QID 198747
Date Published: 2022-04-21
QID 198747: Ubuntu Security Notification for Linux kernel (OEM) Vulnerabilities (USN-5381-1)
The netfilter subsystem in the linux kerneldid not properly validate passed user register indices.
The block layer subsystem in the linux kernel didnot properly initialize memory in some situations.
The dma subsystem in the linux kernel did notproperly ensure bounce buffers were completely overwritten by the dmadevice.
The fuse file system in the linux kernelcontained a use-after-free vulnerability.
The netfilter subsystem in the linux kerneldid not initialize memory in some situations.
Multiple race conditions existed in the advancedlinux sound architecture (alsa) framework, leading to use-after-freevulnerabilities.
The usb gadget file system interface in the linuxkernel contained a use-after-free vulnerability.
The st21nfca nfc driver in the linux kernel did notproperly validate the size of certain data in evt_transaction events.
The usb sr9700 ethernet device driver for the linuxkernel did not properly validate the length of requests from the device.
The xilinx usb2 device gadget driver in the linuxkernel did not properly validate endpoint indices from the host.
The 802.
A local attackercould use this to cause a denial of service or possibly execute arbitrarycode.
A privileged localattacker could use this to expose sensitive information (kernel memory).
A local attacker could use this to expose sensitive information(kernel memory).
A local attacker could use thisto cause a denial of service (system crash) or possibly execute arbitrarycode.
A local attacker could usethis to expose sensitive information (kernel memory).
A local attacker could use these to cause a denial ofservice (system crash) or possibly execute arbitrary code.
A local attacker could usethis to cause a denial of service (system crash) or possibly executearbitrary code.
Aphysically proximate attacker could use this to cause a denial of service(system crash) or possibly execute arbitrary code.
Aphysically proximate attacker could possibly use this to expose sensitiveinformation (kernel memory).
Aphysically proximate attacker could possibly use this to cause a denial ofservice (system crash).
2 llc type 2 driver in the linux kernel did notproperly perform reference counting in some error conditions.
A localattacker could use this to cause a denial of service.
- USN-5381-1 -
ubuntu.com/security/notices/USN-5381-1
CVEs related to QID 198747
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| USN-5381-1 | Ubuntu Linux |
|