LSN-0102-1
Dashboard / Vulnerabilities / LSN-0102-1
LSN-0102-1
Summary: Kernel Live Patch Security Notice
Details: It was discovered that a race condition existed in the io_uring subsystem in the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.(CVE-2023-1872) Lonial Con discovered that the netfilter subsystem in the Linux kernel contained a memory leak when handling certain element flush operations. A local attacker could use this to expose sensitive information (kernel memory).(CVE-2023-4569) It was discovered that the TLS subsystem in the Linux kernel did not properly perform cryptographic operations in some situations, leading to a null pointer dereference vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.(CVE-2023-6176) It was discovered that a race condition existed in the AppleTalk networking subsystem of the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.(CVE-2023-51781) Jann Horn discovered that the TLS subsystem in the Linux kernel did not properly handle spliced messages, leading to an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.(CVE-2024-0646) Notselwyn discovered that the netfilter subsystem in the Linux kernel did not properly handle verdict parameters in certain cases, leading to a use- after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.(CVE-2024-1086)
References: https://ubuntu.com/security/notices/LSN-0102-1, https://ubuntu.com/security/CVE-2023-1872, https://ubuntu.com/security/CVE-2023-4569, https://ubuntu.com/security/CVE-2023-6176, https://ubuntu.com/security/CVE-2023-51781, https://ubuntu.com/security/CVE-2024-0646, https://ubuntu.com/security/CVE-2024-1086
Affected packages
Package
Name: linux-lts-xenial
Purl: pkg:deb/ubuntu/linux-lts-xenial?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
