[USN-4069-1] Linux kernel vulnerabilities

Severity High
Affected Packages 20
CVEs 4

Several security issues were fixed in the Linux kernel.

It was discovered that an integer overflow existed in the Linux kernel when
reference counting pages, leading to potential use-after-free issues. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2019-11487)

Jann Horn discovered that a race condition existed in the Linux kernel when
performing core dumps. A local attacker could use this to cause a denial of
service (system crash) or expose sensitive information. (CVE-2019-11599)

It was discovered that the ext4 file system implementation in the Linux
kernel did not properly zero out memory in some situations. A local
attacker could use this to expose sensitive information (kernel memory).
(CVE-2019-11833)

It was discovered that the Bluetooth Human Interface Device Protocol (HIDP)
implementation in the Linux kernel did not properly verify strings were
NULL terminated in certain situations. A local attacker could use this to
expose sensitive information (kernel memory). (CVE-2019-11884)

ID
USN-4069-1
Severity
high
Severity from
CVE-2019-11487
URL
https://ubuntu.com/security/notices/USN-4069-1
Published
2019-07-23T06:28:52
(5 years ago)
Modified
2019-07-23T06:28:52
(5 years ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/linux-image-virtual?distro=disco ubuntu linux-image-virtual < 5.0.0.21.22 disco
Affected pkg:deb/ubuntu/linux-image-snapdragon?distro=disco ubuntu linux-image-snapdragon < 5.0.0.1017.10 disco
Affected pkg:deb/ubuntu/linux-image-raspi2?distro=disco ubuntu linux-image-raspi2 < 5.0.0.1013.10 disco
Affected pkg:deb/ubuntu/linux-image-lowlatency?distro=disco ubuntu linux-image-lowlatency < 5.0.0.21.22 disco
Affected pkg:deb/ubuntu/linux-image-kvm?distro=disco ubuntu linux-image-kvm < 5.0.0.1011.11 disco
Affected pkg:deb/ubuntu/linux-image-gke?distro=disco ubuntu linux-image-gke < 5.0.0.1011.11 disco
Affected pkg:deb/ubuntu/linux-image-generic?distro=disco ubuntu linux-image-generic < 5.0.0.21.22 disco
Affected pkg:deb/ubuntu/linux-image-generic-lpae?distro=disco ubuntu linux-image-generic-lpae < 5.0.0.21.22 disco
Affected pkg:deb/ubuntu/linux-image-gcp?distro=disco ubuntu linux-image-gcp < 5.0.0.1011.11 disco
Affected pkg:deb/ubuntu/linux-image-azure?distro=disco ubuntu linux-image-azure < 5.0.0.1012.11 disco
Affected pkg:deb/ubuntu/linux-image-aws?distro=disco ubuntu linux-image-aws < 5.0.0.1011.11 disco
Affected pkg:deb/ubuntu/linux-image-5.0.0-21-lowlatency?distro=disco ubuntu linux-image-5.0.0-21-lowlatency < 5.0.0-21.22 disco
Affected pkg:deb/ubuntu/linux-image-5.0.0-21-generic?distro=disco ubuntu linux-image-5.0.0-21-generic < 5.0.0-21.22 disco
Affected pkg:deb/ubuntu/linux-image-5.0.0-21-generic-lpae?distro=disco ubuntu linux-image-5.0.0-21-generic-lpae < 5.0.0-21.22 disco
Affected pkg:deb/ubuntu/linux-image-5.0.0-1017-snapdragon?distro=disco ubuntu linux-image-5.0.0-1017-snapdragon < 5.0.0-1017.18 disco
Affected pkg:deb/ubuntu/linux-image-5.0.0-1013-raspi2?distro=disco ubuntu linux-image-5.0.0-1013-raspi2 < 5.0.0-1013.13 disco
Affected pkg:deb/ubuntu/linux-image-5.0.0-1012-azure?distro=disco ubuntu linux-image-5.0.0-1012-azure < 5.0.0-1012.12 disco
Affected pkg:deb/ubuntu/linux-image-5.0.0-1011-kvm?distro=disco ubuntu linux-image-5.0.0-1011-kvm < 5.0.0-1011.12 disco
Affected pkg:deb/ubuntu/linux-image-5.0.0-1011-gcp?distro=disco ubuntu linux-image-5.0.0-1011-gcp < 5.0.0-1011.11 disco
Affected pkg:deb/ubuntu/linux-image-5.0.0-1011-aws?distro=disco ubuntu linux-image-5.0.0-1011-aws < 5.0.0-1011.12 disco
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...