-
Notifications
You must be signed in to change notification settings - Fork 0
/
USN-5940-1.json
159 lines (159 loc) · 8.98 KB
/
USN-5940-1.json
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
{
"id": "USN-5940-1",
"summary": "linux-raspi-5.4 vulnerabilities",
"details": "It was discovered that the Upper Level Protocol (ULP) subsystem in the\nLinux kernel did not properly handle sockets entering the LISTEN state in\ncertain protocols, leading to a use-after-free vulnerability. A local\nattacker could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2023-0461)\n\nIt was discovered that the NVMe driver in the Linux kernel did not properly\nhandle reset events in some situations. A local attacker could use this to\ncause a denial of service (system crash). (CVE-2022-3169)\n\nIt was discovered that a use-after-free vulnerability existed in the SGI\nGRU driver in the Linux kernel. A local attacker could possibly use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2022-3424)\n\nGwangun Jung discovered a race condition in the IPv4 implementation in the\nLinux kernel when deleting multipath routes, resulting in an out-of-bounds\nread. An attacker could use this to cause a denial of service (system\ncrash) or possibly expose sensitive information (kernel memory).\n(CVE-2022-3435)\n\nIt was discovered that a race condition existed in the Kernel Connection\nMultiplexor (KCM) socket implementation in the Linux kernel when releasing\nsockets in certain situations. A local attacker could use this to cause a\ndenial of service (system crash). (CVE-2022-3521)\n\nIt was discovered that the Netronome Ethernet driver in the Linux kernel\ncontained a use-after-free vulnerability. A local attacker could use this\nto cause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2022-3545)\n\nIt was discovered that the hugetlb implementation in the Linux kernel\ncontained a race condition in some situations. A local attacker could use\nthis to cause a denial of service (system crash) or expose sensitive\ninformation (kernel memory). (CVE-2022-3623)\n\nZiming Zhang discovered that the VMware Virtual GPU DRM driver in the Linux\nkernel contained an out-of-bounds write vulnerability. A local attacker\ncould use this to cause a denial of service (system crash).\n(CVE-2022-36280)\n\nHyunwoo Kim discovered that the DVB Core driver in the Linux kernel did not\nproperly perform reference counting in some situations, leading to a use-\nafter-free vulnerability. A local attacker could use this to cause a denial\nof service (system crash) or possibly execute arbitrary code.\n(CVE-2022-41218)\n\nIt was discovered that the Intel i915 graphics driver in the Linux kernel\ndid not perform a GPU TLB flush in some situations. A local attacker could\nuse this to cause a denial of service or possibly execute arbitrary code.\n(CVE-2022-4139)\n\nIt was discovered that a race condition existed in the Xen network backend\ndriver in the Linux kernel when handling dropped packets in certain\ncircumstances. An attacker could use this to cause a denial of service\n(kernel deadlock). (CVE-2022-42328, CVE-2022-42329)\n\nIt was discovered that the Atmel WILC1000 driver in the Linux kernel did\nnot properly validate offsets, leading to an out-of-bounds read\nvulnerability. An attacker could use this to cause a denial of service\n(system crash). (CVE-2022-47520)\n\nIt was discovered that the network queuing discipline implementation in the\nLinux kernel contained a null pointer dereference in some situations. A\nlocal attacker could use this to cause a denial of service (system crash).\n(CVE-2022-47929)\n\nJos\u00e9 Oliveira and Rodrigo Branco discovered that the prctl syscall\nimplementation in the Linux kernel did not properly protect against\nindirect branch prediction attacks in some situations. A local attacker\ncould possibly use this to expose sensitive information. (CVE-2023-0045)\n\nIt was discovered that a use-after-free vulnerability existed in the\nAdvanced Linux Sound Architecture (ALSA) subsystem. A local attacker could\nuse this to cause a denial of service (system crash). (CVE-2023-0266)\n\nKyle Zeng discovered that the IPv6 implementation in the Linux kernel\ncontained a NULL pointer dereference vulnerability in certain situations. A\nlocal attacker could use this to cause a denial of service (system crash).