QID 198624

Date Published: 2022-01-13

QID 198624: Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-5217-1)

The nfs server implementation in the linux kernelcontained an out-of-bounds write vulnerability.
The ebpf implementation in the linux kernel didnot properly validate the memory size of certain ring buffer operationarguments.

A local attacker could usethis to cause a denial of service (system crash) or possibly executearbitrary code.
A local attacker could use this to cause a denial of service(system crash) or possibly execute arbitrary code.

  • CVSS V3 rated as Medium - 4.2 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5217-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198624

    Software Advisories
    Advisory ID Software Component Link
    USN-5217-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5217-1