Ubuntu Security Notice USN-2590-1

Discussion in 'News Aggregator' started by Packet Storm, 1 May 2015.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 2590-1 - Jan Beulich discovered the Xen virtual machine subsystem of the Linux kernel did not properly restrict access to PCI command registers. A local guest user could exploit this flaw to cause a denial of service (host crash). A stack overflow was discovered in the the microcode loader for the intel x86 platform. A local attacker could exploit this flaw to cause a denial of service (kernel crash) or to potentially execute code with kernel privileges. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...