QID 198437

Date Published: 2021-07-21

QID 198437: Ubuntu Security Notification for Linux kernel vulnerabilities (USN-5016-1) (Sequoia)

The virtual file system implementation in the linux kernel contained an unsigned to signed integer conversion error.
Use-after-free vulnerability in the nfc implementation in the linux kernel.
A race condition in the kernel bluetooth subsystem could lead to use-after-free of slab objects.
A use-after-free existed in the bluetooth hci driver of the linux kernel.
An out-of-bounds (oob) memory access flaw existed in the f2fs module of the linux kernel.

Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

a local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (Cve-2021-33909).
A privileged local attacker could use this issue to cause a denial of service (system crash) or possibly execute arbitrary code. (Cve-2021-23134).
An attacker could use this issue to possibly execute arbitrary code. (Cve-2021-32399).
A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (Cve-2021-33034).
A local attacker could use this issue to cause a denial of service (system crash) (cve-2021-3506).

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Refer to Ubuntu advisory: USN-5016-1 for affected packages and patching details, or update with your package manager.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-5016-1 Ubuntu Linux URL Logo usn.ubuntu.com/5016-1