USN-6503-1
Dashboard / Vulnerabilities / USN-6503-1
USN-6503-1
Summary: linux, linux-aws, linux-laptop, linux-lowlatency, linux-oem-6.5, linux-oracle, linux-raspi, linux-starfive vulnerabilities
Details: Yu Hao discovered that the UBI driver in the Linux kernel did not properly check for MTD with zero erasesize during device attachment. A local privileged attacker could use this to cause a denial of service (system crash). (CVE-2023-31085) Bien Pham discovered that the netfiler subsystem in the Linux kernel contained a race condition, leading to a use-after-free vulnerability. A local user could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-4244) Maxim Levitsky discovered that the KVM nested virtualization (SVM) implementation for AMD processors in the Linux kernel did not properly handle x2AVIC MSRs. An attacker in a guest VM could use this to cause a denial of service (host kernel crash). (CVE-2023-5090) It was discovered that the SMB network file sharing protocol implementation in the Linux kernel did not properly handle certain error conditions, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-5345) Murray McAllister discovered that the VMware Virtual GPU DRM driver in the Linux kernel did not properly handle memory objects when storing surfaces, leading to a use-after-free vulnerability. A local attacker in a guest VM could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-5633)
References: https://ubuntu.com/security/notices/USN-6503-1, https://ubuntu.com/security/CVE-2023-4244, https://ubuntu.com/security/CVE-2023-5090, https://ubuntu.com/security/CVE-2023-5345, https://ubuntu.com/security/CVE-2023-5633, https://ubuntu.com/security/CVE-2023-31085
Affected packages
Package
Name: linux-oem-6.5
Purl: pkg:deb/ubuntu/linux-oem-6.5?arch=source&distro=jammy
Affected ranges
Type: ECOSYSTEM
Events:
