First published: Sat Dec 19 2015(Updated: )
Jann Horn discovered a ptrace issue with user namespaces in the Linux kernel. The namespace owner could potentially exploit this flaw by ptracing a root owned process entering the user namespace to elevate its privileges and potentially gain access outside of the namespace. (http://bugs.launchpad.net/bugs/1527374, CVE-2015-8709)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/linux-image-4.2.0-1017-raspi2 | <4.2.0-1017.24 | 4.2.0-1017.24 |
=15.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is USN-2852-1.
The vulnerability allows the namespace owner to potentially elevate privileges and gain access outside of the namespace.
The Linux kernel version 4.2.0-1017.24 on Raspberry Pi 2 is affected.
Update the Linux kernel to version 4.2.0-1017.24 or later.
You can find more information about this vulnerability at the following links: [CVE-2015-8709](https://ubuntu.com/security/CVE-2015-8709), [USN-2853-1](https://ubuntu.com/security/notices/USN-2853-1), [USN-2851-1](https://ubuntu.com/security/notices/USN-2851-1).