QID 198694

Date Published: 2022-03-09

QID 198694: Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5317-1)

The linux kernel incorrectly handled networkoffload functionality.
Hardware mitigations added by arm to theirprocessors to address spectre-bti were insufficient.
The linux kernel incorrectly handled unixpipes.
Hardware mitigations added by intel to theirprocessors to address spectre-bti were insufficient.

A local attacker could use this to cause a denial ofservice or possibly execute arbitrary code.
A local attacker couldpotentially use this to expose sensitive information.
A local attacker could potentially use this to modify any file thatcould be opened for reading.
A local attacker couldpotentially use this to expose sensitive information.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as High - 7.2 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5317-1 for updates and patch information.
    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    USN-5317-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5317-1