First published: Thu Nov 05 2015(Updated: )
It was discovered that in certain situations, a directory could be renamed outside of a bind mounted location. An attacker could use this to escape bind mount containment and gain access to sensitive information. (CVE-2015-2925) Moein Ghasemzadeh discovered that the USB WhiteHEAT serial driver contained hardcoded attributes about the USB devices. An attacker could construct a fake WhiteHEAT USB device that, when inserted, causes a denial of service (system crash). (CVE-2015-5257)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/linux-image-3.19.0-32-powerpc-e500mc | <3.19.0-32.37 | 3.19.0-32.37 |
=15.04 | ||
All of | ||
ubuntu/linux-image-3.19.0-32-powerpc-smp | <3.19.0-32.37 | 3.19.0-32.37 |
=15.04 | ||
All of | ||
ubuntu/linux-image-3.19.0-32-powerpc64-emb | <3.19.0-32.37 | 3.19.0-32.37 |
=15.04 | ||
All of | ||
ubuntu/linux-image-3.19.0-32-lowlatency | <3.19.0-32.37 | 3.19.0-32.37 |
=15.04 | ||
All of | ||
ubuntu/linux-image-3.19.0-32-generic | <3.19.0-32.37 | 3.19.0-32.37 |
=15.04 | ||
All of | ||
ubuntu/linux-image-3.19.0-32-powerpc64-smp | <3.19.0-32.37 | 3.19.0-32.37 |
=15.04 | ||
All of | ||
ubuntu/linux-image-3.19.0-32-generic-lpae | <3.19.0-32.37 | 3.19.0-32.37 |
=15.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-2925 is a vulnerability that allows an attacker to escape bind mount containment and gain access to sensitive information.
The affected software versions for USN-2799-1 include linux-image-3.19.0-32-powerpc-e500mc, linux-image-3.19.0-32-powerpc-smp, linux-image-3.19.0-32-powerpc64-emb, linux-image-3.19.0-32-lowlatency, linux-image-3.19.0-32-generic, linux-image-3.19.0-32-powerpc64-smp, and linux-image-3.19.0-32-generic-lpae.
To fix the vulnerability in USN-2799-1, you should update the linux-image packages to version 3.19.0-32.37 or higher.
You can find more information about CVE-2015-2925 on the Ubuntu security website.