USN-5911-1

Source
https://ubuntu.com/security/notices/USN-5911-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5911-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-5911-1
Related
Published
2023-03-02T23:06:33Z
Modified
2023-03-02T23:06:33Z
Summary
linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.19, linux-ibm, linux-lowlatency, linux-oracle vulnerabilities
Details

It was discovered that the Upper Level Protocol (ULP) subsystem in the Linux kernel did not properly handle sockets entering the LISTEN state in certain protocols, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-0461)

Davide Ornaghi discovered that the netfilter subsystem in the Linux kernel did not properly handle VLAN headers in some situations. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-0179)

It was discovered that the NVMe driver in the Linux kernel did not properly handle reset events in some situations. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-3169)

Maxim Levitsky discovered that the KVM nested virtualization (SVM) implementation for AMD processors in the Linux kernel did not properly handle nested shutdown execution. An attacker in a guest vm could use this to cause a denial of service (host kernel crash) (CVE-2022-3344)

Gwangun Jung discovered a race condition in the IPv4 implementation in the Linux kernel when deleting multipath routes, resulting in an out-of-bounds read. An attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information (kernel memory). (CVE-2022-3435)

It was discovered that a race condition existed in the Kernel Connection Multiplexor (KCM) socket implementation in the Linux kernel when releasing sockets in certain situations. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-3521)

It was discovered that the Netronome Ethernet driver in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-3545)

It was discovered that the Intel i915 graphics driver in the Linux kernel did not perform a GPU TLB flush in some situations. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2022-4139)

It was discovered that the NFSD implementation in the Linux kernel contained a use-after-free vulnerability. A remote attacker could possibly use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-4379)

It was discovered that a race condition existed in the x86 KVM subsystem implementation in the Linux kernel when nested virtualization and the TDP MMU are enabled. An attacker in a guest vm could use this to cause a denial of service (host OS crash). (CVE-2022-45869)

It was discovered that the Atmel WILC1000 driver in the Linux kernel did not properly validate the number of channels, leading to an out-of-bounds write vulnerability. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-47518)

It was discovered that the Atmel WILC1000 driver in the Linux kernel did not properly validate specific attributes, leading to an out-of-bounds write vulnerability. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-47519)

It was discovered that the Atmel WILC1000 driver in the Linux kernel did not properly validate offsets, leading to an out-of-bounds read vulnerability. An attacker could use this to cause a denial of service (system crash). (CVE-2022-47520)

It was discovered that the Atmel WILC1000 driver in the Linux kernel did not properly validate specific attributes, leading to a heap-based buffer overflow. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-47521)

It was discovered that the file system writeback functionality in the Linux kernel contained a user-after-free vulnerability. A local attacker could possibly use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2023-26605)

References

Affected packages

Ubuntu:22.04:LTS / linux-hwe-5.19

Package

Name
linux-hwe-5.19
Purl
pkg:deb/ubuntu/linux-hwe-5.19?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.19.0-35.36~22.04.1

Affected versions

5.*

5.19.0-28.29~22.04.1
5.19.0-32.33~22.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-buildinfo-5.19.0-35-generic"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-buildinfo-5.19.0-35-generic-64k"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-buildinfo-5.19.0-35-generic-lpae"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-cloud-tools-5.19.0-35-generic"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-headers-5.19.0-35-generic"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-headers-5.19.0-35-generic-64k"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-headers-5.19.0-35-generic-lpae"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-hwe-5.19-cloud-tools-5.19.0-35"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-hwe-5.19-cloud-tools-common"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-hwe-5.19-headers-5.19.0-35"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-hwe-5.19-tools-5.19.0-35"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-hwe-5.19-tools-common"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-hwe-5.19-tools-host"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-image-5.19.0-35-generic"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-image-5.19.0-35-generic-dbgsym"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-image-5.19.0-35-generic-lpae"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-image-5.19.0-35-generic-lpae-dbgsym"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-image-unsigned-5.19.0-35-generic"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-image-unsigned-5.19.0-35-generic-64k"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-image-unsigned-5.19.0-35-generic-64k-dbgsym"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-image-unsigned-5.19.0-35-generic-dbgsym"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-modules-5.19.0-35-generic"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-modules-5.19.0-35-generic-64k"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-modules-5.19.0-35-generic-lpae"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-modules-extra-5.19.0-35-generic"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-modules-ipu6-5.19.0-35-generic"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-modules-ivsc-5.19.0-35-generic"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-modules-iwlwifi-5.19.0-35-generic"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-source-5.19.0"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-tools-5.19.0-35-generic"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-tools-5.19.0-35-generic-64k"
        },
        {
            "binary_version": "5.19.0-35.36~22.04.1",
            "binary_name": "linux-tools-5.19.0-35-generic-lpae"
        }
    ]
}