QID 198333
Date Published: 2021-04-26
QID 198333: Ubuntu Security Notification for Linux kernel vulnerabilities (USN-4917-1)
The overlayfs implementation in the linux kernel did
not properly validate the application of file system capabilities with
respect to user namespaces
The shiftfs file system in the ubuntu linux
kernel did not properly handle faults in copy_from_user() when passing
through ioctls to an underlying file system
The bpf jit compiler for x86 in the linux
kernel did not properly validate computation of branch displacements in
some situations
A local attacker could use this to gain
elevated privileges
(CVE-2021-3493)
A local attacker could use
this to cause a denial of service (memory exhaustion) or execute arbitrary
code
(CVE-2021-3492)
A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code
(CVE-2021-29154)
- USN-4917-1 -
usn.ubuntu.com/4917-1
CVEs related to QID 198333
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| USN-4917-1 | Ubuntu Linux |
|