CLSA-2023-1695901429
Dashboard / Vulnerabilities / CLSA-2023-1695901429
CLSA-2023-1695901429
Summary: Fix of 7 CVEs
Details: * CVE-url: https://ubuntu.com/security/CVE-2023-42753 - netfilter: ipset: add the missing IP_SET_HASH_WITH_NET0 macro for ip_set_hash_netportnet.c * CVE-2022-40982 // CVE-url: https://ubuntu.com/security/CVE-2022-40982 - init: Provide arch_cpu_finalize_init() - x86/cpu: Switch to arch_cpu_finalize_init() - init: Remove check_bugs() leftovers - x86/speculation: Add Gather Data Sampling mitigation - x86/speculation: Add force option to GDS mitigation - x86/speculation: Add Kconfig option for GDS - KVM: Add GDS_NO support to KVM * CVE-url: https://ubuntu.com/security/CVE-2022-40982 - x86/cpu: Move arch_smt_update() to a neutral place * Bionic update: upstream stable patchset 2019-07-23 (LP: #1837664) // CVE- url: https://ubuntu.com/security/CVE-2022-40982 - cpu/hotplug: Fix "SMT disabled by BIOS" detection for KVM * Jammy update: v5.15.94 upstream stable release (LP: #2012673) // CVE-url: https://ubuntu.com/security/CVE-2022-40982 - x86/speculation: Identify processors vulnerable to SMT RSB predictions * CVE-2023-20588 // CVE-url: https://ubuntu.com/security/CVE-2023-20588 - x86/bugs: Increase the x86 bugs vector size to two u32s - x86/CPU/AMD: Do not leak quotient data after a division by 0 - x86/CPU/AMD: Fix the DIV(0) initial fix attempt * CVE-2023-3863 // CVE-url: https://ubuntu.com/security/CVE-2023-3863 - nfc: llcp: simplify llcp_sock_connect() error paths - net: nfc: Fix use-after-free caused by nfc_llcp_find_local * Jammy update: v5.15.46 upstream stable release (LP: #1981864) // CVE-url: https://ubuntu.com/security/CVE-2023-4385 - fs: jfs: fix possible NULL pointer dereference in dbFree() * Jammy update: v5.15.42 upstream stable release (LP: #1981375) // CVE-url: https://ubuntu.com/security/CVE-2023-4459 - net: vmxnet3: fix possible NULL pointer dereference in vmxnet3_rq_cleanup() * CVE-url: https://ubuntu.com/security/CVE-2023-4921 - net: sched: sch_qfq: Fix UAF in qfq_dequeue() * Miscellaneous Ubuntu changes - [Config] CONFIG_GDS_FORCE_MITIGATION=n
Affected packages
Package
Name: linux-buildinfo-4.4.0-246-tuxcare.els17-generic
Purl: pkg:deb/tuxcare/linux-buildinfo-4.4.0-246-tuxcare.els17-generic?distro=ubuntu-16.04
Affected ranges
Type: ECOSYSTEM
Events:
