USN-3510-1: Linux kernel vulnerabilities
Mohamed Ghannam discovered that a use-after-free vulnerability existed in the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2017-16939) It was discovered that the Linux kernel did not properly handle copy-on- write of transparent huge pages. A local attacker could use this to cause a denial of service (application crashes) or possibly gain administrative privileges. (CVE-2017-1000405)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this advisory?
The vulnerability ID for this advisory is CVE-2017-16939.
What is the severity of CVE-2017-16939?
The severity of CVE-2017-16939 is high.
How does CVE-2017-16939 affect Ubuntu 14.04?
CVE-2017-16939 affects Ubuntu 14.04 with Linux kernel version up to and excluding 3.13.0-137.186.
How can I fix CVE-2017-16939?
To fix CVE-2017-16939, update the Linux kernel to version 3.13.0-137.186 or later.
Where can I find more information about CVE-2017-16939?
You can find more information about CVE-2017-16939 in the Ubuntu security advisory USN-3510-1.