Debian Security Advisory
DLA-412-1 linux-2.6 -- LTS security update
- Date Reported:
- 06 Feb 2016
- Affected Packages:
- linux-2.6
- Vulnerable:
- Yes
- Security database references:
- In Mitre's CVE dictionary: CVE-2015-7566, CVE-2015-8767, CVE-2015-8785, CVE-2016-0723, CVE-2016-2069.
- More information:
-
This update fixes the CVEs described below.
- CVE-2015-7566
Ralf Spenneberg of OpenSource Security reported that the visor driver crashes when a specially crafted USB device without bulk-out endpoint is detected.
- CVE-2015-8767
An SCTP denial-of-service was discovered which can be triggered by a local attacker during a heartbeat timeout event after the 4-way handshake.
- CVE-2015-8785
It was discovered that local users permitted to write to a file on a FUSE filesystem could cause a denial of service (unkillable loop in the kernel).
- CVE-2016-0723
A use-after-free vulnerability was discovered in the TIOCGETD ioctl. A local attacker could use this flaw for denial-of-service.
- CVE-2016-2069
Andy Lutomirski discovered a race condition in flushing of the TLB when switching tasks. On an SMP system this could possibly lead to a crash, information leak or privilege escalation.
For the oldoldstable distribution (squeeze), these problems have been fixed in version 2.6.32-48squeeze19. Additionally, this version includes upstream stable update 2.6.32.70. This is the final update to the linux-2.6 package for squeeze.
For the oldstable distribution (wheezy), these problems will be fixed soon.
For the stable distribution (jessie), CVE-2015-7566, CVE-2015-8767 and CVE-2016-0723 were fixed in linux version 3.16.7-ckt20-1+deb8u3 and the remaining problems will be fixed soon.
- CVE-2015-7566