First published: Wed May 17 2017(Updated: )
Dmitry Vyukov discovered that KVM implementation in the Linux kernel improperly emulated the VMXON instruction. A local attacker in a guest OS could use this to cause a denial of service (memory consumption) in the host OS. (CVE-2017-2596) Dmitry Vyukov discovered that the generic SCSI (sg) subsystem in the Linux kernel contained a stack-based buffer overflow. A local attacker with access to an sg device could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2017-7187) It was discovered that a NULL pointer dereference existed in the Direct Rendering Manager (DRM) driver for VMWare devices in the Linux kernel. A local attacker could use this to cause a denial of service (system crash). (CVE-2017-7261) Li Qiang discovered that an integer overflow vulnerability existed in the Direct Rendering Manager (DRM) driver for VMWare devices in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2017-7294) Jason Donenfeld discovered a heap overflow in the MACsec module in the Linux kernel. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2017-7477) It was discovered that an information leak existed in the set_mempolicy and mbind compat syscalls in the Linux kernel. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2017-7616)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/linux-image-4.10.0-21-generic-lpae | <4.10.0-21.23 | 4.10.0-21.23 |
=17.04 | ||
All of | ||
ubuntu/linux-image-generic | <4.10.0.21.23 | 4.10.0.21.23 |
=17.04 | ||
All of | ||
ubuntu/linux-image-4.10.0-1005-raspi2 | <4.10.0-1005.7 | 4.10.0-1005.7 |
=17.04 | ||
All of | ||
ubuntu/linux-image-generic-lpae | <4.10.0.21.23 | 4.10.0.21.23 |
=17.04 | ||
All of | ||
ubuntu/linux-image-4.10.0-21-generic | <4.10.0-21.23 | 4.10.0-21.23 |
=17.04 | ||
All of | ||
ubuntu/linux-image-4.10.0-21-lowlatency | <4.10.0-21.23 | 4.10.0-21.23 |
=17.04 | ||
All of | ||
ubuntu/linux-image-lowlatency | <4.10.0.21.23 | 4.10.0.21.23 |
=17.04 | ||
All of | ||
ubuntu/linux-image-raspi2 | <4.10.0.1005.7 | 4.10.0.1005.7 |
=17.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The vulnerability ID for this Linux kernel vulnerability is CVE-2017-2596.
This vulnerability allows a local attacker in a guest OS to cause a denial of service (memory consumption) in the host OS.
Software versions 4.10.0-21.23 and earlier are affected by this vulnerability.
To fix this vulnerability, update the Linux kernel to version 4.10.0-21.23 or later.
You can find more information about this vulnerability on the Ubuntu security website: https://ubuntu.com/security/CVE-2017-2596.