[USN-662-1] Linux kernel vulnerabilities
Date: Wed, 5 Nov 2008 01:52:53 -0800
From: Kees Cook <kees@ubuntu.com.>
To: [email protected]
Subject: [USN-662-1] Linux kernel vulnerabilities
Message-ID: <20081105095253.GO9448@outflux.net.>
MIME-Version: 1.0
Content-Type: multipart/signed; micalg=pgp-sha1;
protocol="application/pgp-signature"; boundary="t4apE7yKrX2dGgJC"
Content-Disposition: inline
Organization: Ubuntu
X-MIMEDefang-Filter: outflux$Revision: 1.316 $
X-HELO: www.outflux.net
X-Scanned-By: MIMEDefang 2.63 on 10.2.0.1
X-Virus-Scanned: antivirus-gw at tyumen.ru
--t4apE7yKrX2dGgJC
Content-Type: text/plain; charset=us-ascii
Content-Disposition: inline
Ubuntu Security Notice USN-662-1 November 05, 2008
linux vulnerability
CVE-2008-3528, CVE-2008-4395
A security issue affects the following Ubuntu releases:
Ubuntu 8.10
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package versions:
Ubuntu 8.10:
linux-image-2.6.27-7-generic 2.6.27-7.16
linux-image-2.6.27-7-server 2.6.27-7.16
linux-image-2.6.27-7-virtual 2.6.27-7.16
After a standard system upgrade you need to reboot your computer to
effect the necessary changes.
Details follow:
It was discovered that the Linux kernel could be made to hang temporarily
when mounting corrupted ext2/3 filesystems. If a user were tricked into
mounting a specially crafted filesystem, a remote attacker could cause
system hangs, leading to a denial of service. (CVE-2008-3528)
Anders Kaseorg discovered that ndiswrapper did not correctly handle long
ESSIDs. For a system using ndiswrapper, a physically near-by attacker
could generate specially crafted wireless network traffic and execute
arbitrary code with root privileges. (CVE-2008-4395)
Updated packages for Ubuntu 8.10:
Source archives:
http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux_2.6.27-7.16.diff.gz
Size/MD5: 2863888 b1052e6aee92d46c4145620b1b8e65ee
http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux_2.6.27-7.16.dsc
Size/MD5: 1513 28e5b4d99b4ff47bdd31a7c7c125c3d0
http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux_2.6.27.orig.tar.gz
Size/MD5: 63721466 482b04f680ce6676114ccfaaf8f66a55
Architecture independent packages:
http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-doc-2.6.27_2.6.27-7.16_all.deb
Size/MD5: 3469330 aa00f7f555299257767ee8bf5d2bd08f
http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-headers-2.6.27-7_2.6.27-7.16_all.deb
Size/MD5: 5770686 3f4d5517ab70ac57766244843b06bc24
http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-source-2.6.27_2.6.27-7.16_all.deb
Size/MD5: 51951896 db1f17d562bb0c31e5fd2839dd5538a1
amd64 architecture (Athlon64, Opteron, EM64T Xeon):
http://security.ubuntu.com/ubuntu/pool/main/l/linux/acpi-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 36502 7aaa51517f74f727cd9b247ad3bdf241
http://security.ubuntu.com/ubuntu/pool/main/l/linux/block-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 263916 ffd1d0223f84312694b853ddcc3f6f2a
http://security.ubuntu.com/ubuntu/pool/main/l/linux/crypto-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 53480 736c4c1f8c1b69408dcef471031af2c1
http://security.ubuntu.com/ubuntu/pool/main/l/linux/fat-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 43114 86d52a39e37574f906424b6bcfb9132e
http://security.ubuntu.com/ubuntu/pool/main/l/linux/fb-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 52364 9e6193a120fd97f0f22eda94ca65d49b
http://security.ubuntu.com/ubuntu/pool/main/l/linux/firewire-core-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 89712 75b58dda7c91a14f102dd513a9884b91
http://security.ubuntu.com/ubuntu/pool/main/l/linux/floppy-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 38126 107bd036a86295b765b865b592cae856
