Errata overview
Errata ID 243
Date 2014-12-03
Source package univention-kernel-image
Fixed in version 7.0.0-16.67.201412010901
Description
The Linux kernel in Univention Corporate Server 3.2 has been updated to 
3.10.61. This provides many bugfixes and also addresses the following 
security vulnerabilities:
* Information leak in vhost-net zerocopy support (CVE-2014-0131)
* Information leak in skb_zerocopy (CVE-2014-2568)
* Denial of service in memory management (CVE-2014-4171)
* Denial of service in SCTP (CVE-2014-4667)
* Denial of service in isofs (CVE-2014-5471, CVE-2014-5472)
* Denial of service in KVM (CVE-2014-3601)
* Denial of service in SCTP (CVE-2014-5077)
* Denial of service in the ceph cluster filesystem (CVE-2014-6416, 
  CVE-2014-6417,CVE-2014-6418)
* Privilege escalation in special HID drivers (CVE-2014-3181, 
  CVE-2014-3182, CVE-2014-3183, CVE-2014-3184, CVE-2014-3185, 
  CVE-2014-3186)
* Denial of service in CIFS (CVE-2014-7145)
* Denial of service in XFS (CVE-2014-7283)
* Denial of service in the UDF filesystem (CVE-2014-6410)
* Denial of service in the VFS layer when dealing with user namespaces
  (CVE-2014-7970, CVE-2014-7975)
* Three denial of service vulnerabilities in SCTP (CVE-2014-3673, 
  CVE-2014-3687, CVE-2014-3688)
* Race condition in PIT handler in KVM (CVE-2014-3611)
* Denial of service in handling on MSR registers in KVM (CVE-2014-3610)
* Local denial of service in syscall perf profiling (CVE-2014-7825)
* Privilege escalation in ftrace syscall tracing (CVE-2014-7826)
* Denial of service in SCTP (CVE-2014-7841)
* Buffer overflow in ttusb-dec (CVE-2014-8884)
In addition a bug in ACL handling when using NFS file shares has been fixed.
Additional notes This is the second part of the fix, which updates the meta package.
CVE ID CVE-2014-0131
CVE-2014-2568
CVE-2014-4171
CVE-2014-4667
CVE-2014-5471
CVE-2014-5472
CVE-2014-3601
CVE-2014-5077
CVE-2014-6416
CVE-2014-6417
CVE-2014-6418
CVE-2014-3181
CVE-2014-3182
CVE-2014-3183
CVE-2014-3184
CVE-2014-3185
CVE-2014-3186
CVE-2014-7145
CVE-2014-7283
CVE-2014-6410
CVE-2014-7970
CVE-2014-7975
CVE-2014-3673
CVE-2014-3687
CVE-2014-3688
CVE-2014-3611
CVE-2014-3610
CVE-2014-7825
CVE-2014-7826
CVE-2014-7841
CVE-2014-8884
UCS Bug number #35397
#36990