[USN-4068-1] Linux kernel vulnerabilities

Severity Medium
Affected Packages 27
CVEs 4

Several security issues were fixed in the Linux kernel.

Adam Zabrocki discovered that the Intel i915 kernel mode graphics driver in
the Linux kernel did not properly restrict mmap() ranges in some
situations. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2019-11085)

It was discovered that a race condition leading to a use-after-free existed
in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux
kernel. The RDS protocol is disabled via blocklist by default in Ubuntu.
If enabled, a local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2019-11815)

It was discovered that the ext4 file system implementation in the Linux
kernel did not properly zero out memory in some situations. A local
attacker could use this to expose sensitive information (kernel memory).
(CVE-2019-11833)

It was discovered that the Bluetooth Human Interface Device Protocol (HIDP)
implementation in the Linux kernel did not properly verify strings were
NULL terminated in certain situations. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2019-11884)

Package Affected Version
pkg:deb/ubuntu/linux-image-virtual?distro=bionic < 4.15.0.55.57
pkg:deb/ubuntu/linux-image-virtual-hwe-16.04?distro=bionic < 4.15.0.55.57
pkg:deb/ubuntu/linux-image-virtual-hwe-16.04-edge?distro=bionic < 4.15.0.55.57
pkg:deb/ubuntu/linux-image-snapdragon?distro=bionic < 4.15.0.1058.61
pkg:deb/ubuntu/linux-image-raspi2?distro=bionic < 4.15.0.1041.39
pkg:deb/ubuntu/linux-image-oracle?distro=bionic < 4.15.0.1018.21
pkg:deb/ubuntu/linux-image-lowlatency?distro=bionic < 4.15.0.55.57
pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04?distro=bionic < 4.15.0.55.57
pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04-edge?distro=bionic < 4.15.0.55.57
pkg:deb/ubuntu/linux-image-kvm?distro=bionic < 4.15.0.1039.39
pkg:deb/ubuntu/linux-image-generic?distro=bionic < 4.15.0.55.57
pkg:deb/ubuntu/linux-image-generic-lpae?distro=bionic < 4.15.0.55.57
pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04?distro=bionic < 4.15.0.55.57
pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04-edge?distro=bionic < 4.15.0.55.57
pkg:deb/ubuntu/linux-image-generic-hwe-16.04?distro=bionic < 4.15.0.55.57
pkg:deb/ubuntu/linux-image-generic-hwe-16.04-edge?distro=bionic < 4.15.0.55.57
pkg:deb/ubuntu/linux-image-gcp?distro=bionic < 4.15.0.1037.39
pkg:deb/ubuntu/linux-image-aws?distro=bionic < 4.15.0.1044.43
pkg:deb/ubuntu/linux-image-4.15.0-55-lowlatency?distro=bionic < 4.15.0-55.60
pkg:deb/ubuntu/linux-image-4.15.0-55-generic?distro=bionic < 4.15.0-55.60
pkg:deb/ubuntu/linux-image-4.15.0-55-generic-lpae?distro=bionic < 4.15.0-55.60
pkg:deb/ubuntu/linux-image-4.15.0-1058-snapdragon?distro=bionic < 4.15.0-1058.64
pkg:deb/ubuntu/linux-image-4.15.0-1044-aws?distro=bionic < 4.15.0-1044.46
pkg:deb/ubuntu/linux-image-4.15.0-1041-raspi2?distro=bionic < 4.15.0-1041.44
pkg:deb/ubuntu/linux-image-4.15.0-1039-kvm?distro=bionic < 4.15.0-1039.39
pkg:deb/ubuntu/linux-image-4.15.0-1037-gcp?distro=bionic < 4.15.0-1037.39
pkg:deb/ubuntu/linux-image-4.15.0-1018-oracle?distro=bionic < 4.15.0-1018.20
ID
USN-4068-1
Severity
medium
URL
https://ubuntu.com/security/notices/USN-4068-1
Published
2019-07-23T03:20:44
(5 years ago)
Modified
2019-07-23T03:20:44
(5 years ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/linux-image-virtual?distro=bionic ubuntu linux-image-virtual < 4.15.0.55.57 bionic
