USN-2642-1: Linux kernel (Trusty HWE) vulnerability
Published Jun 15, 2015
·Updated
Philip Pettersson discovered a privilege escalation when using overlayfs mounts inside of user namespaces. A local user could exploit this flaw to gain administrative privileges on the system.
Affected Software
4 affected componentsFixes available
All of the following
ubuntu/linux-image-3.13.0-55-generic-lpae<3.13.0-55.92~precise1
3.13.0-55.92~precise1
Ubuntu Ubuntu=12.04
All of the following
ubuntu/linux-image-3.13.0-55-generic<3.13.0-55.92~precise1
3.13.0-55.92~precise1
Ubuntu Ubuntu=12.04
Event History
Jun 15, 2015
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-2642-1?
USN-2642-1 has a high severity level due to the potential for privilege escalation.
2
How do I fix USN-2642-1?
To fix USN-2642-1, update your system to the linux-image-3.13.0-55.92~precise1 package or later.
3
Who discovered the vulnerability in USN-2642-1?
The vulnerability in USN-2642-1 was discovered by Philip Pettersson.
4
What can a local user exploit in USN-2642-1?
A local user can exploit USN-2642-1 to gain administrative privileges through overlayfs mounts inside user namespaces.
5
Which versions of Ubuntu are affected by USN-2642-1?
USN-2642-1 affects Ubuntu 12.04 for specific packages such as linux-image-3.13.0-55-generic-lpae and linux-image-3.13.0-55-generic.