USN-5621-1
Dashboard / Vulnerabilities / USN-5621-1
USN-5621-1
Summary: linux, linux-aws, linux-aws-hwe, linux-azure-4.15, linux-dell300x, linux-gcp, linux-gcp-4.15, lnux-hwe, inux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities
Details: It was discovered that the framebuffer driver on the Linux kernel did not verify size limits when changing font or screen size, leading to an out-of- bounds write. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-33655) Domingo Dirutigliano and Nicola Guerrera discovered that the netfilter subsystem in the Linux kernel did not properly handle rules that truncated packets below the packet header size. When such rules are in place, a remote attacker could possibly use this to cause a denial of service (system crash). (CVE-2022-36946)
References: https://ubuntu.com/security/notices/USN-5621-1, https://ubuntu.com/security/CVE-2021-33655, https://ubuntu.com/security/CVE-2022-36946
Affected packages
Package
Name: linux-aws-hwe
Purl: pkg:deb/ubuntu/linux-aws-hwe?arch=source&distro=esm-infra%2Fxenial
Affected ranges
Type: ECOSYSTEM
Events:
