USN-3444-1: Linux kernel vulnerabilities
Jan H. Schönherr discovered that the Xen subsystem did not properly handle block IO merges correctly in some situations. An attacker in a guest vm could use this to cause a denial of service (host crash) or possibly gain administrative privileges in the host. (CVE-2017-12134) Andrey Konovalov discovered that a divide-by-zero error existed in the TCP stack implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash). (CVE-2017-14106) Otto Ebeling discovered that the memory manager in the Linux kernel did not properly check the effective UID in some situations. A local attacker could use this to expose sensitive information. (CVE-2017-14140)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability identified by USN-3444-1?
The vulnerability identified by USN-3444-1 is a Linux kernel vulnerability.
What is the severity of the Linux kernel vulnerability in USN-3444-1?
The severity of the Linux kernel vulnerability in USN-3444-1 is not mentioned in the description.
What are the affected software versions by the Linux kernel vulnerability in USN-3444-1?
The Linux kernel vulnerability in USN-3444-1 affects Ubuntu 16.04 with various kernel versions.
How can an attacker exploit the Linux kernel vulnerability in USN-3444-1?
An attacker in a guest vm could exploit the Linux kernel vulnerability in USN-3444-1 to cause a denial of service (host crash) or possibly gain administrative privileges in the host.
Where can I find more information about the Linux kernel vulnerability in USN-3444-1?
More information about the Linux kernel vulnerability in USN-3444-1 can be found on the Ubuntu website.