Ubuntu Security Notice USN-3655-1

Discussion in 'News Aggregator' started by Packet Storm, 23 May 2018.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 3655-1 - Jann Horn and Ken Johnson discovered that microprocessors utilizing speculative execution of a memory read may allow unauthorized memory reads via a sidechannel attack. This flaw is known as Spectre Variant 4. A local attacker could use this to expose sensitive information, including kernel memory. Jan H. Schonherr discovered that the Xen subsystem did not properly handle block IO merges correctly in some situations. An attacker in a guest vm could use this to cause a denial of service or possibly gain administrative privileges in the host. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...