QID 198297

Date Published: 2021-03-26

QID 198297: Ubuntu Security Notification for Linux, Linux-aws, Linux-aws-5.4, Linux-azure, Linux-azure-5.4, Linux-gcp, (USN-4878-1)

It was discovered that the Marvell WiFi-Ex device driver in the Linux kernel did not properly validate ad-hoc SSIDs.

It was discovered that the sockopt BPF hooks in the Linux kernel could allow a user space program to probe for valid kernel addresses.

It was discovered that the priority inheritance futex implementation in the Linux kernel contained a race condition, leading to a use-after-free vulnerability.

It was discovered that the NFS implementation in the Linux kernel did not properly prevent access outside of an NFS export that is a subdirectory of a file system.

A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-36158)

A local attacker could use this to ease exploitation of another kernel vulnerability. (CVE-2021-20239)

A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-3347)

An attacker could possibly use this to bypass NFS access restrictions. (CVE-2021-3178)

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Refer to Ubuntu advisory USN-4878-1 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 198297

    Software Advisories
    Advisory ID Software Component Link
    USN-4878-1 18.04 (bionic) on src linux-image-5.4.0-1011-gkeop URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-5.4.0-1030-raspi URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-5.4.0-1037-gke URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-5.4.0-1038-gcp URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-5.4.0-1039-aws URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-5.4.0-1039-oracle URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-5.4.0-1041-azure URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-5.4.0-67-generic URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-5.4.0-67-generic-lpae URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-5.4.0-67-lowlatency URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-aws URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-aws-edge URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-azure URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-azure-edge URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-gcp URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-gcp-edge URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-generic-hwe-18.04 URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-generic-lpae-hwe-18.04 URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-gke-5.4 URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-gkeop-5.4 URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-lowlatency-hwe-18.04 URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-oem URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-oem-osp1 URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-oracle URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-raspi-hwe-18.04 URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-snapdragon-hwe-18.04 URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 18.04 (bionic) on src linux-image-virtual-hwe-18.04 URL Logo launchpad.net/ubuntu/+source/linux-aws/5.4.0-1039.41
    USN-4878-1 20.04 (focal) on src linux-image-5.4.0-1011-gkeop URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-5.4.0-1030-raspi URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-5.4.0-1034-kvm URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-5.4.0-1038-gcp URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-5.4.0-1039-aws URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-5.4.0-1039-oracle URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-5.4.0-1041-azure URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-5.4.0-67-generic URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-5.4.0-67-generic-lpae URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-5.4.0-67-lowlatency URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-aws URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-azure URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-gcp URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-generic URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-generic-lpae URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-gkeop URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-gkeop-5.4 URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-kvm URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-lowlatency URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-oem URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-oem-osp1 URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-oracle URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-raspi URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-raspi2 URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75
    USN-4878-1 20.04 (focal) on src linux-image-virtual URL Logo launchpad.net/ubuntu/+source/linux/5.4.0-67.75