QID 198767

Date Published: 2022-05-05

QID 198767: Ubuntu Security Notification for Linux kernel Vulnerabilities (USN-5390-1)

The netfilter subsystem in the linux kerneldid not properly validate passed user register indices.
The netfilter subsystem in the linux kerneldid not initialize memory in some situations.
The st21nfca nfc driver in the linux kernel did notproperly validate the size of certain data in evt_transaction events.

A local attackercould use this to cause a denial of service or possibly execute arbitrarycode.
A local attacker could usethis to expose sensitive information (kernel memory).
Aphysically proximate attacker could use this to cause a denial of service(system crash) or possibly execute arbitrary code.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution
    Refer to Ubuntu security advisory USN-5390-1 for updates and patch information.
    Vendor References

    CVEs related to QID 198767

    Software Advisories
    Advisory ID Software Component Link
    USN-5390-1 Ubuntu Linux URL Logo ubuntu.com/security/notices/USN-5390-1