Security vulnerability: update kernel packages on Ubuntu slaves (USN-2800-1 and related)

Bug #1514759 reported by Adam Heczko
264
This bug affects 1 person
Affects Status Importance Assigned to Milestone
Mirantis OpenStack
Invalid
High
MOS Linux
5.1.x
Won't Fix
High
MOS Maintenance
6.0.x
Won't Fix
High
MOS Maintenance
6.1.x
Won't Fix
High
MOS Maintenance
7.0.x
Invalid
High
MOS Maintenance
8.0.x
Invalid
High
MOS Linux

Bug Description

Problem description:
Ubuntu updated Linux 3.13 kernel packages for 14.04 and 12.04 LTS editions to mitigate DOS vulnerability in KVM.

Ben Serebrin discovered that the KVM hypervisor implementation in the Linux
kernel did not properly catch Alignment Check exceptions. An attacker in a
guest virtual machine could use this to cause a denial of service (system
crash) in the host OS.

Solution proposal:
Recompile and publish updated Linux kernel packages.

Upstream bug reports:
Ubuntu 14.04: http://www.ubuntu.com/usn/usn-2801-1/
Ubuntu 12.04 HWE: http://www.ubuntu.com/usn/usn-2804-1/

CVE References

Revision history for this message
Aleksander Mogylchenko (amogylchenko) wrote :

All updates will be consumed from Ubuntu.

Revision history for this message
Vitaly Sedelnik (vsedelnik) wrote :

Invalid for 7.0, Confirmed for 6.1, 6.0 and 5.1.1

Revision history for this message
Vitaly Sedelnik (vsedelnik) wrote :

Reassigned to -updates milestones for consideration. Kernel update affectes the whole thing - so adding this to updates requires complete acceptance cycle.

Revision history for this message
Alexey Stupnikov (astupnikov) wrote :

MOS5.1 and MOS6.0 are no longer supported, moving to Won't Fix.

Revision history for this message
Alexey Stupnikov (astupnikov) wrote :

We no longer support MOS5.1, MOS6.0, MOS6.1
We deliver only Critical/Security fixes to MOS7.0, MOS8.0.
We deliver only High/Critical/Security fixes to MOS9.2.

To post a comment you must log in.
This report contains Public Security information  
Everyone can see this security related information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.