Canonical is patching leaks and administrative privilege issues. On September 3, the company informed its users about updates to the new Linux kernel for the Ubuntu 12.04 ( Precise Pangolin ) and Ubuntu 14.04 LTS ( Trusty Tahr ) operating systems , fixing one critical issue in each.
According to the company, the information leak appears to have been discovered in the MD (Multiple Device) driver of the Linux kernelpackages for Ubuntu 12.04 LTS, which could allow privileged access to sensitive data to the attacker (local). This hole was discovered by Benjamin Randazzo.
In Ubuntu 14.04 LTS (Trusty Tahr), Canonical is patching an integer overflow bug found in the Linux Kernel's generic SCSI driver, which could allow a local attacker with write permissions to SCSI to gain root access or even cause a system crash through a DoS attack.
The company urges all users of the above operating systems to immediately with the new updates. The new versions are already available.
To install the updates, you will need to open the Software Updater utility, and after checking for new updates, then apply all available ones. Also note that you will need to reboot your computer after updating the Linux kernel packages, otherwise it will not be updated. After updating, make sure you are running linux-image-3.2.0-90 (3.2.0-90.128) on Ubuntu 12.01 LTS and linux-image-3.13.0-63 (3.13.0-63.103) on Ubuntu 14.04 LTS using the “uname -a” command in the Terminal app.
