USN-5468-1
Dashboard / Vulnerabilities / USN-5468-1
USN-5468-1
Summary: linux, linux-aws, linux-aws-5.13, linux-azure, linux-azure-5.13, linux-gcp, linux-gcp-5.13, linux-hwe-5.13, linux-intel-5.13, linux-kvm, linux-oracle, linux-oracle-5.13, linux-raspi vulnerabilities
Details: It was discovered that the Linux kernel did not properly restrict access to the kernel debugger when booted in secure boot environments. A privileged attacker could use this to bypass UEFI Secure Boot restrictions. (CVE-2022-21499) Aaron Adams discovered that the netfilter subsystem in the Linux kernel did not properly handle the removal of stateful expressions in some situations, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-1966) Qiuhao Li, Gaoning Pan and Yongkang Jia discovered that the KVM implementation in the Linux kernel did not properly perform guest page table updates in some situations. An attacker in a guest vm could possibly use this to crash the host OS. (CVE-2022-1158) Ziming Zhang discovered that the netfilter subsystem in the Linux kernel did not properly validate sets with multiple ranged fields. A local attacker could use this to cause a denial of service or execute arbitrary code. (CVE-2022-1972) It was discovered that the USB Gadget file system interface in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-24958) It was discovered that the EMS CAN/USB interface implementation in the Linux kernel contained a double-free vulnerability when handling certain error conditions. A local attacker could use this to cause a denial of service (memory exhaustion). (CVE-2022-28390)
References: https://ubuntu.com/security/notices/USN-5468-1, https://ubuntu.com/security/CVE-2022-1158, https://ubuntu.com/security/CVE-2022-1966, https://ubuntu.com/security/CVE-2022-1972, https://ubuntu.com/security/CVE-2022-21499, https://ubuntu.com/security/CVE-2022-24958, https://ubuntu.com/security/CVE-2022-28390
Affected packages
Package
Name: linux-aws-5.13
Purl: pkg:deb/ubuntu/linux-aws-5.13?arch=source&distro=focal
Affected ranges
Type: ECOSYSTEM
Events:
