USN-2852-1: Linux kernel (Raspberry Pi 2) vulnerability
Jann Horn discovered a ptrace issue with user namespaces in the Linux kernel. The namespace owner could potentially exploit this flaw by ptracing a root owned process entering the user namespace to elevate its privileges and potentially gain access outside of the namespace. (http://bugs.launchpad.net/bugs/1527374, CVE-2015-8709)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Linux kernel vulnerability on Raspberry Pi 2?
The vulnerability ID is USN-2852-1.
What is the impact of the vulnerability?
The vulnerability allows the namespace owner to potentially elevate privileges and gain access outside of the namespace.
Which Linux kernel version is affected by this vulnerability?
The Linux kernel version 4.2.0-1017.24 on Raspberry Pi 2 is affected.
How can I fix this vulnerability?
Update the Linux kernel to version 4.2.0-1017.24 or later.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following links: [CVE-2015-8709](https://ubuntu.com/security/CVE-2015-8709), [USN-2853-1](https://ubuntu.com/security/notices/USN-2853-1), [USN-2851-1](https://ubuntu.com/security/notices/USN-2851-1).