USN-2738-1: Linux kernel vulnerability
Published Sep 9, 2015
·Updated
It was discovered that an integer overflow error existed in the SCSI generic (sg) driver in the Linux kernel. A local attacker with write permission to a SCSI generic device could use this to cause a denial of service (system crash) or potentially escalate their privileges.
Affected Software
14 affected componentsFixes available
All of the following
ubuntu/linux-image-3.19.0-28-lowlatency<3.19.0-28.30
3.19.0-28.30
Ubuntu Ubuntu=15.04
All of the following
ubuntu/linux-image-3.19.0-28-powerpc64-emb<3.19.0-28.30
3.19.0-28.30
Ubuntu Ubuntu=15.04
All of the following
ubuntu/linux-image-3.19.0-28-powerpc-smp<3.19.0-28.30
3.19.0-28.30
Ubuntu Ubuntu=15.04
All of the following
ubuntu/linux-image-3.19.0-28-generic-lpae<3.19.0-28.30
3.19.0-28.30
Ubuntu Ubuntu=15.04
All of the following
ubuntu/linux-image-3.19.0-28-generic<3.19.0-28.30
3.19.0-28.30
Ubuntu Ubuntu=15.04
All of the following
ubuntu/linux-image-3.19.0-28-powerpc-e500mc<3.19.0-28.30
3.19.0-28.30
Ubuntu Ubuntu=15.04
All of the following
ubuntu/linux-image-3.19.0-28-powerpc64-smp<3.19.0-28.30
3.19.0-28.30
Ubuntu Ubuntu=15.04
Event History
Sep 9, 2015
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the vulnerability ID for this Linux kernel vulnerability?
The vulnerability ID for this Linux kernel vulnerability is USN-2738-1.
2
What is the impact of this vulnerability?
This vulnerability can cause a denial of service (system crash) or potentially escalate privileges.
3
Which version of the Linux kernel is affected by this vulnerability?
The Linux kernel version 3.19.0-28.30 is affected by this vulnerability.
4
How can I fix this vulnerability in Ubuntu?
To fix this vulnerability in Ubuntu, update the linux-image-3.19.0-28 packages to version 3.19.0-28.30.
5
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Ubuntu website using the provided references.