\n(CVE-2023-0394)\n\nIt was discovered that the Android Binder IPC subsystem in the Linux kernel\ndid not properly validate inputs in some situations, leading to a use-\nafter-free vulnerability. A local attacker could use this to cause a denial\nof service (system crash) or possibly execute arbitrary code.\n(CVE-2023-20938)\n\nKyle Zeng discovered that the class-based queuing discipline implementation\nin the Linux kernel contained a type confusion vulnerability in some\nsituations. An attacker could use this to cause a denial of service (system\ncrash). (CVE-2023-23454)\n\nKyle Zeng discovered that the ATM VC queuing discipline implementation in\nthe Linux kernel contained a type confusion vulnerability in some\nsituations. An attacker could use this to cause a denial of service (system\ncrash). (CVE-2023-23455)\n\n",
"aliases": [],
"related": [
"CVE-2022-3169",
"CVE-2022-3424",
"CVE-2022-3435",
"CVE-2022-3521",
"CVE-2022-3545",
"CVE-2022-3623",
"CVE-2022-36280",
"CVE-2022-41218",
"CVE-2022-4139",
"CVE-2022-42328",
"CVE-2022-42329",
"CVE-2022-47520",
"CVE-2022-47929",
"CVE-2023-0045",
"CVE-2023-0266",
"CVE-2023-0394",
"CVE-2023-0461",
"CVE-2023-20938",
"CVE-2023-23454",
"CVE-2023-23455"
],
"published": "2023-03-09T12:46:59.873320Z",
"modified": "2023-03-09T12:46:59.873320Z",
"affected": [
{
"package": {
"ecosystem": "Ubuntu:18.04:LTS",
"name": "linux-raspi-5.4"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "5.4.0-1081.92~18.04.1"
}
]
}
],
"ecosystem_specific": {
"binaries": [
{
"linux-image-raspi-hwe-18.04-edge": "5.4.0.1081.78",
"linux-tools-raspi-hwe-18.04": "5.4.0.1081.78",
"linux-image-5.4.0-1081-raspi": "5.4.0-1081.92~18.04.1",
"linux-headers-raspi-hwe-18.04-edge": "5.4.0.1081.78",
"linux-image-raspi-hwe-18.04": "5.4.0.1081.78",
"linux-raspi-hwe-18.04-edge": "5.4.0.1081.78",
"linux-headers-5.4.0-1081-raspi": "5.4.0-1081.92~18.04.1",
"linux-modules-5.4.0-1081-raspi": "5.4.0-1081.92~18.04.1",
"linux-tools-5.4.0-1081-raspi": "5.4.0-1081.92~18.04.1",
"linux-raspi-5.4-headers-5.4.0-1081": "5.4.0-1081.92~18.04.1",
"linux-raspi-hwe-18.04": "5.4.0.1081.78",
"linux-buildinfo-5.4.0-1081-raspi": "5.4.0-1081.92~18.04.1",
"linux-headers-raspi-hwe-18.04": "5.4.0.1081.78",
"linux-raspi-5.4-tools-5.4.0-1081": "5.4.0-1081.92~18.04.1",
"linux-tools-raspi-hwe-18.04-edge": "5.4.0.1081.78"
}
],
"availability": "No subscription needed"
}
}
],
"references": [
{
"type": "ADVISORY",
"url": "https://ubuntu.com/security/notices/USN-5940-1"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2022-3169"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2022-3424"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2022-3435"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2022-3521"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2022-3545"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2022-3623"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2022-36280"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2022-41218"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2022-4139"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2022-42328"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2022-42329"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2022-47520"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2022-47929"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2023-0045"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2023-0266"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2023-0394"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2023-0461"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2023-20938"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2023-23454"
},
{
"type": "REPORT",
"url": "https://ubuntu.com/security/CVE-2023-23455"
}
]
}