USN-2684-1: Linux kernel vulnerabilities
A flaw was discovered in the kvm (kernel virtual machine) subsystem's kvmapichasevents function. A unprivileged local user could exploit this flaw to cause a denial of service (system crash). (CVE-2015-4692) Daniel Borkmann reported a kernel crash in the Linux kernel's BPF filter JIT optimization. A local attacker could exploit this flaw to cause a denial of service (system crash). (CVE-2015-4700) A flaw was discovered in how the Linux kernel handles invalid UDP checksums. A remote attacker could exploit this flaw to cause a denial of service using a flood of UDP packets with invalid checksums. (CVE-2015-5364) A flaw was discovered in how the Linux kernel handles invalid UDP checksums. A remote attacker can cause a denial of service against applications that use epoll by injecting a single packet with an invalid checksum. (CVE-2015-5366)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-2684-1?
USN-2684-1 has been classified as a denial of service vulnerability that can cause system crashes.
How do I fix USN-2684-1?
To fix USN-2684-1, upgrade your Linux kernel to version 3.19.0-23.24 or later.
Who is affected by USN-2684-1?
USN-2684-1 affects unprivileged local users running Ubuntu Linux 15.04 with specific kernel packages.
What is the impact of exploiting USN-2684-1?
Exploiting USN-2684-1 can result in a denial of service, leading to a system crash.
When was USN-2684-1 reported?
USN-2684-1 was reported on October 20, 2015, in relation to a flaw discovered in the kvm subsystem.