USN-2226-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-2226-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/USN-2226-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-2226-1
Related
  • CVE-2014-0077
  • CVE-2014-1737
  • CVE-2014-1738
  • CVE-2014-2580
  • CVE-2014-2851
  • CVE-2014-7283
Published
2014-05-27T06:49:10.556919Z
Modified
2014-05-27T06:49:10.556919Z
Summary
linux vulnerabilities
Details

Matthew Daley reported an information leak in the floppy disk driver of the Linux kernel. An unprivileged local user could exploit this flaw to obtain potentially sensitive information from kernel memory. (CVE-2014-1738)

Matthew Daley reported a flaw in the handling of ioctl commands by the floppy disk driver in the Linux kernel. An unprivileged local user could exploit this flaw to gain administrative privileges if the floppy disk module is loaded. (CVE-2014-1737)

A flaw was discovered in the handling of network packets when mergeable buffers are disabled for virtual machines in the Linux kernel. Guest OS users may exploit this flaw to cause a denial of service (host OS crash) or possibly gain privilege on the host OS. (CVE-2014-0077)

Török Edwin discovered a flaw with Xen netback driver when used with Linux configurations that do not allow sleeping in softirq context. A guest administrator could exploit this flaw to cause a denial of service (system crash) on the host. (CVE-2014-2580)

A flaw was discovered in the Linux kernel's ping sockets. An unprivileged local user could exploit this flaw to cause a denial of service (system crash) or possibly gain privileges via a crafted application. (CVE-2014-2851)

Hannes Frederic Sowa reported a hash collision ordering problem in the xfs filesystem in the Linux kernel. A local user could exploit this flaw to cause filesystem corruption and a denial of service (oops or panic). (CVE-2014-7283)

References

Affected packages

Ubuntu:14.04:LTS / linux

Package

Name
linux

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.13.0-27.50

Ecosystem specific

{
    "availability": "No subscription needed",
    "binaries": [
        {
            "linux-image-3.13.0-27-generic-lpae": "3.13.0-27.50",
            "linux-image-3.13.0-27-powerpc-e500mc": "3.13.0-27.50",
            "linux-image-3.13.0-27-powerpc-smp": "3.13.0-27.50",
            "linux-image-3.13.0-27-powerpc64-emb": "3.13.0-27.50",
            "linux-image-3.13.0-27-generic": "3.13.0-27.50",
            "linux-image-3.13.0-27-powerpc-e500": "3.13.0-27.50",
            "linux-image-extra-3.13.0-27-generic": "3.13.0-27.50",
            "linux-image-3.13.0-27-powerpc64-smp": "3.13.0-27.50",
            "linux-image-3.13.0-27-lowlatency": "3.13.0-27.50"
        }
    ]
}