USN-3581-3: Linux kernel (Raspberry Pi 2) vulnerabilities
Mohamed Ghannam discovered that the IPv4 raw socket implementation in the Linux kernel contained a race condition leading to uninitialized pointer usage. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2017-17712) ChunYu Wang discovered that a use-after-free vulnerability existed in the SCTP protocol implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code, (CVE-2017-15115) Mohamed Ghannam discovered a use-after-free vulnerability in the DCCP protocol implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2017-8824)
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the vulnerability in USN-3581-3?
The vulnerability in USN-3581-3 is a race condition leading to uninitialized pointer usage in the IPv4 raw socket implementation in the Linux kernel.
What is the impact of the vulnerability in USN-3581-3?
The vulnerability in USN-3581-3 could allow a local attacker to cause a denial of service or possibly execute arbitrary code.
How can I fix the vulnerability in USN-3581-3?
To fix the vulnerability in USN-3581-3, update the Linux kernel to version 4.13.0-1014.15 or later.
Which versions of Ubuntu are affected by the vulnerability in USN-3581-3?
The vulnerability in USN-3581-3 affects Ubuntu 17.10.
Where can I find more information about the vulnerability in USN-3581-3?
You can find more information about the vulnerability in USN-3581-3 on the Ubuntu Security website.