linux vulnerability

Related Vulnerabilities: CVE-2014-8159  

The system could be made to crash or run programs as an administrator.

It was discovered that the Linux kernel’s Infiniband subsystem did not properly sanitize its input parameters while registering memory regions from userspace. A local user could exploit this flaw to cause a denial of service (system crash) or to potentially gain administrative privileges.

12 March 2015

linux vulnerability

A security issue affects these releases of Ubuntu and its derivatives:

  • Ubuntu 12.04 LTS

Summary

The system could be made to crash or run programs as an administrator.

Software Description

  • linux - Linux kernel

Details

It was discovered that the Linux kernel’s Infiniband subsystem did not properly sanitize its input parameters while registering memory regions from userspace. A local user could exploit this flaw to cause a denial of service (system crash) or to potentially gain administrative privileges.

Update instructions

The problem can be corrected by updating your system to the following package versions:

Ubuntu 12.04 LTS
linux-image-3.2.0-77-generic - 3.2.0-77.114
linux-image-3.2.0-77-generic-pae - 3.2.0-77.114
linux-image-3.2.0-77-highbank - 3.2.0-77.114
linux-image-3.2.0-77-omap - 3.2.0-77.114
linux-image-3.2.0-77-powerpc-smp - 3.2.0-77.114
linux-image-3.2.0-77-powerpc64-smp - 3.2.0-77.114
linux-image-3.2.0-77-virtual - 3.2.0-77.114

To update your system, please follow these instructions: https://wiki.ubuntu.com/Security/Upgrades.

After a standard system update you need to reboot your computer to make all the necessary changes.

References