USN-4709-1
Dashboard / Vulnerabilities / USN-4709-1
USN-4709-1
Summary: linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerabilities
Details: It was discovered that the LIO SCSI target implementation in the Linux kernel performed insufficient identifier checking in certain XCOPY requests. An attacker with access to at least one LUN in a multiple backstore environment could use this to expose sensitive information or modify data. (CVE-2020-28374) Wen Xu discovered that the XFS filesystem implementation in the Linux kernel did not properly track inode validations. An attacker could use this to construct a malicious XFS image that, when mounted, could cause a denial of service (system crash). (CVE-2018-13093) It was discovered that the btrfs file system implementation in the Linux kernel did not properly validate file system metadata in some situations. An attacker could use this to construct a malicious btrfs image that, when mounted, could cause a denial of service (system crash). (CVE-2019-19813, CVE-2019-19816) Bodong Zhao discovered a use-after-free in the Sun keyboard driver implementation in the Linux kernel. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2020-25669)
References: https://ubuntu.com/security/notices/USN-4709-1, https://ubuntu.com/security/CVE-2018-13093, https://ubuntu.com/security/CVE-2019-19813, https://ubuntu.com/security/CVE-2019-19816, https://ubuntu.com/security/CVE-2020-25669, https://ubuntu.com/security/CVE-2020-28374
Affected packages
Package
Name: linux-aws
Purl: pkg:deb/ubuntu/linux-aws?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
