Ubuntu Security Notice 2153-1 - Kees Cook discovered that initramfs-tools incorrectly mounted /run without the noexec option, contrary to expected behaviour.
0c0be50832191b5dd596c547394e1fef8f12e9e8ef6f54a4d8205d8eaaae8cda
==========================================================================
Ubuntu Security Notice USN-2153-1
March 24, 2014
initramfs-tools vulnerability
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 12.10
- Ubuntu 12.04 LTS
Summary:
initramfs-tools used incorrect mount options.
Software Description:
- initramfs-tools: tools for generating an initramfs
Details:
Kees Cook discovered that initramfs-tools incorrectly mounted /run without
the noexec option, contrary to expected behaviour.
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 12.10:
initramfs-tools 0.103ubuntu0.2.2
Ubuntu 12.04 LTS:
initramfs-tools 0.99ubuntu13.5
After a standard system update you need to reboot your computer to make all
the necessary changes.
References:
http://www.ubuntu.com/usn/usn-2153-1
https://launchpad.net/bugs/1152744
Package Information:
https://launchpad.net/ubuntu/+source/initramfs-tools/0.103ubuntu0.2.2
https://launchpad.net/ubuntu/+source/initramfs-tools/0.99ubuntu13.5