[USN-4313-1] Linux kernel vulnerability

Severity High
Affected Packages 45
CVEs 1

The system could be made to expose sensitive information or run programs as an administrator.

Manfred Paul discovered that the bpf verifier in the Linux kernel did not
properly calculate register bounds for certain operations. A local attacker
could use this to expose sensitive information (kernel memory) or gain
administrative privileges.

Package Affected Version
pkg:deb/ubuntu/linux-image-virtual?distro=eoan < 5.3.0.45.38
pkg:deb/ubuntu/linux-image-virtual-hwe-18.04?distro=bionic < 5.3.0.45.101
pkg:deb/ubuntu/linux-image-virtual-hwe-18.04-edge?distro=bionic < 5.3.0.45.101
pkg:deb/ubuntu/linux-image-snapdragon?distro=eoan < 5.3.0.45.38
pkg:deb/ubuntu/linux-image-snapdragon-hwe-18.04?distro=bionic < 5.3.0.45.101
pkg:deb/ubuntu/linux-image-snapdragon-hwe-18.04-edge?distro=bionic < 5.3.0.45.101
pkg:deb/ubuntu/linux-image-raspi2?distro=eoan < 5.3.0.1021.18
pkg:deb/ubuntu/linux-image-raspi2-hwe-18.04?distro=bionic < 5.3.0.1021.10
pkg:deb/ubuntu/linux-image-oracle?distro=eoan < 5.3.0.1013.14
pkg:deb/ubuntu/linux-image-oracle-edge?distro=bionic < 5.3.0.1013.12
pkg:deb/ubuntu/linux-image-lowlatency?distro=eoan < 5.3.0.45.38
pkg:deb/ubuntu/linux-image-lowlatency-hwe-18.04?distro=bionic < 5.3.0.45.101
pkg:deb/ubuntu/linux-image-lowlatency-hwe-18.04-edge?distro=bionic < 5.3.0.45.101
pkg:deb/ubuntu/linux-image-kvm?distro=eoan < 5.3.0.1014.16
pkg:deb/ubuntu/linux-image-gke?distro=eoan < 5.3.0.1016.17
pkg:deb/ubuntu/linux-image-gke-5.3?distro=bionic < 5.3.0.1016.6
pkg:deb/ubuntu/linux-image-generic?distro=eoan < 5.3.0.45.38
pkg:deb/ubuntu/linux-image-generic-lpae?distro=eoan < 5.3.0.45.38
pkg:deb/ubuntu/linux-image-generic-lpae-hwe-18.04?distro=bionic < 5.3.0.45.101
pkg:deb/ubuntu/linux-image-generic-lpae-hwe-18.04-edge?distro=bionic < 5.3.0.45.101
pkg:deb/ubuntu/linux-image-generic-hwe-18.04?distro=bionic < 5.3.0.45.101
pkg:deb/ubuntu/linux-image-generic-hwe-18.04-edge?distro=bionic < 5.3.0.45.101
pkg:deb/ubuntu/linux-image-gcp?distro=eoan < 5.3.0.1016.17
pkg:deb/ubuntu/linux-image-gcp-edge?distro=bionic < 5.3.0.1016.15
pkg:deb/ubuntu/linux-image-azure?distro=eoan < 5.3.0.1018.37
pkg:deb/ubuntu/linux-image-azure-edge?distro=bionic < 5.3.0.1018.18
pkg:deb/ubuntu/linux-image-aws?distro=eoan < 5.3.0.1015.17
pkg:deb/ubuntu/linux-image-5.3.0-45-snapdragon?distro=eoan < 5.3.0-45.37
pkg:deb/ubuntu/linux-image-5.3.0-45-lowlatency?distro=eoan < 5.3.0-45.37
pkg:deb/ubuntu/linux-image-5.3.0-45-lowlatency?distro=bionic < 5.3.0-45.37~18.04.1
pkg:deb/ubuntu/linux-image-5.3.0-45-generic?distro=eoan < 5.3.0-45.37
