USN-4451-1: ppp vulnerability
4 August 2020
ppp could be made to load arbitrary kernel modules and possibly run programs.
Releases
Packages
- ppp - Point-to-Point Protocol (PPP)
Details
Thomas Chauchefoin working with Trend Micro´s Zero Day Initiative,
discovered that ppp incorrectly handled module loading. A local attacker
could use this issue to load arbitrary kernel modules and possibly execute
arbitrary code.
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04
Ubuntu 18.04
Ubuntu 16.04
In general, a standard system update will make all the necessary changes.
References
Related notices
- USN-4451-2: ppp-udeb, ppp-dev, ppp