[Ksplice][Ubuntu-13.10-Updates] New updates available via Ksplice (USN-2096-1)
Oracle Ksplice
ksplice-support_ww at oracle.com
Fri Jan 31 06:24:34 PST 2014
Synopsis: USN-2096-1 can now be patched using Ksplice
CVEs: CVE-2014-0038
Systems running Ubuntu 13.10 Saucy can now use Ksplice to patch
against the latest Ubuntu Security Notice, USN-2096-1.
INSTALLING THE UPDATES
We recommend that all users of Ksplice Uptrack on Ubuntu 13.10 Saucy
install these updates.
On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.
Alternatively, you can install these updates by running:
# /usr/sbin/uptrack-upgrade -y
DESCRIPTION
* CVE-2014-0038: Privilege escalation in X32 recvmmsg.
Missing pointer validation in the X32 ABI compatible version of the recvmmsg(2)
syscall allows users to write arbitrary data to arbitrary kernel memory. This allows
an unprivileged user to gain kernel code execution.
SUPPORT
Ksplice support is available at ksplice-support_ww at oracle.com.
More information about the Ksplice-Ubuntu-13.10-Updates
mailing list