USN-3443-3: Linux kernel (GCP) vulnerability
Published Oct 11, 2017
·Updated
Andrey Konovalov discovered that a divide-by-zero error existed in the TCP stack implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash). (CVE-2017-14106)
Affected Software
2 affected componentsFixes available
All of the following
ubuntu/linux-image-4.10.0-1007-gcp<4.10.0-1007.7
4.10.0-1007.7
Ubuntu Ubuntu=16.04
Event History
Oct 11, 2017
Advisory Published
via Ubuntu·12:00 AM
Frequently Asked Questions
1
What is the severity of USN-3443-3?
The severity of USN-3443-3 is high.
2
How does the TCP stack implementation vulnerability (CVE-2017-14106) affect the Linux kernel?
The vulnerability allows a local attacker to cause a denial of service by triggering a system crash.
3
Which version of the Linux kernel is affected by USN-3443-3?
The Linux kernel version 4.10.0-1007-gcp is affected by USN-3443-3.
4
How can I fix USN-3443-3?
To fix USN-3443-3, update the Linux kernel to version 4.10.0-1007.7 or later.
5
Where can I find more information about USN-3443-3?
You can find more information about USN-3443-3 at the following URL: [https://ubuntu.com/security/notices/USN-3443-2](https://ubuntu.com/security/notices/USN-3443-2)