USN-3189-2

Advisory lineage Upstream: 4 Downstream: 0
Published: 03 Feb 2017, 09:34
Last modified:04 Feb 2026, 03:34

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

03 Feb 2017, 09:34
Published
Vulnerability first disclosed
04 Feb 2026, 03:34
Last Modified
Vulnerability information updated

Description

linux-lts-xenial vulnerabilities USN-3189-1 fixed vulnerabilities in the Linux kernel for Ubuntu 16.04 LTS. This update provides the corresponding updates for the Linux Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu 14.04 LTS. Mikulas Patocka discovered that the asynchronous multibuffer cryptographic daemon (mcryptd) in the Linux kernel did not properly handle being invoked with incompatible algorithms. A local attacker could use this to cause a denial of service (system crash). (CVE-2016-10147) Qidan He discovered that the ICMP implementation in the Linux kernel did not properly check the size of an ICMP header. A local attacker with CAP_NET_ADMIN could use this to expose sensitive information. (CVE-2016-8399)

Affected Systems

  • ubuntulinux-lts-xenial

    < 4.4.0-62.83~14.04.1

References (3)