Ubuntu Security Notice USN-3162-1
20th December, 2016
linux vulnerabilities
A security issue affects these releases of Ubuntu and its
derivatives:
- Ubuntu 16.10
Summary
Several security issues were fixed in the kernel.
Software description
- linux
- Linux kernel
Details
CAI Qian discovered that shared bind mounts in a mount namespace
exponentially added entries without restriction to the Linux kernel's mount
table. A local attacker could use this to cause a denial of service (system
crash). ()
Eyal Itkin discovered that the IP over IEEE 1394 (FireWire) implementation
in the Linux kernel contained a buffer overflow when handling fragmented
packets. A remote attacker could use this to possibly execute arbitrary
code with administrative privileges. ()
It was discovered that the keyring implementation in the Linux kernel
improperly handled crypto registration in conjunction with successful key-
type registration. A local attacker could use this to cause a denial of
service (system crash). ()
Update instructions
The problem can be corrected by updating your system to the following
package version:
- Ubuntu 16.10:
To update your system, please follow these instructions:
,
,
,
CVE-2016-9555
SOCIAL SHARE CARD GENERATOR