Mohamed Ghannam discovered that the IPv4 raw socket implementation in the Linux kernel contained a race condition leading to uninitialized pointer usage. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2017-17712)
Laurent Guerby discovered that the mbcache feature in the ext2 and ext4 filesystems in the Linux kernel improperly handled xattr block caching. A local attacker could use this to cause a denial of service. (CVE-2015-8952)
Vitaly Mayatskikh discovered that the SCSI subsystem in the Linux kernel did not properly track reference counts when merging buffers. A local attacker could use this to cause a denial of service (memory exhaustion). (CVE-2017-12190)
ChunYu Wang discovered that a use-after-free vulnerability existed in the SCTP protocol implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code, (CVE-2017-15115)
Mohamed Ghannam discovered a use-after-free vulnerability in the DCCP protocol implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2017-8824)
USN-3540-1 mitigated CVE-2017-5715 (Spectre Variant 2) for the amd64 architecture in Ubuntu 16.04 LTS. This update provides the compiler-based retpoline kernel mitigation for the amd64 and i386 architectures. Original advisory details:
Jann Horn discovered that microprocessors utilizing speculative execution and branch prediction may allow unauthorized memory reads via sidechannel attacks. This flaw is known as Spectre. A local attacker could use this to expose sensitive information, including kernel memory. (CVE-2017-5715)
{ "availability": "No subscription required", "binaries": [ { "ipmi-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "pata-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "linux-cloud-tools-4.4.0-116": "4.4.0-116.140", "md-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "virtio-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "speakup-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "linux-source-4.4.0": "4.4.0-116.140", "irda-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "ppp-modules-4.4.0-116-generic-di": "4.4.0-116.140", "speakup-modules-4.4.0-116-generic-di": "4.4.0-116.140", "fs-core-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "ppp-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "linux-image-4.4.0-116-lowlatency": "4.4.0-116.140", "firewire-core-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "linux-cloud-tools-4.4.0-116-generic": "4.4.0-116.140", "usb-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "kernel-image-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "parport-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "serial-modules-4.4.0-116-generic-di": "4.4.0-116.140", "md-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "linux-image-4.4.0-116-powerpc64-smp": "4.4.0-116.140", "linux-tools-4.4.0-116-powerpc64-smp": "4.4.0-116.140", "linux-headers-4.4.0-116": "4.4.0-116.140", "crypto-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "input-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "pcmcia-modules-4.4.0-116-generic-di": "4.4.0-116.140", "ppp-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "linux-tools-4.4.0-116-powerpc-smp": "4.4.0-116.140", "sata-modules-4.4.0-116-generic-di": "4.4.0-116.140", "virtio-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "input-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "ipmi-modules-4.4.0-116-generic-di": "4.4.0-116.140", "linux-tools-4.4.0-116-generic-lpae": "4.4.0-116.140", "vlan-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "multipath-modules-4.4.0-116-generic-di": "4.4.0-116.140", "usb-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "linux-headers-4.4.0-116-powerpc-e500mc": "4.4.0-116.140", "firewire-core-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "crypto-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "storage-core-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "plip-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "vlan-modules-4.4.0-116-generic-di": "4.4.0-116.140", "kernel-image-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "fs-core-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "nic-modules-4.4.0-116-generic-di": "4.4.0-116.140", "parport-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "input-modules-4.4.0-116-generic-di": "4.4.0-116.140", "nic-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "irda-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "nic-pcmcia-modules-4.4.0-116-generic-di": "4.4.0-116.140", "crypto-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "md-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "linux-tools-4.4.0-116": "4.4.0-116.140", "linux-cloud-tools-common": "4.4.0-116.140", "scsi-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "linux-image-4.4.0-116-powerpc-e500mc-dbgsym": "4.4.0-116.140", "plip-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "linux-libc-dev": "4.4.0-116.140", "crypto-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "speakup-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "fat-modules-4.4.0-116