pkg:deb/ubuntu/linux-image-5.3.0-45-generic?distro=bionic < 5.3.0-45.37~18.04.1
pkg:deb/ubuntu/linux-image-5.3.0-45-generic-lpae?distro=eoan < 5.3.0-45.37
pkg:deb/ubuntu/linux-image-5.3.0-45-generic-lpae?distro=bionic < 5.3.0-45.37~18.04.1
pkg:deb/ubuntu/linux-image-5.3.0-1021-raspi2?distro=eoan < 5.3.0-1021.23
pkg:deb/ubuntu/linux-image-5.3.0-1021-raspi2?distro=bionic < 5.3.0-1021.23~18.04.1
pkg:deb/ubuntu/linux-image-5.3.0-1018-azure?distro=eoan < 5.3.0-1018.19
pkg:deb/ubuntu/linux-image-5.3.0-1018-azure?distro=bionic < 5.3.0-1018.19~18.04.1
pkg:deb/ubuntu/linux-image-5.3.0-1016-gke?distro=bionic < 5.3.0-1016.17~18.04.1
pkg:deb/ubuntu/linux-image-5.3.0-1016-gcp?distro=eoan < 5.3.0-1016.17
pkg:deb/ubuntu/linux-image-5.3.0-1016-gcp?distro=bionic < 5.3.0-1016.17~18.04.1
pkg:deb/ubuntu/linux-image-5.3.0-1015-aws?distro=eoan < 5.3.0-1015.16
pkg:deb/ubuntu/linux-image-5.3.0-1014-kvm?distro=eoan < 5.3.0-1014.15
pkg:deb/ubuntu/linux-image-5.3.0-1013-oracle?distro=eoan < 5.3.0-1013.14
pkg:deb/ubuntu/linux-image-5.3.0-1013-oracle?distro=bionic < 5.3.0-1013.14~18.04.1
ID
USN-4313-1
Severity
high
URL
https://ubuntu.com/security/notices/USN-4313-1
Published
2020-03-30T18:10:34
(4 years ago)
Modified
2020-03-30T18:10:34
(4 years ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/linux-image-virtual?distro=eoan ubuntu linux-image-virtual < 5.3.0.45.38 eoan
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-18.04?distro=bionic ubuntu linux-image-virtual-hwe-18.04 < 5.3.0.45.101 bionic
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-18.04-edge?distro=bionic ubuntu linux-image-virtual-hwe-18.04-edge < 5.3.0.45.101 bionic
Affected pkg:deb/ubuntu/linux-image-snapdragon?distro=eoan ubuntu linux-image-snapdragon < 5.3.0.45.38 eoan
Affected pkg:deb/ubuntu/linux-image-snapdragon-hwe-18.04?distro=bionic ubuntu linux-image-snapdragon-hwe-18.04 < 5.3.0.45.101 bionic
Affected pkg:deb/ubuntu/linux-image-snapdragon-hwe-18.04-edge?distro=bionic ubuntu linux-image-snapdragon-hwe-18.04-edge < 5.3.0.45.101 bionic
Affected pkg:deb/ubuntu/linux-image-raspi2?distro=eoan ubuntu linux-image-raspi2 < 5.3.0.1021.18 eoan
Affected pkg:deb/ubuntu/linux-image-raspi2-hwe-18.04?distro=bionic ubuntu linux-image-raspi2-hwe-18.04 < 5.3.0.1021.10 bionic
Affected pkg:deb/ubuntu/linux-image-oracle?distro=eoan ubuntu linux-image-oracle < 5.3.0.1013.14 eoan
Affected pkg:deb/ubuntu/linux-image-oracle-edge?distro=bionic ubuntu linux-image-oracle-edge < 5.3.0.1013.12 bionic
Affected pkg:deb/ubuntu/linux-image-lowlatency?distro=eoan ubuntu linux-image-lowlatency < 5.3.0.45.38 eoan
