USN-3508-2: Linux kernel (HWE) vulnerabilities
USN-3508-1 fixed vulnerabilities in the Linux kernel for Ubuntu 17.04. This update provides the corresponding updates for the Linux Hardware Enablement (HWE) kernel from Ubuntu 17.04 for Ubuntu 16.04 LTS. Mohamed Ghannam discovered that a use-after-free vulnerability existed in the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2017-16939) It was discovered that the Linux kernel did not properly handle copy-on- write of transparent huge pages. A local attacker could use this to cause a denial of service (application crashes) or possibly gain administrative privileges. (CVE-2017-1000405) Yonggang Guo discovered that a race condition existed in the driver subsystem in the Linux kernel. A local attacker could use this to possibly gain administrative privileges. (CVE-2017-12146)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-3508-2?
The severity of USN-3508-2 is not specified in the information provided.
How do I determine if my system is affected by USN-3508-2?
You can determine if your system is affected by USN-3508-2 by checking the installed version of the Linux kernel against the affected versions specified in the information.
How do I fix USN-3508-2?
You can fix USN-3508-2 by updating the Linux kernel to the specified remedy version.
Where can I find more information about USN-3508-2?
You can find more information about USN-3508-2 on the Ubuntu Security Notices website using the provided references.
What are the CWE IDs associated with USN-3508-2?
The CWE IDs associated with USN-3508-2 are CWE-416 and CWE-362.