USN-3107-1: Linux kernel vulnerability
Published Oct 20, 2016
·Updated
It was discovered that a race condition existed in the memory manager of the Linux kernel when handling copy-on-write breakage of private read-only memory mappings. A local attacker could use this to gain administrative privileges.
Affected Software
12 affected componentsFixes available
All of the following
ubuntu/linux-image-4.8.0-26-powerpc64-emb<4.8.0-26.28
4.8.0-26.28
Ubuntu Ubuntu=16.10
All of the following
ubuntu/linux-image-4.8.0-26-generic<4.8.0-26.28
4.8.0-26.28
Ubuntu Ubuntu=16.10
All of the following
ubuntu/linux-image-4.8.0-26-generic-lpae<4.8.0-26.28
4.8.0-26.28
Ubuntu Ubuntu=16.10
All of the following
ubuntu/linux-image-4.8.0-26-lowlatency<4.8.0-26.28
4.8.0-26.28
Ubuntu Ubuntu=16.10
All of the following
ubuntu/linux-image-4.8.0-26-powerpc-smp<4.8.0-26.28
4.8.0-26.28
Ubuntu Ubuntu=16.10
All of the following
ubuntu/linux-image-4.8.0-26-powerpc-e500mc<4.8.0-26.28
4.8.0-26.28
Ubuntu Ubuntu=16.10
Event History
Oct 20, 2016
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-3107-1?
The severity of USN-3107-1 is classified as critical due to the potential for local attackers to gain administrative privileges.
2
How do I fix USN-3107-1?
To fix USN-3107-1, update the kernel to version 4.8.0-26.28 or later.
3
Which systems are affected by USN-3107-1?
USN-3107-1 affects Ubuntu version 16.10 running the linux-image 4.8.0-26 for various architectures.
4
Can I exploit USN-3107-1 remotely?
No, USN-3107-1 requires local access for exploitation, making it a local privilege escalation vulnerability.
5
Is USN-3107-1 related to CVE-2016-5195?
Yes, USN-3107-1 addresses the vulnerability identified as CVE-2016-5195.