USN-3509-1: Linux kernel vulnerabilities
Mohamed Ghannam discovered that a use-after-free vulnerability existed in the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2017-16939) It was discovered that the Linux kernel did not properly handle copy-on- write of transparent huge pages. A local attacker could use this to cause a denial of service (application crashes) or possibly gain administrative privileges. (CVE-2017-1000405) Fan Wu, Haoran Qiu, and Shixiong Zhao discovered that the associative array implementation in the Linux kernel sometimes did not properly handle adding a new entry. A local attacker could use this to cause a denial of service (system crash). (CVE-2017-12193) Andrey Konovalov discovered an out-of-bounds read in the GTCO digitizer USB driver for the Linux kernel. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2017-16643)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability in USN-3509-1?
The vulnerability in USN-3509-1 is a use-after-free vulnerability in the Netlink subsystem (XFRM) in the Linux kernel.
What can a local attacker do with the vulnerability in USN-3509-1?
A local attacker could cause a denial of service (system crash) or possibly execute arbitrary code.
How can I fix the vulnerability in USN-3509-1?
To fix the vulnerability in USN-3509-1, update the Linux kernel to version 4.4.0-1012.17 or later.
Which versions of Ubuntu are affected by the vulnerability in USN-3509-1?
The vulnerability in USN-3509-1 affects Ubuntu 16.04.
Where can I find more information about the vulnerability in USN-3509-1?
You can find more information about the vulnerability in USN-3509-1 on the Ubuntu security website.