-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2016.1616
                           linux security update
                               29 June 2016

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           Linux kernel
Publisher:         Debian
Operating System:  Debian GNU/Linux 8
Impact/Access:     Root Compromise          -- Existing Account      
                   Denial of Service        -- Existing Account      
                   Access Confidential Data -- Remote/Unauthenticated
                   Reduced Security         -- Existing Account      
Resolution:        Patch/Upgrade
CVE Names:         CVE-2016-5244 CVE-2016-5243 CVE-2016-4998
                   CVE-2016-4997 CVE-2016-4913 CVE-2016-4805
                   CVE-2016-4581 CVE-2016-4580 CVE-2016-4578
                   CVE-2016-4569 CVE-2016-4565 CVE-2016-4486
                   CVE-2016-4485 CVE-2016-4482 CVE-2016-4470
                   CVE-2016-3961 CVE-2016-3955 CVE-2016-3951
                   CVE-2016-3672 CVE-2016-3157 CVE-2016-3156
                   CVE-2016-3140 CVE-2016-3138 CVE-2016-3137
                   CVE-2016-3136 CVE-2016-3134 CVE-2016-3070
                   CVE-2016-2187 CVE-2016-2186 CVE-2016-2185
                   CVE-2016-2184 CVE-2016-2143 CVE-2016-2117
                   CVE-2016-1583 CVE-2016-1237 CVE-2016-0821
                   CVE-2015-7515  

Reference:         ESB-2016.1608
                   ESB-2016.1599
                   ESB-2016.1539
                   ESB-2016.1078
                   ESB-2016.0821

Original Bulletin: 
   http://www.debian.org/security/2016/dsa-3607

- --------------------------BEGIN INCLUDED TEXT--------------------

- -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512

- - -------------------------------------------------------------------------
Debian Security Advisory DSA-3607-1                   security@debian.org
https://www.debian.org/security/                     Salvatore Bonaccorso
June 28, 2016                         https://www.debian.org/security/faq
- - -------------------------------------------------------------------------

Package        : linux
CVE ID         : CVE-2015-7515 CVE-2016-0821 CVE-2016-1237 CVE-2016-1583
                 CVE-2016-2117 CVE-2016-2143 CVE-2016-2184 CVE-2016-2185
                 CVE-2016-2186 CVE-2016-2187 CVE-2016-3070 CVE-2016-3134
                 CVE-2016-3136 CVE-2016-3137 CVE-2016-3138 CVE-2016-3140
                 CVE-2016-3156 CVE-2016-3157 CVE-2016-3672 CVE-2016-3951
                 CVE-2016-3955 CVE-2016-3961 CVE-2016-4470 CVE-2016-4482
                 CVE-2016-4485 CVE-2016-4486 CVE-2016-4565 CVE-2016-4569
                 CVE-2016-4578 CVE-2016-4580 CVE-2016-4581 CVE-2016-4805
                 CVE-2016-4913 CVE-2016-4997 CVE-2016-4998 CVE-2016-5243
                 CVE-2016-5244

Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.

CVE-2015-7515, CVE-2016-2184, CVE-2016-2185, CVE-2016-2186,
CVE-2016-2187, CVE-2016-3136, CVE-2016-3137, CVE-2016-3138,
CVE-2016-3140

    Ralf Spenneberg of OpenSource Security reported that various USB
    drivers do not sufficiently validate USB descriptors.  This
    allowed a physically present user with a specially designed USB
    device to cause a denial of service (crash).

CVE-2016-0821

    Solar Designer noted that the list 'poisoning' feature, intended
    to mitigate the effects of bugs in list manipulation in the
    kernel, used poison values within the range of virtual addresses
    that can be allocated by user processes.

CVE-2016-1237

    David Sinquin discovered that nfsd does not check permissions when
    setting ACLs, allowing users to grant themselves permissions to a
    file by setting the ACL.

CVE-2016-1583

    Jann Horn of Google Project Zero reported that the eCryptfs
    filesystem could be used together with the proc filesystem to
    cause a kernel stack overflow.  If the ecryptfs-utils package is
    installed, local users could exploit this, via the
    mount.ecryptfs_private program, for denial of service (crash) or
    possibly for privilege escalation.

