QID 198625

Date Published: 2022-01-13

QID 198625: Ubuntu Security Notification for Linux kernel Vulnerability (USN-5219-1)

The ebpf implementation in the linux kernel didnot properly validate the memory size of certain ring buffer operationarguments.

A local attacker could use this to cause a denial of service(system crash) or possibly execute arbitrary code.

  • CVSS V3 rated as Medium - 4.2 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5219-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198625

    Software Advisories
    Advisory ID Software Component Link
    USN-5219-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5219-1