---

Canonical Releases New Kernel Security Update for Ubuntu 16.10, 16.04 and 14.04

Only the kernel packages of the Ubuntu 16.04 LTS and 16.04.1 LTS releases received the most attention in this new update, addressing a stack-based buffer overflow (CVE-2017-7187) issue discovered by Dmitry Vyukov in Linux kernel’s generic SCSI (sg) subsystem, which lets local attackers that had access to an sg device to crash the affected system or execute random code. The second vulnerability (CVE-2017-7261) is a NULL pointer dereference discovered in Linux kernel’s Direct Rendering Manager (DRM) driver for VMWare devices, which could allow a local attacker to crash the system by causing a denial of service, and the third one (CVE-2017-7616) appears to be an information leak in Linux kernel’s set_mempolicy and mbind compat syscalls, allowing a local attacker to expose sensitive information from kernel memory.

Get the Free Newsletter!

Subscribe to Developer Insider for top news, trends, & analysis