USN-2719-1: Linux kernel vulnerability
Published Aug 18, 2015
·Updated
Marcelo Ricardo Leitner discovered a race condition in the Linux kernel's SCTP address configuration lists when using Address Configuration Change (ASCONF) options on a socket. An unprivileged local user could exploit this flaw to cause a denial of service (system crash).
Affected Software
14 affected componentsFixes available
All of the following
ubuntu/linux-image-3.19.0-26-generic-lpae<3.19.0-26.28
3.19.0-26.28
Ubuntu Ubuntu=15.04
All of the following
ubuntu/linux-image-3.19.0-26-lowlatency<3.19.0-26.28
3.19.0-26.28
Ubuntu Ubuntu=15.04
All of the following
ubuntu/linux-image-3.19.0-26-generic<3.19.0-26.28
3.19.0-26.28
Ubuntu Ubuntu=15.04
All of the following
ubuntu/linux-image-3.19.0-26-powerpc64-emb<3.19.0-26.28
3.19.0-26.28
Ubuntu Ubuntu=15.04
All of the following
ubuntu/linux-image-3.19.0-26-powerpc-smp<3.19.0-26.28
3.19.0-26.28
Ubuntu Ubuntu=15.04
All of the following
ubuntu/linux-image-3.19.0-26-powerpc64-smp<3.19.0-26.28
3.19.0-26.28
Ubuntu Ubuntu=15.04
All of the following
ubuntu/linux-image-3.19.0-26-powerpc-e500mc<3.19.0-26.28
3.19.0-26.28
Ubuntu Ubuntu=15.04
Event History
Aug 18, 2015
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-2719-1?
The severity of USN-2719-1 is classified as a denial of service vulnerability.
2
How do I fix USN-2719-1?
To fix USN-2719-1, update the kernel to version 3.19.0-26.28 or later.
3
Who is affected by USN-2719-1?
USN-2719-1 affects unprivileged local users of Ubuntu 15.04 or older using the affected Linux kernel versions.
4
What type of vulnerability is USN-2719-1?
USN-2719-1 is a race condition vulnerability in the Linux kernel's SCTP address configuration.
5
Can USN-2719-1 be exploited remotely?
No, USN-2719-1 requires local access to the system for exploitation.