USN-4209-1
Dashboard / Vulnerabilities / USN-4209-1
USN-4209-1
Summary: linux, linux-aws, linux-aws-5.0, linux-gcp, linux-gke-5.0, linux-hwe, linux-kvm, linux-oem-osp1, linux-oracle, linux-oracle-5.0, linux-raspi2 vulnerabilities
Details: Jann Horn discovered that the OverlayFS and ShiftFS Drivers in the Linux kernel did not properly handle reference counting during memory mapping operations when used in conjunction with AUFS. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2019-15794) It was discovered that a buffer overflow existed in the 802.11 Wi-Fi configuration interface for the Linux kernel when handling beacon settings. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2019-16746) It was discovered that there was a memory leak in the Advanced Buffer Management functionality of the Netronome NFP4000/NFP6000 NIC Driver in the Linux kernel during certain error scenarios. A local attacker could use this to cause a denial of service (memory exhaustion). (CVE-2019-19076)
References: https://ubuntu.com/security/notices/USN-4209-1, https://ubuntu.com/security/CVE-2019-15794, https://ubuntu.com/security/CVE-2019-16746, https://ubuntu.com/security/CVE-2019-19076
Affected packages
Package
Name: linux-aws-5.0
Purl: pkg:deb/ubuntu/linux-aws-5.0?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
