Ubuntu Security Notice USN-2792-1

Discussion in 'News Aggregator' started by Packet Storm, 6 Nov 2015.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 2792-1 - Dmitry Vyukov discovered that the Linux kernel did not properly initialize IPC object state in certain situations. A local attacker could use this to escalate their privileges, expose confidential information, or cause a denial of service (system crash). It was discovered that the Linux kernel did not check if a new IPv6 MTU set by a user space application was valid. A remote attacker could forge a route advertisement with an invalid MTU that a user space daemon like NetworkManager would honor and apply to the kernel, causing a denial of service. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...