USN-3511-1: Linux kernel (Azure) vulnerabilities
Mohamed Ghannam discovered that a use-after-free vulnerability existed in the Netlink subsystem (XFRM) in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2017-16939) It was discovered that the Linux kernel did not properly handle copy-on- write of transparent huge pages. A local attacker could use this to cause a denial of service (application crashes) or possibly gain administrative privileges. (CVE-2017-1000405)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this advisory?
The vulnerability ID of this advisory is USN-3511-1.
What is the severity of USN-3511-1?
The severity of USN-3511-1 is not specified in the provided information.
How does the use-after-free vulnerability in the Netlink subsystem (XFRM) affect the Linux kernel?
The use-after-free vulnerability in the Netlink subsystem (XFRM) could allow a local attacker to cause a denial of service (system crash) or possibly execute arbitrary code.
Which version of the Linux kernel is affected by this vulnerability?
The Linux kernel version affected by this vulnerability is 4.11.0-1016.16 (Azure).
How can I fix the vulnerability in my Ubuntu system?
To fix the vulnerability in Ubuntu, update the 'linux-image-4.11.0-1016-azure' package to version 4.11.0-1016.16 or higher.