Ubuntu Security Notice USN-3775-1

Discussion in 'News Aggregator' started by Packet Storm, 3 Oct 2018.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 3775-1 - It was discovered that the paravirtualization implementation in the Linux kernel did not properly handle some indirect calls, reducing the effectiveness of Spectre v2 mitigations for paravirtual guests. A local attacker could use this to expose sensitive information. It was discovered that microprocessors utilizing speculative execution and prediction of return addresses via Return Stack Buffer may allow unauthorized memory reads via sidechannel attacks. An attacker could use this to expose sensitive information. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...