http://security.ubuntu.com/ubuntu/pool/main/l/linux/fs-core-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 676982 b162978a3b55d0a7f3682ea28c23e2b2
http://security.ubuntu.com/ubuntu/pool/main/l/linux/fs-secondary-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 158454 aaf6ae3e6d430f7e06f71b398e2a7433
http://security.ubuntu.com/ubuntu/pool/main/l/linux/input-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 46404 52491f24cdfee2795758dd28ab1a8583
http://security.ubuntu.com/ubuntu/pool/main/l/linux/ipv6-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 154016 054373c25e230ae6d2d7de5026c78aa8
http://security.ubuntu.com/ubuntu/pool/main/l/linux/irda-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 312610 033df8299f5c265367ea295c83165e3b
http://security.ubuntu.com/ubuntu/pool/main/l/linux/kernel-image-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 2596386 37ee7ec2a1d488e6f6de8f34176987f4
http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-headers-2.6.27-7-generic_2.6.27-7.16_amd64.deb
Size/MD5: 639082 ed8f3a70d90f169d172c6e173e0b6b1b
http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-headers-2.6.27-7-server_2.6.27-7.16_amd64.deb
Size/MD5: 638916 ffae21ca3ebd4400d503913ea9f08a77
http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-image-2.6.27-7-generic_2.6.27-7.16_amd64.deb
Size/MD5: 23022032 fd3e4e8ab005389ec0cc615cea22874d
http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-image-2.6.27-7-server_2.6.27-7.16_amd64.deb
Size/MD5: 23010520 0b171157949ada26b8ba89d8e67ddc0e
http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-image-2.6.27-7-virtual_2.6.27-7.16_amd64.deb
Size/MD5: 10436412 530186b8d1d7dc10e507e6bc452403ab
http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-libc-dev_2.6.27-7.16_amd64.deb
Size/MD5: 653232 f48b15dbf0ba532ccb97e22a7d3b4627
http://security.ubuntu.com/ubuntu/pool/main/l/linux/md-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 434628 bc318d4de2651e91305548666dead618
http://security.ubuntu.com/ubuntu/pool/main/l/linux/message-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 186306 c3ca7cc803a73d5aca4e0c80464d8274
http://security.ubuntu.com/ubuntu/pool/main/l/linux/nfs-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 275524 899bdf5de6963962c89b691eb26cd28d
http://security.ubuntu.com/ubuntu/pool/main/l/linux/nic-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 1743146 5d9c0145c50ab7e0c51fbc0cef950834
http://security.ubuntu.com/ubuntu/pool/main/l/linux/nic-pcmcia-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 151282 c02d1b6ef56dc28403beadad2bf88309
http://security.ubuntu.com/ubuntu/pool/main/l/linux/nic-shared-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 194184 66a2c1f8320659b94f6b90f119a9c964
http://security.ubuntu.com/ubuntu/pool/main/l/linux/nic-usb-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 167964 df927206736f4f2a8a7be1e7f013194f
http://security.ubuntu.com/ubuntu/pool/main/l/linux/parport-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 36454 e7312f2e6286590c1dbcbe5e7de35eeb
http://security.ubuntu.com/ubuntu/pool/main/l/linux/pata-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 83384 5d38ea1f3a73bad990ed52f66c7a7a28
http://security.ubuntu.com/ubuntu/pool/main/l/linux/pcmcia-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 71938 087964f10e908341f287ccea80e27008
http://security.ubuntu.com/ubuntu/pool/main/l/linux/pcmcia-storage-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 23244 643c72067e2cb27c1ec228fc8d57e217
http://security.ubuntu.com/ubuntu/pool/main/l/linux/plip-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 9012 360892e9ef95ab6bd1dc90bb9e08249d
http://security.ubuntu.com/ubuntu/pool/main/l/linux/ppp-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 68450 67e964ac3d95c5f4a1b12e6b271de74a
