USN-6921-2
Dashboard / Vulnerabilities / USN-6921-2
USN-6921-2
Summary: linux-lowlatency vulnerabilities
Details: Benedict Schlüter, Supraja Sridhara, Andrin Bertschi, and Shweta Shinde discovered that an untrusted hypervisor could inject malicious #VC interrupts and compromise the security guarantees of AMD SEV-SNP. This flaw is known as WeSee. A local attacker in control of the hypervisor could use this to expose sensitive information or possibly execute arbitrary code in the trusted execution environment. (CVE-2024-25742) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - DMA engine subsystem; - HID subsystem; - I2C subsystem; - PHY drivers; - TTY drivers; - IPv4 networking; (CVE-2024-35997, CVE-2024-36016, CVE-2024-35990, CVE-2024-35984, CVE-2024-35992, CVE-2024-36008)
References: https://ubuntu.com/security/notices/USN-6921-2, https://ubuntu.com/security/CVE-2024-25742, https://ubuntu.com/security/CVE-2024-35984, https://ubuntu.com/security/CVE-2024-35990, https://ubuntu.com/security/CVE-2024-35992, https://ubuntu.com/security/CVE-2024-35997, https://ubuntu.com/security/CVE-2024-36008, https://ubuntu.com/security/CVE-2024-36016
Affected packages
Package
Name: linux-lowlatency
Purl: pkg:deb/ubuntu/linux-lowlatency?arch=source&distro=noble
Affected ranges
Type: ECOSYSTEM
Events:
