Errata overview
Errata ID 242
Date 2014-12-03
Source package linux
Fixed in version 3.10.11-1.107.201411281532
Description
The Linux kernel in Univention Corporate Server 3.2 has been updated to 
3.10.61. This provides many bugfixes and also addresses the following 
security vulnerabilities:
* Information leak in vhost-net zerocopy support (CVE-2014-0131)
* Information leak in skb_zerocopy (CVE-2014-2568)
* Denial of service in memory management (CVE-2014-4171)
* Denial of service in SCTP (CVE-2014-4667)
* Denial of service in isofs (CVE-2014-5471, CVE-2014-5472)
* Denial of service in KVM (CVE-2014-3601)
* Denial of service in SCTP (CVE-2014-5077)
* Denial of service in the ceph cluster filesystem (CVE-2014-6416, 
  CVE-2014-6417,CVE-2014-6418)
* Privilege escalation in special HID drivers (CVE-2014-3181, 
  CVE-2014-3182, CVE-2014-3183, CVE-2014-3184, CVE-2014-3185, 
  CVE-2014-3186)
* Denial of service in CIFS (CVE-2014-7145)
* Denial of service in XFS (CVE-2014-7283)
* Denial of service in the UDF filesystem (CVE-2014-6410)
* Denial of service in the VFS layer when dealing with user namespaces
  (CVE-2014-7970, CVE-2014-7975)
* Three denial of service vulnerabilities in SCTP (CVE-2014-3673, 
  CVE-2014-3687, CVE-2014-3688)
* Race condition in PIT handler in KVM (CVE-2014-3611)
* Denial of service in handling on MSR registers in KVM (CVE-2014-3610)
* Local denial of service in syscall perf profiling (CVE-2014-7825)
* Privilege escalation in ftrace syscall tracing (CVE-2014-7826)
* Denial of service in SCTP (CVE-2014-7841)
* Buffer overflow in ttusb-dec (CVE-2014-8884)
In addition a bug in ACL handling when using NFS file shares has been fixed.
Additional notes This is the first part of the fix, which provides the new kernel package.
CVE ID CVE-2014-0131
CVE-2014-2568
CVE-2014-4171
CVE-2014-4667
CVE-2014-5471
CVE-2014-5472
CVE-2014-3601
CVE-2014-5077
CVE-2014-6416
CVE-2014-6417
CVE-2014-6418
CVE-2014-3181
CVE-2014-3182
CVE-2014-3183
CVE-2014-3184
CVE-2014-3185
CVE-2014-3186
CVE-2014-7145
CVE-2014-7283
CVE-2014-6410
CVE-2014-7970
CVE-2014-7975
CVE-2014-3673
CVE-2014-3687
CVE-2014-3688
CVE-2014-3611
CVE-2014-3610
CVE-2014-7825
CVE-2014-7826
CVE-2014-7841
CVE-2014-8884
UCS Bug number #35397
#36990