QID 198666

Date Published: 2022-02-21

QID 198666: Ubuntu Security Notification for Linux kernel (Raspberry Pi) Vulnerabilities (USN-5267-3)

The bluetooth subsystem in the linux kernel contained a use-after-free vulnerability.
A race condition existed in the bluetooth subsystem of the linux kernel, leading to a use-after-free vulnerability.
The firedtv firewire driver in the linux kernel did not properly perform bounds checking in some situations.

Usn-5267-1 fixed vulnerabilities in the linux kernel.
This updateprovides the corresponding updates for the linux kernel for raspberrypi devices.
A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.
A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.
A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.

  • CVSS V3 rated as High - 7.1 severity.
  • CVSS V2 rated as High - 7.9 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5267-3 for updates and patch information.
    Vendor References

    CVEs related to QID 198666

    Software Advisories
    Advisory ID Software Component Link
    USN-5267-3 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5267-3