-generic-di": "4.4.0-116.140", "input-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "kernel-image-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "fs-secondary-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "fb-modules-4.4.0-116-generic-di": "4.4.0-116.140", "linux-tools-4.4.0-116-lowlatency": "4.4.0-116.140", "nfs-modules-4.4.0-116-generic-di": "4.4.0-116.140", "block-modules-4.4.0-116-generic-di": "4.4.0-116.140", "vlan-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "linux-image-4.4.0-116-powerpc64-smp-dbgsym": "4.4.0-116.140", "storage-core-modules-4.4.0-116-generic-di": "4.4.0-116.140", "linux-image-4.4.0-116-powerpc64-emb-dbgsym": "4.4.0-116.140", "linux-udebs-powerpc-smp": "4.4.0-116.140", "pcmcia-storage-modules-4.4.0-116-generic-di": "4.4.0-116.140", "message-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "multipath-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "fs-core-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "scsi-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "dasd-extra-modules-4.4.0-116-generic-di": "4.4.0-116.140", "nic-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "pata-modules-4.4.0-116-generic-di": "4.4.0-116.140", "parport-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "nic-shared-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "irda-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "nic-shared-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "storage-core-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "linux-headers-4.4.0-116-lowlatency": "4.4.0-116.140", "usb-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "block-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "fat-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "nic-usb-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "sata-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "fs-secondary-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "linux-tools-common": "4.4.0-116.140", "nic-usb-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "sata-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "input-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "linux-cloud-tools-4.4.0-116-dbgsym": "4.4.0-116.140", "nfs-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "ipmi-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "linux-tools-4.4.0-116-powerpc-e500mc": "4.4.0-116.140", "linux-image-4.4.0-116-powerpc64-emb": "4.4.0-116.140", "storage-core-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "fat-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "nfs-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "floppy-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "linux-headers-4.4.0-116-powerpc-smp": "4.4.0-116.140", "plip-modules-4.4.0-116-generic-di": "4.4.0-116.140", "fat-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "vlan-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "linux-image-4.4.0-116-generic": "4.4.0-116.140", "plip-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "parport-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "ppp-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "nic-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "fs-core-modules-4.4.0-116-generic-di": "4.4.0-116.140", "linux-tools-4.4.0-116-dbgsym": "4.4.0-116.140", "floppy-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "linux-udebs-generic": "4.4.0-116.140", "scsi-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "multipath-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "block-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "pata-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "firewire-core-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "fs-secondary-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "nic-usb-modules-4.4.0-116-generic-di": "4.4.0-116.140", "linux-udebs-powerpc-e500mc": "4.4.0-116.140", "linux-headers-4.4.0-116-powerpc64-emb": "4.4.0-116.140", "linux-image-4.4.0-116-powerpc-smp-dbgsym": "4.4.0-116.140", "md-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "linux-udebs-powerpc64-smp": "4.4.0-116.140", "linux-headers-4.4.0-116-powerpc64-smp": "4.4.0-116.140", "mouse-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "linux-tools-4.4.0-116-generic": "4.4.0-116.140", "ipmi-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "mouse-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "message-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "vlan-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "nic-usb-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "linux-image-4.4.0-116-lowlatency-dbgsym": "4.4.0-116.140", "nic-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "usb-modules-4.4.0-116-generic-di": "4.4.0-116.140", "linux-image-4.4.0-116-generic-dbgsym": "4.4.0-116.140", "mouse-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "sata-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "kernel-image-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "linux-cloud-tools-4.4.0-116-lowlatency