USN-2752-1: Linux kernel vulnerabilities
Benjamin Randazzo discovered an information leak in the md (multiple device) driver when the bitmapinfo.file is disabled. A local privileged attacker could use this to obtain sensitive information from the kernel. (CVE-2015-5697) Marc-André Lureau discovered that the vhost driver did not properly release the userspace provided log file descriptor. A privileged attacker could use this to cause a denial of service (resource exhaustion). (CVE-2015-6252)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-2752-1?
The severity of USN-2752-1 is moderate.
How can a local attacker exploit USN-2752-1?
A local privileged attacker could exploit USN-2752-1 to obtain sensitive information from the kernel.
Which version of Ubuntu is affected by USN-2752-1?
Ubuntu version 15.04 is affected by USN-2752-1.
How do I fix USN-2752-1?
To fix USN-2752-1, update your system to linux-image-3.19.0-30.33 version or higher.
Where can I find more information about USN-2752-1?
You can find more information about USN-2752-1 on the Ubuntu security website.