Ubuntu Security Notice USN-3160-1

Discussion in 'News Aggregator' started by Packet Storm, 22 Dec 2016.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 3160-1 - CAI Qian discovered that shared bind mounts in a mount namespace exponentially added entries without restriction to the Linux kernel's mount table. A local attacker could use this to cause a denial of service. It was discovered that a race condition existed in the procfs environ_read function in the Linux kernel, leading to an integer underflow. A local attacker could use this to expose sensitive information. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...