http://security.ubuntu.com/ubuntu/pool/main/l/linux/sata-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 110228 e18c86fcc58d390c4d2ad0e58fcb16a9
http://security.ubuntu.com/ubuntu/pool/main/l/linux/scsi-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 1275798 5242af32c6a8a1e38f31e7d8d8857644
http://security.ubuntu.com/ubuntu/pool/main/l/linux/serial-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 47570 f8e459e40f399d1f966111122344504b
http://security.ubuntu.com/ubuntu/pool/main/l/linux/socket-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 13312 03eb83515fc5d90aeb272c540e165c6f
http://security.ubuntu.com/ubuntu/pool/main/l/linux/storage-core-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 391200 b7c4499c38f44e23908ef0fb63bdca45
http://security.ubuntu.com/ubuntu/pool/main/l/linux/usb-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 198786 770b109f3971e9718fbeb2cc5f05c35d
http://security.ubuntu.com/ubuntu/pool/main/l/linux/virtio-modules-2.6.27-7-generic-di_2.6.27-7.16_amd64.udeb
Size/MD5: 13578 dba0b8949f78e43c90545b7fd092c7b6
i386 architecture (x86 compatible Intel/AMD):
http://security.ubuntu.com/ubuntu/pool/main/l/linux/acpi-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 33934 cfb49d89dd70429f2b730c7a2e8964b8
http://security.ubuntu.com/ubuntu/pool/main/l/linux/block-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 244326 f8aedcc6ff1c95f0bacd870628bd34bd
http://security.ubuntu.com/ubuntu/pool/main/l/linux/crypto-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 55394 ee8205b481dd6112058349957db14aa6
http://security.ubuntu.com/ubuntu/pool/main/l/linux/fat-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 41252 54cf9023f441a0699b3b380de4058160
http://security.ubuntu.com/ubuntu/pool/main/l/linux/fb-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 48696 2e10bdbbd0be743e553bfd937ba44d9a
http://security.ubuntu.com/ubuntu/pool/main/l/linux/firewire-core-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 86902 f5ed38f167db71b3601d1811a8b45a17
http://security.ubuntu.com/ubuntu/pool/main/l/linux/floppy-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 33940 2e90360f4470554283ebd7670cad3a57
http://security.ubuntu.com/ubuntu/pool/main/l/linux/fs-core-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 674272 22f6dcac8dce84d5163d062bdf09460f
http://security.ubuntu.com/ubuntu/pool/main/l/linux/fs-secondary-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 158080 80298237cf5abe9f179750748d4858f4
http://security.ubuntu.com/ubuntu/pool/main/l/linux/input-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 43708 d3135a501ea45cf5e18576c92cee7759
http://security.ubuntu.com/ubuntu/pool/main/l/linux/ipv6-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 144930 abadde5392b98fcdb9d7ce8fa508f746
http://security.ubuntu.com/ubuntu/pool/main/l/linux/irda-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 301938 1f69318efc172f2bdab1ca436471ea48
http://security.ubuntu.com/ubuntu/pool/main/l/linux/kernel-image-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 2427088 0e03f701335f5379361ce51bec448626
http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-headers-2.6.27-7-generic_2.6.27-7.16_i386.deb
Size/MD5: 620778 7228c2aa323fcf657c4d69263ea1821a
http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-headers-2.6.27-7-server_2.6.27-7.16_i386.deb
Size/MD5: 622006 75832cee4f8b79b1add067a274885c04
http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-image-2.6.27-7-generic_2.6.27-7.16_i386.deb
Size/MD5: 23398356 d5209ae17503b72ba9024f6ae5ba2a05
http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-image-2.6.27-7-server_2.6.27-7.16_i386.deb
Size/MD5: 23535584 4af9bab584739538dcb962c208cdd31d
