Ubuntu Security Notice USN-3931-1

Discussion in 'News Aggregator' started by Packet Storm, 4 Apr 2019.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 3931-1 - M. Vefa Bicakci and Andy Lutomirski discovered that the kernel did not properly set up all arguments to an error handler callback used when running as a paravirtualized guest. An unprivileged attacker in a paravirtualized guest VM could use this to cause a denial of service. It was discovered that the KVM implementation in the Linux kernel on ARM 64bit processors did not properly handle some ioctls. An attacker with the privilege to create KVM-based virtual machines could use this to cause a denial of service or execute arbitrary code in the host. Various other issues were also addressed.

    Continue reading...
     

Share This Page

Loading...