QID 198654

Date Published: 2022-02-07

QID 198654: Ubuntu Security Notification for Linux kernel (GKE) Vulnerabilities (USN-5266-1)

The packet network protocol implementation in thelinux kernel contained a double-free vulnerability.
The firedtv firewire driver in the linux kerneldid not properly perform bounds checking in some situations.

A local attacker coulduse this to cause a denial of service (system crash) or possibly executearbitrary code.
A localattacker could use this to cause a denial of service (system crash) orpossibly execute arbitrary code.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5266-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198654

    Software Advisories
    Advisory ID Software Component Link
    USN-5266-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5266-1