QID 198721

Date Published: 2022-04-04

QID 198721: Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5358-1)

The network traffic control implementation in thelinux kernel contained a use-after-free vulnerability.
The ipsec implementation in the linux kernel did notproperly allocate enough memory when performing esp transformations,leading to a heap-based buffer overflow.

A local attackercould use this to cause a denial of service (system crash) or possiblyexecute arbitrary code.
A local attacker could use this tocause a denial of service (system crash) or possibly execute arbitrarycode.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5358-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198721

    Software Advisories
    Advisory ID Software Component Link
    USN-5358-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5358-1