QID 198296
Date Published: 2021-03-26
QID 198296: Ubuntu Security Notification for Linux, Linux-aws, Linux-aws-hwe, Linux-azure, Linux-azure-4.15, (USN-4877-1)
It was discovered that the Marvell WiFi-Ex device driver in the Linux kernel did not properly validate ad-hoc SSIDs.
It was discovered that the NFS implementation in the Linux kernel did not properly prevent access outside of an NFS export that is a subdirectory of a file system.
A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-36158)
An attacker could possibly use this to bypass NFS access restrictions. (CVE-2021-3178)
Solution
Refer to Ubuntu advisory USN-4877-1 for affected packages and patching details, or update with your package manager.
Vendor References
- USN-4877-1 -
usn.ubuntu.com/4877-1/
CVEs related to QID 198296
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| USN-4877-1 | 16.04 (Xenial) on src | linux-image-4.15.0-1066-oracle |
|
| USN-4877-1 | 16.04 (Xenial) on src | linux-image-4.15.0-1094-gcp |
|
| USN-4877-1 | 16.04 (Xenial) on src | linux-image-4.15.0-1095-aws |
|
| USN-4877-1 | 16.04 (Xenial) on src | linux-image-4.15.0-1109-azure |
|
| USN-4877-1 | 16.04 (Xenial) on src | linux-image-4.15.0-137-generic |
|
| USN-4877-1 | 16.04 (Xenial) on src | linux-image-4.15.0-137-generic-lpae |
|
| USN-4877-1 | 16.04 (Xenial) on src | linux-image-4.15.0-137-lowlatency |
|
| USN-4877-1 | 16.04 (Xenial) on src | linux-image-aws-hwe |
|
| USN-4877-1 | 16.04 (Xenial) on src | linux-image-azure |
|
| USN-4877-1 | 16.04 (Xenial) on src | linux-image-gcp |
|
| USN-4877-1 | 16.04 (Xenial) on src | linux-image-generic-hwe-16.04 |
|
| USN-4877-1 | 16.04 (Xenial) on src | linux-image-generic-lpae-hwe-16.04 |
|
| USN-4877-1 | 16.04 (Xenial) on src | linux-image-gke |
|
| USN-4877-1 | 16.04 (Xenial) on src | linux-image-lowlatency-hwe-16.04 |
|
| USN-4877-1 | 16.04 (Xenial) on src | linux-image-oem |
|
| USN-4877-1 | 16.04 (Xenial) on src | linux-image-oracle |
|
| USN-4877-1 | 16.04 (Xenial) on src | linux-image-virtual-hwe-16.04 |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-4.15.0-1013-dell300x |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-4.15.0-1066-oracle |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-4.15.0-1080-raspi2 |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-4.15.0-1086-kvm |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-4.15.0-1094-gcp |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-4.15.0-1095-aws |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-4.15.0-1097-snapdragon |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-4.15.0-1109-azure |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-4.15.0-137-generic |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-4.15.0-137-generic-lpae |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-4.15.0-137-lowlatency |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-aws-lts-18.04 |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-azure-lts-18.04 |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-dell300x |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-gcp-lts-18.04 |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-generic |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-generic-lpae |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-kvm |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-lowlatency |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-oracle-lts-18.04 |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-powerpc-e500mc |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-powerpc-smp |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-powerpc64-emb |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-powerpc64-smp |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-raspi2 |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-snapdragon |
|
| USN-4877-1 | 18.04 (bionic) on src | linux-image-virtual |
|