USN-4577-1
Dashboard / Vulnerabilities / USN-4577-1
USN-4577-1
Summary: linux-hwe, linux-gke-5.0, linux-gke-5.3, linux-oem-osp1, linux-raspi2-5.3 vulnerabilities
Details: Hadar Manor discovered that the DCCP protocol implementation in the Linux kernel improperly handled socket reuse, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-16119) Giuseppe Scrivano discovered that the overlay file system in the Linux kernel did not properly perform permission checks in some situations. A local attacker could possibly use this to bypass intended restrictions and gain read access to restricted files. (CVE-2020-16120)
References: https://ubuntu.com/security/notices/USN-4577-1, https://ubuntu.com/security/CVE-2020-16119, https://ubuntu.com/security/CVE-2020-16120
Affected packages
Package
Name: linux-gke-5.0
Purl: pkg:deb/ubuntu/linux-gke-5.0?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