CVE-2016-2117

    Justin Yackoski of Cryptonite discovered that the Atheros L2
    ethernet driver incorrectly enables scatter/gather I/O. A remote
    attacker could take advantage of this flaw to obtain potentially
    sensitive information from kernel memory.

CVE-2016-2143

    Marcin Koscielnicki discovered that the fork implementation in the
    Linux kernel on s390 platforms mishandles the case of four
    page-table levels, which allows local users to cause a denial of
    service (system crash).

CVE-2016-3070

    Jan Stancek of Red Hat discovered a local denial of service
    vulnerability in AIO handling.

CVE-2016-3134

    The Google Project Zero team found that the netfilter subsystem does
    not sufficiently validate filter table entries. A user with the
    CAP_NET_ADMIN capability could use this for denial of service
    (crash) or possibly for privilege escalation. Debian disables
    unprivileged user namespaces by default, if locally enabled with the
    kernel.unprivileged_userns_clone sysctl, this allows privilege
    escalation.

CVE-2016-3156

    Solar Designer discovered that the IPv4 implementation in the Linux
    kernel did not perform the destruction of inet device objects
    properly. An attacker in a guest OS could use this to cause a denial
    of service (networking outage) in the host OS.

CVE-2016-3157 / XSA-171

    Andy Lutomirski discovered that the x86_64 (amd64) task switching
    implementation did not correctly update the I/O permission level
    when running as a Xen paravirtual (PV) guest.  In some
    configurations this would allow local users to cause a denial of
    service (crash) or to escalate their privileges within the guest.

CVE-2016-3672

    Hector Marco and Ismael Ripoll noted that it was possible to disable
    Address Space Layout Randomisation (ASLR) for x86_32 (i386) programs
    by removing the stack resource limit. This made it easier for local
    users to exploit security flaws in programs that have the setuid or
    setgid flag set.

CVE-2016-3951

    It was discovered that the cdc_ncm driver would free memory
    prematurely if certain errors occurred during its initialisation.
    This allowed a physically present user with a specially designed
    USB device to cause a denial of service (crash) or possibly to
    escalate their privileges.

CVE-2016-3955

    Ignat Korchagin reported that the usbip subsystem did not check
    the length of data received for a USB buffer.  This allowed denial
    of service (crash) or privilege escalation on a system configured
    as a usbip client, by the usbip server or by an attacker able to
    impersonate it over the network.  A system configured as a usbip
    server might be similarly vulnerable to physically present users.

CVE-2016-3961 / XSA-174

    Vitaly Kuznetsov of Red Hat discovered that Linux allowed the use of
    hugetlbfs on x86 (i386 and amd64) systems even when running as a Xen
    paravirtualised (PV) guest, although Xen does not support huge
    pages. This allowed users with access to /dev/hugepages to cause a
    denial of service (crash) in the guest.

CVE-2016-4470

    David Howells of Red Hat discovered that a local user can trigger a
    flaw in the Linux kernel's handling of key lookups in the keychain
    subsystem, leading to a denial of service (crash) or possibly to
    privilege escalation.

CVE-2016-4482, CVE-2016-4485, CVE-2016-4486, CVE-2016-4569,
CVE-2016-4578, CVE-2016-4580, CVE-2016-5243, CVE-2016-5244

    Kangjie Lu reported that the USB devio, llc, rtnetlink, ALSA
    timer, x25, tipc, and rds facilities leaked information from the
    kernel stack.

CVE-2016-4565

    Jann Horn of Google Project Zero reported that various components
    in the InfiniBand stack implemented unusual semantics for the
    write() operation.  On a system with InfiniBand drivers loaded,
    local users could use this for denial of service or privilege
    escalation.

CVE-2016-4581

    Tycho Andersen discovered that in some situations the Linux kernel
    did not handle propagated mounts correctly. A local user can take
    advantage of this flaw to cause a denial of service (system crash).

CVE-2016-4805

    Baozeng Ding discovered a use-after-free in the generic PPP layer in
    the Linux kernel. A local user can take advantage of this flaw to
    cause a denial of service (system crash), or potentially escalate
    their privileges.

CVE-2016-4913

    Al Viro found that the ISO9660 filesystem implementation did not
    correctly count the length of certain invalid name entries.
    Reading a directory containing such name entries would leak
    information from kernel memory.  Users permitted to mount disks or
    disk images could use this to obtain sensitive information.

