From ksplice-support_ww at oracle.com Thu Apr 30 05:31:04 2015 From: ksplice-support_ww at oracle.com (Oracle Ksplice) Date: Thu, 30 Apr 2015 12:31:04 GMT Subject: [Ksplice][Ubuntu 10.04 Updates] New updates available via Ksplice (USN-2583-1) Message-ID: <201504301231.t3UCV3T6014184@aserv0021.oracle.com> Synopsis: USN-2583-1 can now be patched using Ksplice CVEs: CVE-2015-3339 Systems running Ubuntu 10.04 Lucid can now use Ksplice to patch against the latest Ubuntu Security Notice, USN-2583-1. INSTALLING THE UPDATES We recommend that all users of Ksplice Uptrack on Ubuntu 10.04 Lucid install these updates. On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf, these updates will be installed automatically and you do not need to take any action. Alternatively, you can install these updates by running: # /usr/sbin/uptrack-upgrade -y DESCRIPTION * CVE-2015-3339: Privilege escalation due to race condition between execve and chown. The execve() syscall can race with inode attribute changes made by chown(). This race condition could result in execve() setting uid/gid to the new owner, leading to privilege escalation. SUPPORT Ksplice support is available at ksplice-support_ww at oracle.com.