[Ksplice][Ubuntu-14.04-Updates] New updates available via Ksplice (USN-2848-1)

Oracle Ksplice ksplice-support_ww at oracle.com
Mon Dec 21 15:04:34 PST 2015


Synopsis: USN-2848-1 can now be patched using Ksplice

Systems running Ubuntu 14.04 Trusty can now use Ksplice to patch
against the latest Ubuntu Security Notice, USN-2848-1.

INSTALLING THE UPDATES

We recommend that all users of Ksplice Uptrack on Ubuntu 14.04 Trusty
install these updates.

On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.

Alternatively, you can install these updates by running:

# /usr/sbin/uptrack-upgrade -y


DESCRIPTION

* Privilege escalation in user-namespace switching.

Incorrect capabilities check for ptrace() could allow a privileged user
in an untrusted user-namespace to escape the namespace when a root-owned
process entered the user-namespace.

Ksplice will not be providing an update for Xen security advisories 155
and 157.  Fixing XSA-155 requires updates to the hypervisor and qemu
which are not available through Ksplice.  Xen hosts should reboot into
an updated hypervisor, qemu and kernel to protect against this issue,
and live migration may be used to avoid disruption to guests.  Systems
other than Xen Dom0s (i.e.  systems not hosting Xen virtual machines)
are not vulnerable and do not need to be rebooted in order to remain
secure.

SUPPORT

Ksplice support is available at ksplice-support_ww at oracle.com.


  



More information about the Ksplice-Ubuntu-14.04-updates mailing list