USN-988-1: Linux kernel vulnerabilities
Ben Hawkes discovered that the Linux kernel did not correctly validate memory ranges on 64bit kernels when allocating memory on behalf of 32bit system calls. On a 64bit system, a local attacker could perform malicious multicast getsockopt calls to gain root privileges. (CVE-2010-3081) Ben Hawkes discovered that the Linux kernel did not correctly filter registers on 64bit kernels when performing 32bit system calls. On a 64bit system, a local attacker could manipulate 32bit system calls to gain root privileges. (Ubuntu 6.06 LTS and 8.04 LTS were not affected.) (CVE-2010-3301)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-988-1?
The vulnerability identified by USN-988-1 has been rated as high severity due to the potential for local attackers to gain root privileges.
How do I fix USN-988-1?
To fix USN-988-1, update your system to the latest kernel version 2.6.31-22.65 or later.
Who is affected by USN-988-1?
USN-988-1 affects local users of Ubuntu 9.10 systems running vulnerable versions of the Linux kernel.
What type of vulnerability is identified in USN-988-1?
USN-988-1 is a privilege escalation vulnerability that allows local attackers to perform malicious multicast getsockopt calls.
Is there a workaround for USN-988-1?
There is no specific workaround for USN-988-1, so it is recommended to apply the proper updates.