USN-2799-1: Linux kernel vulnerabilities
It was discovered that in certain situations, a directory could be renamed outside of a bind mounted location. An attacker could use this to escape bind mount containment and gain access to sensitive information. (CVE-2015-2925) Moein Ghasemzadeh discovered that the USB WhiteHEAT serial driver contained hardcoded attributes about the USB devices. An attacker could construct a fake WhiteHEAT USB device that, when inserted, causes a denial of service (system crash). (CVE-2015-5257)
Affected Software
Event History
Frequently Asked Questions
What is CVE-2015-2925?
CVE-2015-2925 is a vulnerability that allows an attacker to escape bind mount containment and gain access to sensitive information.
What software versions are affected by USN-2799-1?
The affected software versions for USN-2799-1 include linux-image-3.19.0-32-powerpc-e500mc, linux-image-3.19.0-32-powerpc-smp, linux-image-3.19.0-32-powerpc64-emb, linux-image-3.19.0-32-lowlatency, linux-image-3.19.0-32-generic, linux-image-3.19.0-32-powerpc64-smp, and linux-image-3.19.0-32-generic-lpae.
How can I fix the vulnerability in USN-2799-1?
To fix the vulnerability in USN-2799-1, you should update the linux-image packages to version 3.19.0-32.37 or higher.
Where can I find more information about CVE-2015-2925?
You can find more information about CVE-2015-2925 on the Ubuntu security website.