CVE-2015-3636 – ipv4 use-after-free
Medium
Ubuntu
A use-after-free flaw was discovered in the Linux kernel’s ipv4 ping support. A local user could exploit this flaw to gain administrative privileges on the system.
The Cloud Foundry project is releasing a BOSH stemcell version 2983 that has the patched version of ipv4.
_Severity is medium unless otherwise noted.
_
Users of affected versions should apply the following mitigation:
Wen Xu