Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Linux

January 30th, 2009, 08:53 GMT · By

Linux Kernel Vulnerabilities in Ubuntu 8.10. Update Today.

SHARE:

Adjust text size:


Ubuntu 8.10
Enlarge picture
On January 29th the Ubuntu developers announced the availability of a new important security update for the Ubuntu 8.10 (Intrepid Ibex) operating system (also applies to Kubuntu, Edubuntu and Xubuntu). The update patches six security issues (see below for details) discovered in the Linux kernel packages of Ubuntu 8.10, that could "help" a local attacker execute malicious code, causing system crashes/hangs, leading to DoS (Denial of Service) attacks. Therefore, it is strongly recommended to update your system as soon as possible!

The following Linux kernel vulnerabilities have been fixed:

1. The ATM subsystem failed to manage socket counts. Because of this, a local attacker could hang the vulnerable system, leading to a DoS (Denial of Service) attack. This issue was discovered by Hugo Dias.

2. The inotify subsystem included watch removal race conditions. Because of this, a local attacker could hang the vulnerable system, leading to a DoS (Denial of Service) attack.

3. sendmsg failed to release the allocated memory, in some cases. Because of this, a local attacker could force a vulnerable system to run out of free memory, leading to a DoS (Denial of Service) attack. This issue was discovered by Dann Frazier.

4. PA-RISC stack unwinding was incorrectly handled. Because of this, a local attacker could crash the vulnerable system, leading to a DoS (Denial of Service) attack. This issue was discovered by Helge Deller.

5. The ATA subsystem failed to set timeouts. Because of this, a local attacker could hang the vulnerable system, leading to a DoS (Denial of Service) attack.

6. The ib700 watchdog timer was incorrectly checking the buffer sizes. Because of this, a local attacker could crash the vulnerable system by sending specially crafted ioctl to the device, leading to a DoS (Denial of Service) attack.

These Linux kernel vulnerabilities can be fixed if you update your system to the following specific packages:

linux-image-2.6.27-11-generic 2.6.27-11.27
linux-image-2.6.27-11-server 2.6.27-11.27
linux-image-2.6.27-11-virtual 2.6.27-11.27


Don't forget to reboot your computer after this update! You can verify the kernel version by typing the sudo dpkg -l linux-image-2.6.27-11-generic command in a terminal.

ATTENTION:
Due to an unavoidable ABI change, the kernel packages have a new version number, which will force you to reinstall or recompile all third-party kernel modules you might have installed. For example, after the upgrade to the above version of your kernel package, a software such as VirtualBox will NOT work anymore, therefore you must recompile its kernel module by issuing a specific command (sudo /etc/init.d/vboxdrv setup) in the terminal.

Get the latest version of Ubuntu right now from Softpedia. Don't forget to share it with your friends and family.

TELL US WHAT YOU THINK:

7,479 hits · 10 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Latest ATI Linux Video Driver Introduces Full OpenGL 3.0 Support

Available Now: KNOPPIX 6.0.0

KDE 4.2 Released

Clonezilla Live 1.2.1-37 Improves Microsoft Windows Cloning

Parted Magic 3.5 Has EXT4 Support

READER COMMENTS:


Comment #1 by: Carl on 30 Jan 2009, 10:42 UTC reply to this comment

"On October 29th the Ubuntu developers announced the..."

Actually it's January :D

Comment #1.1 by: Marius Nestor on 30 Jan 2009, 10:56 GMT

Fixed.. thanks :)


Comment #2 by: Oleg on 30 Jan 2009, 21:35 UTC reply to this comment

This update broke my Ubuntu :(

Comment #2.1 by: Marius Nestor on 31 Jan 2009, 13:32 GMT

Sorry to hear that... We've updated four Ubuntu machines, here at Softpedia, and everything is fine. Can you tell us what exactly did "broke" in your Ubuntu?


Comment #3 by: robert parks on 31 Jan 2009, 23:55 UTC reply to this comment

Kernel 2.6.27-11 broke Ubuntu's support for my Verizon Wireless UTStarcom UM150 VE mobile broadband adapter.


Comment #4 by: Chuck on 01 Feb 2009, 02:25 UTC reply to this comment

It broke my Ubuntu also.
Both Wireless and Auto Etho went after installing update.


Comment #5 by: utkarsh on 01 Feb 2009, 15:22 UTC reply to this comment

My ubuntu is getting freezed/hanged frequently. Will this update solve this issue.


Comment #6 by: shehab on 07 Feb 2009, 01:10 UTC reply to this comment

after updating my ubuntu lost sound and network configurations completely


Comment #7 by: cobra146 on 21 Feb 2009, 16:43 UTC reply to this comment

Ubuntu also broke my broadcom wireless on acer 4520.. no longer picks up driver for it .. had older kernel on machine with no problems


Comment #8 by: alawey on 31 Jul 2009, 08:02 UTC reply to this comment

thank you

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM