UBUNTU-CVE-2022-21499
Dashboard / Vulnerabilities / UBUNTU-CVE-2022-21499
UBUNTU-CVE-2022-21499
Summary:
Details: KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker with access to a serial port could trigger the debugger so it is important that the debugger respect the lockdown mode when/if it is triggered. CVSS 3.1 Base Score 6.7 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H).
References: https://ubuntu.com/security/CVE-2022-21499, https://www.openwall.com/lists/oss-security/2022/05/24/7, https://www.openwall.com/lists/oss-security/2022/05/24/10, https://ubuntu.com/security/notices/USN-5465-1, https://ubuntu.com/security/notices/USN-5466-1, https://ubuntu.com/security/notices/USN-5467-1, https://ubuntu.com/security/notices/USN-5468-1, https://ubuntu.com/security/notices/USN-5469-1, https://ubuntu.com/security/notices/USN-5470-1, https://ubuntu.com/security/notices/USN-5471-1, https://ubuntu.com/security/notices/USN-5484-1, https://www.cve.org/CVERecord?id=CVE-2022-21499
Affected packages
Package
Name: linux-hwe-edge
Purl: pkg:deb/ubuntu/linux-hwe-edge?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
