USN-3160-2: Linux kernel (Trusty HWE) vulnerabilities
USN-3160-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04 LTS. This update provides the corresponding updates for the Linux Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu 12.04 LTS. CAI Qian discovered that shared bind mounts in a mount namespace exponentially added entries without restriction to the Linux kernel's mount table. A local attacker could use this to cause a denial of service (system crash). (CVE-2016-6213) It was discovered that a race condition existed in the procfs environread function in the Linux kernel, leading to an integer underflow. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2016-7916)
Affected Software
Event History
Frequently Asked Questions
What is the title of USN-3160-2 vulnerability?
USN-3160-2: Linux kernel (Trusty HWE) vulnerabilities
What does USN-3160-2 vulnerability affect?
USN-3160-2 vulnerability affects Ubuntu 12.04 LTS with Linux kernel (Trusty HWE).
Who discovered the vulnerability in USN-3160-2?
CAI Qian discovered the vulnerability in USN-3160-2.
What is the severity of USN-3160-2 vulnerability?
The severity of USN-3160-2 vulnerability is not specified, please refer to the references for more information.
How do I fix USN-3160-2 vulnerability?
To fix USN-3160-2 vulnerability, update the Linux kernel to version 3.13.0-106.153~precise1 or higher for Ubuntu 12.04 LTS.