http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-image-2.6.27-7-virtual_2.6.27-7.16_i386.deb
Size/MD5: 10068962 55196eb464330b1376db54f0a93b9a04
http://security.ubuntu.com/ubuntu/pool/main/l/linux/linux-libc-dev_2.6.27-7.16_i386.deb
Size/MD5: 653202 18623f809fe95a1fce18d03b727d2f72
http://security.ubuntu.com/ubuntu/pool/main/l/linux/md-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 432650 7102e7cd30bddcc5c64c9949a3b00fc9
http://security.ubuntu.com/ubuntu/pool/main/l/linux/message-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 170996 d1b2396fefe97dd11b56d0ab9b6bc8ef
http://security.ubuntu.com/ubuntu/pool/main/l/linux/nfs-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 263918 70f6f3a4c7d11b3dc83e0ea3892a3b4c
http://security.ubuntu.com/ubuntu/pool/main/l/linux/nic-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 1929778 484509b351a85edca959c0308251633e
http://security.ubuntu.com/ubuntu/pool/main/l/linux/nic-pcmcia-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 150870 2ffdb3d3586d260c172a4c2a10704d6d
http://security.ubuntu.com/ubuntu/pool/main/l/linux/nic-shared-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 183920 b2b6944a79df8f5cfea8e864faff1a73
http://security.ubuntu.com/ubuntu/pool/main/l/linux/nic-usb-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 157516 88a61734f85432779c5437a3256aff7c
http://security.ubuntu.com/ubuntu/pool/main/l/linux/parport-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 34460 4a5bb06da997b163eabe8d2506276067
http://security.ubuntu.com/ubuntu/pool/main/l/linux/pata-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 78194 e70a5b2735f1565acfd0dccdd42e02f9
http://security.ubuntu.com/ubuntu/pool/main/l/linux/pcmcia-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 86118 2e8ca4c040d8c6f4a51f2064133b8d61
http://security.ubuntu.com/ubuntu/pool/main/l/linux/pcmcia-storage-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 51170 c9fa04db1560010ef4c393a5a1e0ef08
http://security.ubuntu.com/ubuntu/pool/main/l/linux/plip-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 8792 4e53440551c157be34f48106cfccca38
http://security.ubuntu.com/ubuntu/pool/main/l/linux/ppp-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 64160 79f8e7c6a08ce1882215735cfd1846ee
http://security.ubuntu.com/ubuntu/pool/main/l/linux/sata-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 101660 b3b6d533bbd7d88cf9bcad3cdc2dd8c8
http://security.ubuntu.com/ubuntu/pool/main/l/linux/scsi-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 1448942 8b58e86b771357133c686be093ec88e5
http://security.ubuntu.com/ubuntu/pool/main/l/linux/serial-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 44504 9a83fcd3376f36a861c5d82f894e1041
http://security.ubuntu.com/ubuntu/pool/main/l/linux/socket-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 12466 26fb29b1db43062d593f44bb69865785
http://security.ubuntu.com/ubuntu/pool/main/l/linux/storage-core-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 370290 db295ecbc011997bb66d83c69006a1c1
http://security.ubuntu.com/ubuntu/pool/main/l/linux/usb-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 187670 8ef20029cc61364b9df6c182da1dd8b8
http://security.ubuntu.com/ubuntu/pool/main/l/linux/virtio-modules-2.6.27-7-generic-di_2.6.27-7.16_i386.udeb
Size/MD5: 12974 087166c052778fbe0c10e72cc9b3ffe8
--t4apE7yKrX2dGgJC
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: Digital signature
Content-Disposition: inline
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.9 (GNU/Linux)
Comment: Kees Cook <kees@outflux.net.>
iEYEARECAAYFAkkRbPUACgkQH/9LqRcGPm3QqwCcCbS8pMqZEfrygAwBcY/gfB3b
C68AoJZwv17GiC5mCOyqcrymG3q1GdiH
=4w0w
-----END PGP SIGNATURE-----
--t4apE7yKrX2dGgJC--