Ubuntu Security Notice USN-3798-1

Discussion in 'News Aggregator' started by Packet Storm, 24 Oct 2018.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 3798-1 - Dmitry Vyukov discovered that the key management subsystem in the Linux kernel did not properly restrict adding a key that already exists but is negatively instantiated. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. It was discovered that a use-after-free vulnerability existed in the device driver for XCeive xc2028/xc3028 tuners in the Linux kernel. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...