Debian Security Advisory
DLA-412-1 linux-2.6 -- LTS security update
- Date Reported:
- 06 Feb 2016
- Affected Packages:
- Security database references:
- In Mitre's CVE dictionary: CVE-2015-7566, CVE-2015-8767, CVE-2015-8785, CVE-2016-0723, CVE-2016-2069.
- More information:
This update fixes the CVEs described below.
Ralf Spenneberg of OpenSource Security reported that the visor driver crashes when a specially crafted USB device without bulk-out endpoint is detected.
An SCTP denial-of-service was discovered which can be triggered by a local attacker during a heartbeat timeout event after the 4-way handshake.
It was discovered that local users permitted to write to a file on a FUSE filesystem could cause a denial of service (unkillable loop in the kernel).
A use-after-free vulnerability was discovered in the TIOCGETD ioctl. A local attacker could use this flaw for denial-of-service.
Andy Lutomirski discovered a race condition in flushing of the TLB when switching tasks. On an SMP system this could possibly lead to a crash, information leak or privilege escalation.
For the oldoldstable distribution (squeeze), these problems have been fixed in version 2.6.32-48squeeze19. Additionally, this version includes upstream stable update 126.96.36.199. This is the final update to the linux-2.6 package for squeeze.
For the oldstable distribution (wheezy), these problems will be fixed soon.