USN-2525-1: Linux kernel vulnerability

12 March 2015

The system could be made to crash or run programs as an administrator.

Releases

Packages

Details

It was discovered that the Linux kernel's Infiniband subsystem did not
properly sanitize its input parameters while registering memory regions
from userspace. A local user could exploit this flaw to cause a denial of
service (system crash) or to potentially gain administrative privileges.

References

Related notices

  • USN-2526-1: linux-image-3.2.0-77-generic, linux-image-3.2.0-77-virtual, linux-image-3.2.0-77-highbank, linux-image-3.2.0-77-powerpc-smp, linux-image-3.2.0-77-powerpc64-smp, linux-image-3.2.0-77-omap, linux-image-3.2.0-77-generic-pae, linux
  • USN-2527-1: linux-image-3.13.0-46-generic-lpae, linux-lts-trusty, linux-image-3.13.0-46-generic
  • USN-2528-1: linux-image-3.13.0-46-generic-lpae, linux-image-3.13.0-46-lowlatency, linux-image-3.13.0-46-powerpc-smp, linux-image-3.13.0-46-powerpc64-emb, linux-image-3.13.0-46-powerpc64-smp, linux-image-3.13.0-46-generic, linux-image-3.13.0-46-powerpc-e500mc, linux-image-3.13.0-46-powerpc-e500, linux-image-extra-3.13.0-46-generic, linux
  • USN-2529-1: linux-image-3.16.0-31-powerpc-smp, linux-image-3.16.0-31-powerpc64-emb, linux-image-3.16.0-31-powerpc-e500mc, linux-image-extra-3.16.0-31-generic, linux-lts-utopic, linux-image-3.16.0-31-powerpc64-smp, linux-image-3.16.0-31-lowlatency, linux-image-3.16.0-31-generic-lpae, linux-image-3.16.0-31-generic
  • USN-2530-1: linux-image-3.16.0-31-generic, linux-image-3.16.0-31-powerpc-smp, linux-image-3.16.0-31-powerpc64-emb, linux-image-3.16.0-31-powerpc-e500mc, linux-image-3.16.0-31-powerpc64-smp, linux-image-3.16.0-31-lowlatency, linux-image-3.16.0-31-generic-lpae, linux
  • USN-2561-1: linux-image-3.2.0-1462-omap4, linux-ti-omap4