CVE-2016-4997 / CVE-2016-4998

    Jesse Hertz and Tim Newsham discovered that missing input sanitising
    in Netfilter socket handling may result in denial of service. Debian
    disables unprivileged user namespaces by default, if locally enabled
    with the kernel.unprivileged_userns_clone sysctl, this also allows
    privilege escalation.

For the stable distribution (jessie), these problems have been fixed in
version 3.16.7-ckt25-2+deb8u2.

We recommend that you upgrade your linux packages.

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/

Mailing list: debian-security-announce@lists.debian.org
- -----BEGIN PGP SIGNATURE-----
Version: GnuPG v1

iQIcBAEBCgAGBQJXckE+AAoJEAVMuPMTQ89EbVoP/2hxxkUZ6hmCNzqfAdVglANg
xzBg+dWsE/1Q8gl2OiMrxV8Dy/v9+3Xl2lI0Lldx0zDRSqImvxzCm6Fhhye/OiRD
BWeVdeHFdUNTv6MQQ9qFH6ykbz4TQhKPBbbCN0LbbsFa2I1LQNirvMM0fNu915U+
JgMP0JtkvbLZNzT8tg2hR+KkHaZJp+HIZsQD4a8dCPNZVrQJNZt6FFfE0M01IQSw
KnjAmzp9om9CAfrTPyu2bnHXa9ktmU2zOeat267TKzSB8zw1/AlHDpf/sODd6uTi
lTeInri1NNc2r2VS5mAUWwTUHOHPLPS2PTH+Dpd0vla1qcbUFArfFONgICH3VnYs
kqL/Y5ZlhzVC+YXOUDdw+poTSYL/sxTYU+8OImSXbVrhAOT0xTlXX80fqjZJ+lvM
1edtWoZQcpQQ7hZNq919LOrd770e3hkfFHTogwLQ3ROADxGGpOCcsySPDS1Xl2bX
b+7HAagYfYknzF2UyZjmc4zn3BtGYYeHkKAWfeuj3U6V5JV2wut/vTHaSgYt4Jue
Efy3745ZOZGVcj0UJ6YhN7BNY/kpsfeaiTMcismkU0ywKaINY8rX2GjdX68xmGaa
Cs//sGmMSbTNb7JjqdHWY5GJG+q6qUzSyPsSiNfv8F+EsPW/u5PEl/VEo9nl2uvm
bXgDVs7M9codkftA8ma7
=LawE
- -----END PGP SIGNATURE-----

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        http://www.auscert.org.au/render.html?cid=1980

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBV3MZqIx+lLeg9Ub1AQiXihAAodsA3Ep4hJhdW/Zg+WNadWy0rr+63NcQ
uQn0nUj0neJQYxE1L5vGWaUK8ZRJLyPSZGgfgUSqn9B6IFJRFw8QLKVkkxUD7svy
Smf87ImUh0bkB6VwjKHXEJVv2O4oDhDb7phWoz25L8nxGqJvUuzQOYws5t+yQ9Nu
QFS4hb/pznlogdSMMtJpu1JHPSZQ0/U2fdnnhBdEhxa/Yyc8wxUWJPckDiznKpkC
CH+tdGNZv9Qjd9NP0YFBk99NNEol5DKaTfZREpdG/F8I2q5BqvTj1jR8nsLRDkOc
OVYlXXlpRAhTtfIoP+NEl4rLIYOt6TVd8NRcKIgSVM7kRdQcGMenYWbIwanrvSs4
jIlswrnOuSFP94lqNZiWrTQaACFFUlHAGXKqotS7QypVXQIv+V58nM+wTsAmN6CA
A+gGumvljsANSQ1nVp6xn4w3gbFLuLRGXZP1cwdyIuNvQeoljVQ1vhvo+i7L4Aoa
rjGVAFKCKNIqqhzAzFLfpccOV+9xlD3brfyJb90Pcfh9mKJiVCI/8xd5GUmazUq+
KD5EtSgyX+ak8abOleyBSWrxPZK0vRcFFBpBi8sjjrjZPnwWuzml75Da0+Gecrss
G0XhV0ldWaoex3lw1RCQ3KFRRfn8jmBgltagEW6qROlKX+xVdP9UQg0na+OS3dT/
kmlAzbXPiPQ=
=wdt5
-----END PGP SIGNATURE-----