First published: Wed Feb 22 2017(Updated: )
It was discovered that the generic SCSI block layer in the Linux kernel did not properly restrict write operations in certain situations. A local attacker could use this to cause a denial of service (system crash) or possibly gain administrative privileges. (CVE-2016-10088) Jim Mattson discovered that the KVM implementation in the Linux kernel mismanages the #BP and #OF exceptions. A local attacker in a guest virtual machine could use this to cause a denial of service (guest OS crash). (CVE-2016-9588) Andrey Konovalov discovered a use-after-free vulnerability in the DCCP implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly gain administrative privileges. (CVE-2017-6074)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/linux-image-powerpc-smp | <4.8.0.39.50 | 4.8.0.39.50 |
=16.10 | ||
All of | ||
ubuntu/linux-image-4.8.0-39-generic | <4.8.0-39.42 | 4.8.0-39.42 |
=16.10 | ||
All of | ||
ubuntu/linux-image-4.8.0-39-generic-lpae | <4.8.0-39.42 | 4.8.0-39.42 |
=16.10 | ||
All of | ||
ubuntu/linux-image-generic | <4.8.0.39.50 | 4.8.0.39.50 |
=16.10 | ||
All of | ||
ubuntu/linux-image-powerpc-e500mc | <4.8.0.39.50 | 4.8.0.39.50 |
=16.10 | ||
All of | ||
ubuntu/linux-image-lowlatency | <4.8.0.39.50 | 4.8.0.39.50 |
=16.10 | ||
All of | ||
ubuntu/linux-image-4.8.0-39-lowlatency | <4.8.0-39.42 | 4.8.0-39.42 |
=16.10 | ||
All of | ||
ubuntu/linux-image-4.8.0-39-powerpc-smp | <4.8.0-39.42 | 4.8.0-39.42 |
=16.10 | ||
All of | ||
ubuntu/linux-image-generic-lpae | <4.8.0.39.50 | 4.8.0.39.50 |
=16.10 | ||
All of | ||
ubuntu/linux-image-4.8.0-1026-raspi2 | <4.8.0-1026.29 | 4.8.0-1026.29 |
=16.10 | ||
All of | ||
ubuntu/linux-image-4.8.0-39-powerpc64-emb | <4.8.0-39.42 | 4.8.0-39.42 |
=16.10 | ||
All of | ||
ubuntu/linux-image-powerpc64-emb | <4.8.0.39.50 | 4.8.0.39.50 |
=16.10 | ||
All of | ||
ubuntu/linux-image-raspi2 | <4.8.0.1026.29 | 4.8.0.1026.29 |
=16.10 | ||
All of | ||
ubuntu/linux-image-4.8.0-39-powerpc-e500mc | <4.8.0-39.42 | 4.8.0-39.42 |
=16.10 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The vulnerability ID for this security advisory is CVE-2016-10088.
The vulnerability allows a local attacker to cause a denial of service or possibly gain administrative privileges.
The vulnerability affects Linux kernel versions 4.8.0.39.50 and earlier.
To fix the vulnerability, update to Linux kernel version 4.8.0.39.50 or a later version.
More information about this vulnerability can be found on the Ubuntu website.