---
title: Canonical Livepatch Service update – December 2016
description: 'The following kernel security vulnerabilities were addressed through
  live patches on Ubuntu – to ensure you have the fixes, either install at ubuntu.com/livepatch
  or update to newest kernel and reboot. Linux kernel vulnerability 7th December 2016
  (LSN-0014-1) Details: A race condition in the af_packet implementation in the Linux
  kernel. A […]'
url: https://canonical.com/blog/canonical-livepatch-service-update-december-2016?format=md
---

1. [Blog](https://canonical.com/blog)
2. Article

---

[Canonical](https://canonical.com/blog/author/canonical "More about Canonical")

21 December 2016

# Canonical Livepatch Service update – December 2016

[Canonical](https://canonical.com/blog/tag/canonical)
[livepatch](https://canonical.com/blog/tag/livepatch)
[Security](https://canonical.com/blog/tag/security)
[Ubuntu Advantage](https://canonical.com/blog/tag/ubuntu-advantage)
[Ubuntu Advantage for infrastructure](https://canonical.com/blog/tag/ubuntu-advantage-for-infrastructure)

---

Share the article

The following kernel security vulnerabilities were addressed through live patches on Ubuntu – to ensure you have the fixes, either install at [ubuntu.com/livepatch](http://ubunt.eu/KPbmZw) or update to newest kernel and reboot.

## Linux kernel vulnerability

### 7th December 2016 (LSN-0014-1)

Details:

* A race condition in the af\_packet implementation in the Linux kernel. A local unprivileged attacker could use this to cause a denial of service (system crash) or run arbitrary code with administrative privileges.
* A race condition in the Adaptec AAC RAID controller driver in the Linux kernel when handling ioctl()s. A local attacker could use this to cause a denial of service (system crash). A use-after-free condition could occur in the TCP retransmit queue handling code in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.

[Learn more](http://ubunt.eu/dRqTTg)

## Linux kernel vulnerability

### 30th November 2016 (LSN-0013-1)

Details:

* The keyring interface in the Linux kernel contained a buffer overflow when displaying timeout events via the /proc/keys interface. A local attacker could use this to cause a denial of service (system crash).
* A use-after-free vulnerability during error processing in the recvmmsg(2) implementation in the Linux kernel. A remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.
* The driver for Areca RAID Controllers in the Linux kernel did not properly validate control messages. A local attacker could use this to cause a denial of service (system crash) or possibly gain privileges.
* A stack-based buffer overflow in the Broadcom IEEE802.11n FullMAC driver in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly gain privileges.

[Learn more](http://ubunt.eu/0UHR9b)

## Linux kernel vulnerability

### 20th October 2016 (LSN-0012-1)

Details:

* An unbounded recursion in the VLAN and TEB Generic Receive Offload (GRO) processing implementations in the Linux kernel. A remote attacker could use this to cause a stack corruption, leading to a denial of service (system crash).
* It was discovered that a race condition existed in the memory manager of the Linux kernel when handling copy-on-write breakage of private read-only memory mappings. A local attacker could use this to gain administrative privileges.

[Learn more](http://ubunt.eu/Ov2J2G)

[Get in touch

Interested in running Ubuntu in your organization?](https://ubuntu.com/about/contact-us/form)

## Sign up for our newsletter

Get the latest Canonical news and updates in your inbox.

Work email:

\*I agree to receive information about Canonical's
products and services.

By submitting this form, I confirm that I have read and agree to [Canonical's Privacy Policy](https://canonical.com/legal/dataprivacy).

Sign up

## Share on

---

## Related posts

[### Canonical joins the Open Secure AI Alliance](https://canonical.com/blog/open-secure-ai-alliance)

Canonical is now part of the Open Secure AI Alliance, announced by NVIDIA with partners across cloud computing, cybersecurity, enterprise software, open source foundations, and...

[Canonical](https://canonical.com/blog/author/canonical)

28 August 2026

[### Januscape vulnerability CVE-2026-53359 mitigations available](https://canonical.com/blog/januscape-linux-vulnerability-mitigations-available)

Introduction A local privilege escalation (LPE) vulnerability affecting the Linux kernel was publicly disclosed on July 6, 2026. The vulnerability was assigned CVE ID...

[seth-arnold](https://canonical.com/blog/author/seth-arnold)

11 July 2026

[### DirtyClone Linux kernel local privilege escalation vulnerability fixes available](https://canonical.com/blog/dirtyclone-linux-vulnerability-fixes-available)

On June 25, 2026, JFrog published their research into CVE-2026-43503, referring to the vulnerability as DirtyClone. The vulnerability had previously been responsibly disclosed...

[Luci Stanescu](https://canonical.com/blog/author/lucistanescu)

1 July 2026

[### pedit COW kernel local privilege escalation vulnerability mitigations](https://canonical.com/blog/pedit-cow-linux-vulnerability-fixes-available)

Mitigations are available for the Linux vulnerability with CVE ID CVE-2026-46331. The CVE ID was assigned on June 16 2026 and highlighted as a local privilege escalation (LPE)...

[Luci Stanescu](https://canonical.com/blog/author/lucistanescu)

1 July 2026