": "4.4.0-116.140", "fat-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "scsi-modules-4.4.0-116-generic-di": "4.4.0-116.140", "scsi-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "linux-headers-4.4.0-116-generic": "4.4.0-116.140", "block-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "message-modules-4.4.0-116-generic-di": "4.4.0-116.140", "sata-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "mouse-modules-4.4.0-116-generic-di": "4.4.0-116.140", "speakup-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "linux-image-4.4.0-116-powerpc-e500mc": "4.4.0-116.140", "nic-shared-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "multipath-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "fs-secondary-modules-4.4.0-116-generic-di": "4.4.0-116.140", "linux-doc": "4.4.0-116.140", "md-modules-4.4.0-116-generic-di": "4.4.0-116.140", "linux-image-4.4.0-116-generic-lpae": "4.4.0-116.140", "message-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "linux-tools-4.4.0-116-powerpc64-emb": "4.4.0-116.140", "irda-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "linux-image-extra-4.4.0-116-generic": "4.4.0-116.140", "dasd-modules-4.4.0-116-generic-di": "4.4.0-116.140", "mouse-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "ipmi-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "crypto-modules-4.4.0-116-generic-di": "4.4.0-116.140", "virtio-modules-4.4.0-116-generic-di": "4.4.0-116.140", "firewire-core-modules-4.4.0-116-generic-di": "4.4.0-116.140", "virtio-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "nic-shared-modules-4.4.0-116-generic-di": "4.4.0-116.140", "kernel-image-4.4.0-116-generic-di": "4.4.0-116.140", "storage-core-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "nic-usb-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "nic-shared-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "nfs-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "fs-secondary-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "linux-udebs-generic-lpae": "4.4.0-116.140", "multipath-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "floppy-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "floppy-modules-4.4.0-116-generic-di": "4.4.0-116.140", "block-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "irda-modules-4.4.0-116-generic-di": "4.4.0-116.140", "linux-image-4.4.0-116-generic-lpae-dbgsym": "4.4.0-116.140", "speakup-modules-4.4.0-116-generic-lpae-di": "4.4.0-116.140", "plip-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "linux-headers-4.4.0-116-generic-lpae": "4.4.0-116.140", "parport-modules-4.4.0-116-generic-di": "4.4.0-116.140", "usb-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "pata-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "ppp-modules-4.4.0-116-powerpc64-smp-di": "4.4.0-116.140", "fs-core-modules-4.4.0-116-powerpc-e500mc-di": "4.4.0-116.140", "nfs-modules-4.4.0-116-powerpc-smp-di": "4.4.0-116.140", "linux-image-4.4.0-116-powerpc-smp": "4.4.0-116.140" } ] }
{ "availability": "No subscription required", "binaries": [ { "linux-image-4.4.0-1052-aws": "4.4.0-1052.61", "linux-image-4.4.0-1052-aws-dbgsym": "4.4.0-1052.61", "linux-aws-tools-4.4.0-1052": "4.4.0-1052.61", "linux-aws-cloud-tools-4.4.0-1052-dbgsym": "4.4.0-1052.61", "linux-aws-cloud-tools-4.4.0-1052": "4.4.0-1052.61", "linux-tools-4.4.0-1052-aws": "4.4.0-1052.61", "linux-headers-4.4.0-1052-aws": "4.4.0-1052.61", "linux-cloud-tools-4.4.0-1052-aws": "4.4.0-1052.61", "linux-aws-headers-4.4.0-1052": "4.4.0-1052.61", "linux-aws-tools-4.4.0-1052-dbgsym": "4.4.0-1052.61" } ] }
{ "availability": "No subscription required", "binaries": [ { "linux-kvm-cloud-tools-4.4.0-1019-dbgsym": "4.4.0-1019.24", "linux-headers-4.4.0-1019-kvm": "4.4.0-1019.24", "linux-tools-4.4.0-1019-kvm": "4.4.0-1019.24", "linux-kvm-tools-4.4.0-1019-dbgsym": "4.4.0-1019.24", "linux-kvm-tools-4.4.0-1019": "4.4.0-1019.24", "linux-cloud-tools-4.4.0-1019-kvm": "4.4.0-1019.24", "linux-image-4.4.0-1019-kvm": "4.4.0-1019.24", "linux-kvm-headers-4.4.0-1019": "4.4.0-1019.24", "linux-image-4.4.0-1019-kvm-dbgsym": "4.4.0-1019.24", "linux-kvm-cloud-tools-4.4.0-1019": "4.4.0-1019.24" } ] }
{ "availability": "No subscription required", "binaries": [ { "linux-image-4.4.0-1085-raspi2": "4.4.0-1085.93", "linux-tools-4.4.0-1085-raspi2": "4.4.0-1085.93", "linux-raspi2-headers-4.4.0-1085": "4.4.0-1085.93", "linux-raspi2-tools-4.4.0-1085-dbgsym": "4.4.0-1085.93", "linux-image-4.4.0-1085-raspi2-dbgsym": "4.4.0-1085.93", "linux-raspi2-tools-4.4.0-1085": "4.4.0-1085.93", "linux-headers-4.4.0-1085-raspi2": "4.4.0-1085.93" } ] }
{ "availability": "No subscription required", "binaries": [ { "linux-snapdragon-headers-4.4.0-1087": "4.4.0-1087.92", "linux-snapdragon-tools-4.4.0-1087": "4.4.0-1087.92", "linux-image-4.4.0-1087-snapdragon": "4.4.0-1087.92", "linux-snapdragon-tools-4.4.0-1087-dbgsym": "4.4.0-1087.92", "linux-headers-4.4.0-1087-snapdragon": "4.4.0-1087.92", "linux-image-4.4.0-1087-snapdragon-dbgsym": "4.4.0-1087.92", "linux-tools-4.4.0-1087-snapdragon": "4.4.0-1087.92" } ] }