QID 198332
Date Published: 2021-04-26
QID 198332: Ubuntu Security Notification for Linux kernel vulnerabilities (USN-4916-1)
The overlayfs implementation in the linux kernel did
not properly validate the application of file system capabilities with
respect to user namespaces
The bpf jit compiler for x86 in the linux
kernel did not properly validate computation of branch displacements in
some situations
A local attacker could use this to gain
elevated privileges
(CVE-2021-3493)
A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code
(CVE-2021-29154)
Solution
Refer to Ubuntu advisory: USN-4916-1 for affected packages and patching details, or update with your package manager.
Vendor References
- USN-4916-1 -
usn.ubuntu.com/4916-1
CVEs related to QID 198332
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| USN-4916-1 | Ubuntu Linux |
|