USN-5727-1

    Dashboard / Vulnerabilities / USN-5727-1

    USN-5727-1

    Published: 16 Nov 2022Last Modified: 25 Jun 2026

    Summary: linux, linux-aws, linux-aws-hwe, linux-dell300x, linux-hwe, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities

    Details: It was discovered that a race condition existed in the instruction emulator of the Linux kernel on Arm 64-bit systems. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-20422) It was discovered that the KVM implementation in the Linux kernel did not properly handle virtual CPUs without APICs in certain situations. A local attacker could possibly use this to cause a denial of service (host system crash). (CVE-2022-2153) Hao Sun and Jiacheng Xu discovered that the NILFS file system implementation in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-2978) Abhishek Shah discovered a race condition in the PF_KEYv2 implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information (kernel memory). (CVE-2022-3028) It was discovered that the IDT 77252 ATM PCI device driver in the Linux kernel did not properly remove any pending timers during device exit, resulting in a use-after-free vulnerability. A local attacker could possibly use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-3635) It was discovered that the Netlink Transformation (XFRM) subsystem in the Linux kernel contained a reference counting error. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-36879) Xingyuan Mo and Gengjia Chen discovered that the Promise SuperTrak EX storage controller driver in the Linux kernel did not properly handle certain structures. A local attacker could potentially use this to expose sensitive information (kernel memory). (CVE-2022-40768)

    Affected packages

    Package

    Name: linux-aws-hwe

    Purl: pkg:deb/ubuntu/linux-aws-hwe?arch=source&distro=esm-infra%2Fxenial

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.15.0-1143.155~16.04.1

    Affected versions

    4.15.0-1030.31~16.04.1
    4.15.0-1031.33~16.04.1
    4.15.0-1032.34~16.04.1
    4.15.0-1033.35~16.04.1
    4.15.0-1035.37~16.04.1
    4.15.0-1036.38~16.04.1
    4.15.0-1039.41~16.04.1
    4.15.0-1040.42~16.04.1
    4.15.0-1041.43~16.04.1
    4.15.0-1043.45~16.04.1
    4.15.0-1044.46~16.04.1
    4.15.0-1045.47~16.04.1
    4.15.0-1047.49~16.04.1
    4.15.0-1048.50~16.04.1
    4.15.0-1050.52~16.04.1
    4.15.0-1051.53~16.04.1
    4.15.0-1052.54~16.04.1
    4.15.0-1054.56~16.04.1
    4.15.0-1056.58~16.04.1
    4.15.0-1057.59~16.04.1
    4.15.0-1058.60~16.04.1
    4.15.0-1060.62~16.04.1
    4.15.0-1063.67~16.04.1
    4.15.0-1065.69~16.04.1
    4.15.0-1066.70~16.04.1
    4.15.0-1067.71~16.04.1
    4.15.0-1073.77~16.04.1
    4.15.0-1074.78~16.04.1
    4.15.0-1079.83~16.04.1
    4.15.0-1080.84~16.04.1
    4.15.0-1082.86~16.04.1
    4.15.0-1083.87~16.04.1
    4.15.0-1085.90~16.04.1
    4.15.0-1088.93~16.04.1
    4.15.0-1090.95~16.04.1
    4.15.0-1091.96~16.04.1
    4.15.0-1093.99~16.04.1
    4.15.0-1094.101~16.04.1
    4.15.0-1095.102~16.04.1
    4.15.0-1096.103~16.04.1
    4.15.0-1097.104~16.04.1
    4.15.0-1098.105~16.04.1
    4.15.0-1099.106~16.04.1
    4.15.0-1102.109~16.04.1
    4.15.0-1103.110~16.04.1
    4.15.0-1106.113~16.04.1
    4.15.0-1109.116~16.04.1
    4.15.0-1110.117~16.04.1
    4.15.0-1111.118~16.04.1
    4.15.0-1112.119~16.04.1
    4.15.0-1113.120~16.04.1
    4.15.0-1115.122~16.04.1
    4.15.0-1116.123~16.04.1
    4.15.0-1118.125~16.04.1
    4.15.0-1119.126~16.04.2
    4.15.0-1120.128~16.04.1
    4.15.0-1123.132~16.04.1
    4.15.0-1124.133~16.04.1
    4.15.0-1126.135~16.04.2
    4.15.0-1127.136~16.04.1
    4.15.0-1128.137~16.04.1
    4.15.0-1130.139~16.04.1
    4.15.0-1133.143~16.04.1
    4.15.0-1136.147~16.04.1
    4.15.0-1137.148~16.04.1
    4.15.0-1139.150~16.04.1
    4.15.0-1140.151~16.04.1
    4.15.0-1141.152~16.04.1
    4.15.0-1142.154~16.04.1

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    USN-5727-1 | CVE-DB