QID 198295
Date Published: 2021-03-25
QID 198295: Ubuntu Security Notification for Linux, Linux-aws, Linux-kvm, Linux-lts-xenial, Linux-raspi2, (USN-4876-1)
It was discovered a race condition the Xen paravirt block backend in the Linux kernel, leading to a use-after-free vulnerability.
It was discovered that the Marvell WiFi-Ex device driver in the Linux kernel did not properly validate ad-hoc SSIDs.
It was discovered that the NFS implementation in the Linux kernel did not properly prevent access outside of an NFS export that is a subdirectory of a file system.
An attacker in a guest VM could use this to cause a denial of service in the host OS. (CVE-2020-29569)
A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-36158)
An attacker could possibly use this to bypass NFS access restrictions. (CVE-2021-3178)
Solution
Refer to Ubuntu advisory USN-4876-1 for affected packages and patching details, or update with your package manager.
Vendor References
- USN-4876-1 -
usn.ubuntu.com/4876-1/
CVEs related to QID 198295
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-4.4.0-1089-kvm |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-4.4.0-1123-aws |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-4.4.0-1147-raspi2 |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-4.4.0-1151-snapdragon |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-4.4.0-204-generic |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-4.4.0-204-generic-lpae |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-4.4.0-204-lowlatency |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-4.4.0-204-powerpc-e500mc |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-4.4.0-204-powerpc-smp |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-4.4.0-204-powerpc64-emb |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-4.4.0-204-powerpc64-smp |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-aws |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-generic |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-generic-lpae |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-kvm |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-lowlatency |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-powerpc-e500mc |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-powerpc-smp |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-powerpc64-emb |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-powerpc64-smp |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-raspi2 |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-snapdragon |
|
| USN-4876-1 | 16.04 (Xenial) on src | linux-image-virtual |
|