Debian Security Advisory

DLA-378-1 linux-2.6 -- LTS security update

Date Reported:
05 Jan 2016
Affected Packages:
linux-2.6
Vulnerable:
Yes
Security database references:
In Mitre's CVE dictionary: CVE-2015-7550, CVE-2015-8543, CVE-2015-8575.
More information:

This update fixes the CVEs described below.

  • CVE-2015-7550

    Dmitry Vyukov discovered a race condition in the keyring subsystem that allows a local user to cause a denial of service (crash).

  • CVE-2015-8543

    It was discovered that a local user permitted to create raw sockets could cause a denial-of-service by specifying an invalid protocol number for the socket. The attacker must have the CAP_NET_RAW capability.

  • CVE-2015-8575

    David Miller discovered a flaw in the Bluetooth SCO sockets implementation that leads to an information leak to local users.

In addition, this update fixes a regression in the previous update:

  • #808293

    A regression in the UDP implementation prevented freeradius and some other applications from receiving data.

For the oldoldstable distribution (squeeze), these problems have been fixed in version 2.6.32-48squeeze18.

For the oldstable distribution (wheezy), these problems have been fixed in version 3.2.73-2+deb7u2.

For the stable distribution (jessie), these problems have been fixed in version 3.16.7-ckt20-1+deb8u2 or earlier.