USN-3443-1: Linux kernel vulnerabilities
It was discovered that on the PowerPC architecture, the kernel did not properly sanitize the signal stack when handling sigreturn(). A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2017-1000255) Andrey Konovalov discovered that a divide-by-zero error existed in the TCP stack implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash). (CVE-2017-14106)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this security notice?
The vulnerability ID for this security notice is CVE-2017-1000255.
What is the severity of CVE-2017-1000255?
The severity of CVE-2017-1000255 is high.
Which systems are affected by CVE-2017-1000255?
PowerPC architectures running Ubuntu 17.04 are affected by CVE-2017-1000255.
What can an attacker do with CVE-2017-1000255?
An attacker can cause a denial of service (system crash) or possibly execute arbitrary code.
How can I fix CVE-2017-1000255?
To fix CVE-2017-1000255, update the affected systems to kernel version 4.10.0.37.37 or higher.