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-16.04?distro=bionic ubuntu linux-image-virtual-hwe-16.04 < 4.15.0.55.57 bionic
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-16.04-edge?distro=bionic ubuntu linux-image-virtual-hwe-16.04-edge < 4.15.0.55.57 bionic
Affected pkg:deb/ubuntu/linux-image-snapdragon?distro=bionic ubuntu linux-image-snapdragon < 4.15.0.1058.61 bionic
Affected pkg:deb/ubuntu/linux-image-raspi2?distro=bionic ubuntu linux-image-raspi2 < 4.15.0.1041.39 bionic
Affected pkg:deb/ubuntu/linux-image-oracle?distro=bionic ubuntu linux-image-oracle < 4.15.0.1018.21 bionic
Affected pkg:deb/ubuntu/linux-image-lowlatency?distro=bionic ubuntu linux-image-lowlatency < 4.15.0.55.57 bionic
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04?distro=bionic ubuntu linux-image-lowlatency-hwe-16.04 < 4.15.0.55.57 bionic
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04-edge?distro=bionic ubuntu linux-image-lowlatency-hwe-16.04-edge < 4.15.0.55.57 bionic
Affected pkg:deb/ubuntu/linux-image-kvm?distro=bionic ubuntu linux-image-kvm < 4.15.0.1039.39 bionic
Affected pkg:deb/ubuntu/linux-image-generic?distro=bionic ubuntu linux-image-generic < 4.15.0.55.57 bionic
Affected pkg:deb/ubuntu/linux-image-generic-lpae?distro=bionic ubuntu linux-image-generic-lpae < 4.15.0.55.57 bionic
Affected pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04?distro=bionic ubuntu linux-image-generic-lpae-hwe-16.04 < 4.15.0.55.57 bionic
Affected pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04-edge?distro=bionic ubuntu linux-image-generic-lpae-hwe-16.04-edge < 4.15.0.55.57 bionic
Affected pkg:deb/ubuntu/linux-image-generic-hwe-16.04?distro=bionic ubuntu linux-image-generic-hwe-16.04 < 4.15.0.55.57 bionic
Affected pkg:deb/ubuntu/linux-image-generic-hwe-16.04-edge?distro=bionic ubuntu linux-image-generic-hwe-16.04-edge < 4.15.0.55.57 bionic
Affected pkg:deb/ubuntu/linux-image-gcp?distro=bionic ubuntu linux-image-gcp < 4.15.0.1037.39 bionic
Affected pkg:deb/ubuntu/linux-image-aws?distro=bionic ubuntu linux-image-aws < 4.15.0.1044.43 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-55-lowlatency?distro=bionic ubuntu linux-image-4.15.0-55-lowlatency < 4.15.0-55.60 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-55-generic?distro=bionic ubuntu linux-image-4.15.0-55-generic < 4.15.0-55.60 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-55-generic-lpae?distro=bionic ubuntu linux-image-4.15.0-55-generic-lpae < 4.15.0-55.60 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1058-snapdragon?distro=bionic ubuntu linux-image-4.15.0-1058-snapdragon < 4.15.0-1058.64 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1044-aws?distro=bionic ubuntu linux-image-4.15.0-1044-aws < 4.15.0-1044.46 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1041-raspi2?distro=bionic ubuntu linux-image-4.15.0-1041-raspi2 < 4.15.0-1041.44 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1039-kvm?distro=bionic ubuntu linux-image-4.15.0-1039-kvm < 4.15.0-1039.39 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1037-gcp?distro=bionic ubuntu linux-image-4.15.0-1037-gcp < 4.15.0-1037.39 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1018-oracle?distro=bionic ubuntu linux-image-4.15.0-1018-oracle < 4.15.0-1018.20 bionic
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...