USN-2829-1: Linux kernel vulnerabilities
It was discovered that the SCTP protocol implementation in the Linux kernel performed an incorrect sequence of protocol-initialization steps. A local attacker could use this to cause a denial of service (system crash). (CVE-2015-5283) Dmitry Vyukov discovered that the Linux kernel's keyring handler attempted to garbage collect incompletely instantiated keys. A local unprivileged attacker could use this to cause a denial of service (system crash). (CVE-2015-7872)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this advisory?
The vulnerability ID for this advisory is USN-2829-1.
What is the severity of the CVE-2015-5283 vulnerability?
The severity of the CVE-2015-5283 vulnerability is not mentioned in the advisory.
How can a local attacker exploit CVE-2015-5283 vulnerability?
A local attacker can exploit the CVE-2015-5283 vulnerability to cause a denial of service (system crash).
How can I fix the CVE-2015-5283 vulnerability?
To fix the CVE-2015-5283 vulnerability, you need to update the affected Linux kernel packages to version 3.19.0-39.44 or higher.
Where can I find more information about the USN-2829-1 advisory?
You can find more information about the USN-2829-1 advisory on the Ubuntu website.