CLSA-2023-1695900880
Dashboard / Vulnerabilities / CLSA-2023-1695900880
CLSA-2023-1695900880
Summary: Fix of 5 CVEs
Details: * CVE-url: https://ubuntu.com/security/CVE-2023-42753 - netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c * CVE-2022-40982 // CVE-url: https://ubuntu.com/security/CVE-2022-40982 - init: Provide arch_cpu_finalize_init() - x86/cpu: Switch to arch_cpu_finalize_init() - init: Remove check_bugs() leftovers - x86/speculation: Add Gather Data Sampling mitigation - x86/speculation: Add force option to GDS mitigation - x86/speculation: Add Kconfig option for GDS - KVM: Add GDS_NO support to KVM * CVE-url: https://ubuntu.com/security/CVE-2022-40982 - vmlinux.lds.h: Create section for protection against instrumentation - x86/cpu: Move arch_smt_update() to a neutral place * CVE-2023-20588 // CVE-url: https://ubuntu.com/security/CVE-2023-20588 - x86/bugs: Increase the x86 bugs vector size to two u32s - x86/CPU/AMD: Do not leak quotient data after a division by 0 - x86/CPU/AMD: Fix the DIV(0) initial fix attempt * CVE-2023-3863 // CVE-url: https://ubuntu.com/security/CVE-2023-3863 - nfc: llcp: simplify llcp_sock_connect() error paths - net: nfc: Fix use-after-free caused by nfc_llcp_find_local * CVE-url: https://ubuntu.com/security/CVE-2023-3863 - nfc: Fix to check for kmemdup failure * CVE-url: https://ubuntu.com/security/CVE-2023-4921 - net: sched: sch_qfq: Fix UAF in qfq_dequeue() * Miscellaneous Ubuntu changes - [Config] CONFIG_GDS_FORCE_MITIGATION=n
Affected packages
Package
Name: linux-buildinfo-4.15.0-218-tuxcare.els6-generic
Purl: pkg:deb/tuxcare/linux-buildinfo-4.15.0-218-tuxcare.els6-generic?distro=ubuntu-18.04
Affected ranges
Type: ECOSYSTEM
Events:
