QID 198655

Date Published: 2022-02-07

QID 198655: Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5268-1)

The icmp implementation in the linux kernel didnot properly handle received icmp error packets.
The bluetooth subsystem in the linux kernelcontained a use-after-free vulnerability.
A race condition existed in the bluetoothsubsystem of the linux kernel, leading to a use-after-free vulnerability.
The firedtv firewire driver in the linux kerneldid not properly perform bounds checking in some situations.

A remote attacker coulduse this to facilitate attacks on udp based services that depend on sourceport randomization.
A local attacker could use thisto cause a denial of service (system crash) or possibly execute arbitrarycode.
Alocal attacker could use this to cause a denial of service (system crash)or possibly execute arbitrary code.
A localattacker could use this to cause a denial of service (system crash) orpossibly execute arbitrary code.

  • CVSS V3 rated as High - 6.7 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5268-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198655

    Software Advisories
    Advisory ID Software Component Link
    USN-5268-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5268-1