CLSA-2023-1693431257

    Dashboard / Vulnerabilities / CLSA-2023-1693431257

    CLSA-2023-1693431257

    Published: 30 Aug 2023Last Modified: 4 Jun 2026

    Summary: Fix of 17 CVEs

    Details: * Jammy update: v5.15.75 upstream stable release (LP: #1996825) // CVE-url: https://ubuntu.com/security/CVE-2022-1184 - ext4: fix check for block being out of directory size * Jammy update: v5.15.61 upstream stable release (LP: #1990162) // CVE-url: https://ubuntu.com/security/CVE-2022-1184 - ext4: check if directory block is within i_size * Jammy update: v5.15.68 upstream stable release (LP: #1993003) // CVE-url: https://ubuntu.com/security/CVE-2022-3303 - ALSA: pcm: oss: Fix race at SNDCTL_DSP_SYNC * CVE-2023-1670 // CVE-url: https://ubuntu.com/security/CVE-2023-1670 - xirc2ps_cs: Fix use after free bug in xirc2ps_detach * CVE-url: https://ubuntu.com/security/CVE-2023-1989 - Bluetooth: btsdio: fix use after free bug in btsdio_remove due to race condition * Jammy update: v5.15.104 upstream stable release (LP: #2023225) // CVE-url: https://ubuntu.com/security/CVE-2023-1990 - nfc: st-nci: Fix use after free bug in ndlc_remove due to race condition * CVE-url: https://ubuntu.com/security/CVE-2023-2007 - scsi: dpt_i2o: Remove obsolete driver * CVE-2023-2124 // CVE-url: https://ubuntu.com/security/CVE-2023-2124 - xfs: verify buffer contents when we skip log replay * CVE-url: https://ubuntu.com/security/CVE-2023-23000 - phy: tegra: xusb: Fix return value of tegra_xusb_find_port_node function * CVE-url: https://ubuntu.com/security/CVE-2023-28466 - net: tls: fix possible race condition between do_tls_getsockopt_conf() and do_tls_setsockopt_conf() * CVE-url: https://ubuntu.com/security/CVE-2023-3090 - ipvlan:Fix out-of-bounds caused by unclear skb->cb * Jammy update: v5.15.63 upstream stable release (LP: #1990564) // CVE-url: https://ubuntu.com/security/CVE-2023-3111 - btrfs: unset reloc control if transaction commit fails in prepare_to_relocate() * CVE-url: https://ubuntu.com/security/CVE-2023-3111 - btrfs: check return value of btrfs_commit_transaction in relocation * CVE-url: https://ubuntu.com/security/CVE-2023-3141 - memstick: r592: Fix UAF bug in r592_remove due to race condition * CVE-url: https://ubuntu.com/security/CVE-2023-3212 - gfs2: Don't deref jdesc in evict * CVE-url: https://ubuntu.com/security/CVE-2023-3268 - kernel/relay.c: fix read_pos error when multiple readers - relayfs: fix out-of-bounds access in relay_file_read * CVE-url: https://ubuntu.com/security/CVE-2023-3390 - netfilter: nf_tables: incorrect error path handling with NFT_MSG_NEWRULE * CVE-url: https://ubuntu.com/security/CVE-2023-35823 - media: saa7134: fix use after free bug in saa7134_finidev due to race condition * CVE-url: https://ubuntu.com/security/CVE-2023-35824 - media: dm1105: Fix use after free bug in dm1105_remove due to race condition * Miscellaneous Ubuntu changes - [Config] updateconfigs for SCSI_DPT_I2O * Miscellaneous upstream changes - fixup! UBUNTU: [Packaging]: add tuxcare suffix

    Affected packages

    Package

    Name: linux-buildinfo-4.15.0-214-tuxcare.els2-generic

    Purl: pkg:deb/tuxcare/linux-buildinfo-4.15.0-214-tuxcare.els2-generic?distro=ubuntu-18.04

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.15.0-214.225

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CLSA-2023-1693431257 | CVE-DB