Ubuntu Security Notice USN-3358-1
20th July, 2017
linux, linux-raspi2 vulnerabilities
A security issue affects these releases of Ubuntu and its
derivatives:
- Ubuntu 17.04
Summary
Several security issues were fixed in the Linux kernel.
Software description
- linux
- Linux kernel
- linux-raspi2
- Linux kernel for Raspberry Pi 2
Details
It was discovered that the Linux kernel did not properly initialize a Wake-
on-Lan data structure. A local attacker could use this to expose sensitive
information (kernel memory). ()
Li Qiang discovered that the DRM driver for VMware Virtual GPUs in the
Linux kernel did not properly validate some ioctl arguments. A local
attacker could use this to cause a denial of service (system crash).
()
Update instructions
The problem can be corrected by updating your system to the following
package version:
- Ubuntu 17.04:
- linux-image-generic-lpae 4.10.0.28.29
- linux-image-generic 4.10.0.28.29
- linux-image-lowlatency 4.10.0.28.29
- linux-image-raspi2 4.10.0.1011.13
To update your system, please follow these instructions:
,
,
CVE-2017-9605
SOCIAL SHARE CARD GENERATOR