USN-5116-1
Dashboard / Vulnerabilities / USN-5116-1
USN-5116-1
Summary: linux, linux-bluefield, linux-gcp-5.4, linux-hwe-5.4, linux-kvm vulnerabilities
Details: It was discovered that a race condition existed in the Atheros Ath9k WiFi driver in the Linux kernel. An attacker could possibly use this to expose sensitive information (WiFi network traffic). (CVE-2020-3702) Alois Wohlschlager discovered that the overlay file system in the Linux kernel did not restrict private clones in some situations. An attacker could use this to expose sensitive information. (CVE-2021-3732) It was discovered that the KVM hypervisor implementation in the Linux kernel did not properly compute the access permissions for shadow pages in some situations. A local attacker could use this to cause a denial of service. (CVE-2021-38198) It was discovered that the Xilinx 10/100 Ethernet Lite device driver in the Linux kernel could report pointer addresses in some situations. An attacker could use this information to ease the exploitation of another vulnerability. (CVE-2021-38205) It was discovered that the ext4 file system in the Linux kernel contained a race condition when writing xattrs to an inode. A local attacker could use this to cause a denial of service or possibly gain administrative privileges. (CVE-2021-40490) It was discovered that the 6pack network protocol driver in the Linux kernel did not properly perform validation checks. A privileged attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2021-42008)
References: https://ubuntu.com/security/notices/USN-5116-1, https://ubuntu.com/security/CVE-2020-3702, https://ubuntu.com/security/CVE-2021-3732, https://ubuntu.com/security/CVE-2021-38198, https://ubuntu.com/security/CVE-2021-38205, https://ubuntu.com/security/CVE-2021-40490, https://ubuntu.com/security/CVE-2021-42008
Affected packages
Package
Name: linux-gcp-5.4
Purl: pkg:deb/ubuntu/linux-gcp-5.4?arch=source&distro=bionic
Affected ranges
Type: ECOSYSTEM
Events:
