QID 198371
Date Published: 2021-05-27
QID 198371: Ubuntu Security Notification for Linux kernel vulnerabilities (USN-4946-1)
The drm subsystem in the linux kernel contained double-free vulnerabilities.
The xen paravirtualization backend in the linux kernel did not properly propagate errors to frontend drivers in some situations.
Multiple xen backends in the linux kernel did not properly handle certain error conditions under paravirtualization.
The xen netback backend in the linux kernel did not properly handle certain error conditions under paravirtualization.
The xen paravirtualization backend in the linux kernel did not properly deallocate memory in some situations.
The freescale gianfar ethernet driver for the linux kernel did not properly handle receive queue overrun when jumbo frames were enabled in some situations.
The usb/ip driver in the linux kernel contained race conditions during the update of local and shared status.
A race condition existed in the netfilter subsystem of the linux kernel when replacing tables.
The video4linux subsystem in the linux kernel did not properly deallocate memory in some situations.
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
a privileged attacker could possibly use this to cause a denial of service (system crash) or possibly execute arbitrary code. (
cve-2021-20292).
An attacker in a guest vm could possibly use this to cause a denial of service (host domain crash) (cve-2021-26930).
An attacker in a guest vm could possibly use this to cause a denial of service (host domain crash) (cve-2021-26931).
An attacker in a guest vm could possibly use this to cause a denial of service (host domain crash) (cve-2021-28038).
A local attacker could use this to cause a denial of service (memory exhaustion).
(cve-2021-28688).
An attacker could use this to cause a denial of service (system crash) (cve-2021-29264).
An attacker could use this to cause a denial of service (system crash) (cve-2021-29265).
A local attacker could use this to cause a denial of service (system crash) (cve-2021-29650).
A local attacker could use this to cause a denial of service (memory exhaustion).
(cve-2021-30002).
- USN-4946-1 -
usn.ubuntu.com/4946-1
CVEs related to QID 198371
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| USN-4946-1 | Ubuntu Linux |
|