical due to the potential for privilege escalation.
2
How do I fix USN-2640-1?
To fix USN-2640-1, update the affected packages to version 3.2.0-86.123 or later.
3
Which systems are affected by USN-2640-1?
USN-2640-1 affects Ubuntu 12.04 systems with specific linux-image packages installed.
4
Who discovered the vulnerability in USN-2640-1?
The vulnerability in USN-2640-1 was discovered by Philip Pettersson.
5
What type of vulnerability is USN-2640-1?
USN-2640-1 is a privilege escalation vulnerability related to overlayfs mounts inside user namespaces.