USN-7506-3

    Dashboard / Vulnerabilities / USN-7506-3

    USN-7506-3

    Published: 12 May 2025Last Modified: 5 Oct 2026

    Summary: linux-fips vulnerabilities

    Details: Demi Marie Obenour and Simon Gaiser discovered that several Xen para- virtualization device frontends did not properly restrict the access rights of device backends. An attacker could possibly use a malicious Xen backend to gain access to memory pages of a guest VM or cause a denial of service in the guest. (CVE-2022-23041) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Hardware crypto device drivers; - GPU drivers; - IIO subsystem; - Media drivers; - Network drivers; - SCSI subsystem; - SPI subsystem; - USB Gadget drivers; - Ceph distributed file system; - File systems infrastructure; - JFS file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NILFS2 file system; - SMB network file system; - CAN network layer; - IPv6 networking; - MAC80211 subsystem; - Netfilter; - Netlink; - Network traffic control; - SCTP protocol; - TIPC protocol; (CVE-2024-56598, CVE-2024-56650, CVE-2024-46771, CVE-2024-53173, CVE-2024-53063, CVE-2024-26974, CVE-2021-46959, CVE-2024-53066, CVE-2021-47163, CVE-2024-50237, CVE-2021-47587, CVE-2024-56631, CVE-2024-50256, CVE-2021-47150, CVE-2021-47506, CVE-2021-47219, CVE-2023-52741, CVE-2024-49944, CVE-2025-21971, CVE-2024-26689, CVE-2024-46780, CVE-2024-53140, CVE-2021-47245, CVE-2024-56642, CVE-2021-47500, CVE-2024-36934, CVE-2024-26996, CVE-2024-35864, CVE-2021-47191, CVE-2024-26915, CVE-2024-56770)

    Affected packages

    Package

    Name: linux-fips

    Purl: pkg:deb/ubuntu/linux-fips?arch=source&distro=fips-updates%2Fxenial

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.4.0-1113.120

    Affected versions

    4.4.0-1003.3
    4.4.0-1005.5
    4.4.0-1006.6
    4.4.0-1008.10
    4.4.0-1010.13
    4.4.0-1011.14
    4.4.0-1012.16
    4.4.0-1013.17
    4.4.0-1015.20
    4.4.0-1017.22
    4.4.0-1019.24
    4.4.0-1021.26
    4.4.0-1022.27
    4.4.0-1023.28
    4.4.0-1025.30
    4.4.0-1026.31
    4.4.0-1027.32
    4.4.0-1028.33
    4.4.0-1029.34
    4.4.0-1031.36
    4.4.0-1032.37
    4.4.0-1033.38
    4.4.0-1034.39
    4.4.0-1041.46
    4.4.0-1042.47
    4.4.0-1043.48
    4.4.0-1044.49
    4.4.0-1045.50
    4.4.0-1046.51
    4.4.0-1048.53
    4.4.0-1049.55
    4.4.0-1051.57
    4.4.0-1052.58
    4.4.0-1054.60
    4.4.0-1055.61
    4.4.0-1056.62
    4.4.0-1057.63
    4.4.0-1058.64
    4.4.0-1060.66
    4.4.0-1061.67
    4.4.0-1062.68
    4.4.0-1063.69
    4.4.0-1064.70
    4.4.0-1065.71
    4.4.0-1066.72
    4.4.0-1067.73
    4.4.0-1068.74
    4.4.0-1069.75
    4.4.0-1071.77
    4.4.0-1072.78
    4.4.0-1073.79
    4.4.0-1074.80
    4.4.0-1077.84
    4.4.0-1079.86
    4.4.0-1080.87
    4.4.0-1081.88
    4.4.0-1082.89
    4.4.0-1083.90
    4.4.0-1084.91
    4.4.0-1085.92
    4.4.0-1086.93
    4.4.0-1088.95
    4.4.0-1089.96
    4.4.0-1090.97
    4.4.0-1091.98
    4.4.0-1092.99
    4.4.0-1093.100
    4.4.0-1094.101
    4.4.0-1095.102
    4.4.0-1097.104
    4.4.0-1099.106
    4.4.0-1100.107
    4.4.0-1101.108
    4.4.0-1102.109
    4.4.0-1103.110
    4.4.0-1104.111
    4.4.0-1105.112
    4.4.0-1106.113
    4.4.0-1107.114
    4.4.0-1108.115
    4.4.0-1109.116
    4.4.0-1110.117
    4.4.0-1111.118
    4.4.0-1112.119

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    USN-7506-3 | CVE-DB