LSN-0089-1
Dashboard / Vulnerabilities / LSN-0089-1
LSN-0089-1
Summary: Kernel Live Patch Security Notice
Details: Aaron Adams discovered that the netfilter subsystem in the Linux kernel did not properly handle the removal of stateful expressions in some situations, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-1966) Ziming Zhang discovered that the netfilter subsystem in the Linux kernel did not properly validate sets with multiple ranged fields. A local attacker could use this to cause a denial of service or execute arbitrary code.(CVE-2022-1972) It was discovered that the implementation of POSIX timers in the Linux kernel did not properly clean up timers in some situations. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code.(CVE-2022-2585) It was discovered that the netfilter subsystem of the Linux kernel did not prevent one nft object from referencing an nft set in another nft table, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code.(CVE-2022-2586) Zhenpeng Lin discovered that the network packet scheduler implementation in the Linux kernel did not properly remove all references to a route filter before freeing it in some situations. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code.(CVE-2022-2588) It was discovered that the Linux kernel did not properly restrict access to the kernel debugger when booted in secure boot environments. A privileged attacker could use this to bypass UEFI Secure Boot restrictions.(CVE-2022-21499) Kyle Zeng discovered that the Network Queuing and Scheduling subsystem of the Linux kernel did not properly perform reference counting in some situations, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code.(CVE-2022-29581) Arthur Mongodin discovered that the netfilter subsystem in the Linux kernel did not properly perform data validation. A local attacker could use this to escalate privileges in certain situations.(CVE-2022-34918)
References: https://ubuntu.com/security/notices/LSN-0089-1, https://ubuntu.com/security/CVE-2022-1966, https://ubuntu.com/security/CVE-2022-1972, https://ubuntu.com/security/CVE-2022-2585, https://ubuntu.com/security/CVE-2022-2586, https://ubuntu.com/security/CVE-2022-2588, https://ubuntu.com/security/CVE-2022-21499, https://ubuntu.com/security/CVE-2022-29581, https://ubuntu.com/security/CVE-2022-34918
Affected packages
Package
Name: linux-lts-xenial
Purl: pkg:deb/ubuntu/linux-lts-xenial?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
