USN-3187-2: Linux kernel (OMAP4) vulnerabilities
Andrey Konovalov discovered that the SCTP implementation in the Linux kernel improperly handled validation of incoming data. A remote attacker could use this to cause a denial of service (system crash). (CVE-2016-9555) It was discovered that multiple memory leaks existed in the XFS implementation in the Linux kernel. A local attacker could use this to cause a denial of service (memory consumption). (CVE-2016-9685)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-3187-2?
The severity of USN-3187-2 is moderate.
How can a remote attacker exploit CVE-2016-9555?
A remote attacker can exploit CVE-2016-9555 by sending specially crafted data to the SCTP implementation in the Linux kernel, causing a system crash.
What is the affected version of Ubuntu?
Ubuntu 12.04 is affected by USN-3187-2.
How can I fix the vulnerability?
To fix the vulnerability, update to Linux kernel version 3.2.0-1499-omap4 (for Ubuntu 12.04) or version 3.2.0.1499.94 (for Ubuntu 12.04).
Where can I find more information about USN-3187-2?
You can find more information about USN-3187-2 on Ubuntu's security website.