QID 198377

Date Published: 2021-05-31

QID 198377: Ubuntu Security Notification for Linux kernel (Raspberry Pi) vulnerabilities (USN-4945-2)

Usn-4945-1 fixed vulnerabilities in the linux kernel for ubuntu 20.04 lts and ubuntu 18.04 lts. The nouveau gpu driver in the linux kernel did not properly handle error conditions in some situations.
The xen netback backend in the linux kernel did not properly handle certain error conditions under paravirtualization.
The fastrpc driver in the linux kernel did not prevent user space applications from sending kernel rpc messages.
The realtek rtl8188eu wireless device driver in the linux kernel did not properly validate ssid lengths in some situations.
The usb/ip driver in the linux kernel contained race conditions during the update of local and shared status.
A race condition existed in the netfilter subsystem of the linux kernel when replacing tables.
The video4linux subsystem in the linux kernel did not properly deallocate memory in some situations.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.


This update provides the corresponding linux kernel updates targeted specifically for raspberry pi devices in those same ubuntu releases.
A local attacker could use this to cause a denial of service (system crash) (cve-2020-25639).
An attacker in a guest vm could possibly use this to cause a denial of service (host domain crash) (cve-2021-28038).
A local attacker could possibly use this to gain elevated privileges.
(cve-2021-28375).
An attacker could use this to cause a denial of service (system crash).
(cve-2021-28660).
An attacker could use this to cause a denial of service (system crash) (cve-2021-29265).
A local attacker could use this to cause a denial of service (system crash) (cve-2021-29650).
A local attacker could use this to cause a denial of service (memory exhaustion).
(cve-2021-30002).

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Refer to Ubuntu advisory: USN-4945-2 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-4945-2 Ubuntu Linux URL Logo usn.ubuntu.com/4945-2