USN-4884-1
Dashboard / Vulnerabilities / USN-4884-1
USN-4884-1
Summary: linux-oem-5.10 vulnerabilities
Details: Loris Reiff discovered that the BPF implementation in the Linux kernel did not properly validate attributes in the getsockopt BPF hook. A local attacker could possibly use this to cause a denial of service (system crash). (CVE-2021-20194) It was discovered that the priority inheritance futex implementation in the Linux kernel contained a race condition, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-3347) It was discovered that the network block device (nbd) driver in the Linux kernel contained a use-after-free vulnerability during device setup. A local attacker with access to the nbd device could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-3348)
References: https://ubuntu.com/security/notices/USN-4884-1, https://ubuntu.com/security/CVE-2021-3347, https://ubuntu.com/security/CVE-2021-3348, https://ubuntu.com/security/CVE-2021-20194
Affected packages
Package
Name: linux-oem-5.10
Purl: pkg:deb/ubuntu/linux-oem-5.10?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
