Ubuntu Security Notice USN-3234-1

Discussion in 'News Aggregator' started by Packet Storm, 17 Mar 2017.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 3234-1 - Ralf Spenneberg discovered that the ext4 implementation in the Linux kernel did not properly validate meta block groups. An attacker with physical access could use this to specially craft an ext4 image that causes a denial of service. It was discovered that the Linux kernel did not clear the setgid bit during a setxattr call on a tmpfs filesystem. A local attacker could use this to gain elevated group privileges. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...