QID 198295

Date Published: 2021-03-25

QID 198295: Ubuntu Security Notification for Linux, Linux-aws, Linux-kvm, Linux-lts-xenial, Linux-raspi2, (USN-4876-1)

It was discovered a race condition the Xen paravirt block backend in the Linux kernel, leading to a use-after-free vulnerability.

It was discovered that the Marvell WiFi-Ex device driver in the Linux kernel did not properly validate ad-hoc SSIDs.

It was discovered that the NFS implementation in the Linux kernel did not properly prevent access outside of an NFS export that is a subdirectory of a file system.

An attacker in a guest VM could use this to cause a denial of service in the host OS. (CVE-2020-29569)

A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-36158)

An attacker could possibly use this to bypass NFS access restrictions. (CVE-2021-3178)

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Refer to Ubuntu advisory USN-4876-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198295

    Software Advisories
    Advisory ID Software Component Link
    USN-4876-1 16.04 (Xenial) on src linux-image-4.4.0-1089-kvm URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-4.4.0-1123-aws URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-4.4.0-1147-raspi2 URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-4.4.0-1151-snapdragon URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-4.4.0-204-generic URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-4.4.0-204-generic-lpae URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-4.4.0-204-lowlatency URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-4.4.0-204-powerpc-e500mc URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-4.4.0-204-powerpc-smp URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-4.4.0-204-powerpc64-emb URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-4.4.0-204-powerpc64-smp URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-aws URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-generic URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-generic-lpae URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-kvm URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-lowlatency URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-powerpc-e500mc URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-powerpc-smp URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-powerpc64-emb URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-powerpc64-smp URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-raspi2 URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-snapdragon URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236
    USN-4876-1 16.04 (Xenial) on src linux-image-virtual URL Logo launchpad.net/ubuntu/+source/linux/4.4.0-204.236