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-18.04?distro=bionic ubuntu linux-image-lowlatency-hwe-18.04 < 5.3.0.45.101 bionic
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-18.04-edge?distro=bionic ubuntu linux-image-lowlatency-hwe-18.04-edge < 5.3.0.45.101 bionic
Affected pkg:deb/ubuntu/linux-image-kvm?distro=eoan ubuntu linux-image-kvm < 5.3.0.1014.16 eoan
Affected pkg:deb/ubuntu/linux-image-gke?distro=eoan ubuntu linux-image-gke < 5.3.0.1016.17 eoan
Affected pkg:deb/ubuntu/linux-image-gke-5.3?distro=bionic ubuntu linux-image-gke-5.3 < 5.3.0.1016.6 bionic
Affected pkg:deb/ubuntu/linux-image-generic?distro=eoan ubuntu linux-image-generic < 5.3.0.45.38 eoan
Affected pkg:deb/ubuntu/linux-image-generic-lpae?distro=eoan ubuntu linux-image-generic-lpae < 5.3.0.45.38 eoan
Affected pkg:deb/ubuntu/linux-image-generic-lpae-hwe-18.04?distro=bionic ubuntu linux-image-generic-lpae-hwe-18.04 < 5.3.0.45.101 bionic
Affected pkg:deb/ubuntu/linux-image-generic-lpae-hwe-18.04-edge?distro=bionic ubuntu linux-image-generic-lpae-hwe-18.04-edge < 5.3.0.45.101 bionic
Affected pkg:deb/ubuntu/linux-image-generic-hwe-18.04?distro=bionic ubuntu linux-image-generic-hwe-18.04 < 5.3.0.45.101 bionic
Affected pkg:deb/ubuntu/linux-image-generic-hwe-18.04-edge?distro=bionic ubuntu linux-image-generic-hwe-18.04-edge < 5.3.0.45.101 bionic
Affected pkg:deb/ubuntu/linux-image-gcp?distro=eoan ubuntu linux-image-gcp < 5.3.0.1016.17 eoan
Affected pkg:deb/ubuntu/linux-image-gcp-edge?distro=bionic ubuntu linux-image-gcp-edge < 5.3.0.1016.15 bionic
Affected pkg:deb/ubuntu/linux-image-azure?distro=eoan ubuntu linux-image-azure < 5.3.0.1018.37 eoan
Affected pkg:deb/ubuntu/linux-image-azure-edge?distro=bionic ubuntu linux-image-azure-edge < 5.3.0.1018.18 bionic
Affected pkg:deb/ubuntu/linux-image-aws?distro=eoan ubuntu linux-image-aws < 5.3.0.1015.17 eoan
Affected pkg:deb/ubuntu/linux-image-5.3.0-45-snapdragon?distro=eoan ubuntu linux-image-5.3.0-45-snapdragon < 5.3.0-45.37 eoan
Affected pkg:deb/ubuntu/linux-image-5.3.0-45-lowlatency?distro=eoan ubuntu linux-image-5.3.0-45-lowlatency < 5.3.0-45.37 eoan
Affected pkg:deb/ubuntu/linux-image-5.3.0-45-lowlatency?distro=bionic ubuntu linux-image-5.3.0-45-lowlatency < 5.3.0-45.37~18.04.1 bionic
Affected pkg:deb/ubuntu/linux-image-5.3.0-45-generic?distro=eoan ubuntu linux-image-5.3.0-45-generic < 5.3.0-45.37 eoan
Affected pkg:deb/ubuntu/linux-image-5.3.0-45-generic?distro=bionic ubuntu linux-image-5.3.0-45-generic < 5.3.0-45.37~18.04.1 bionic
Affected pkg:deb/ubuntu/linux-image-5.3.0-45-generic-lpae?distro=eoan ubuntu linux-image-5.3.0-45-generic-lpae < 5.3.0-45.37 eoan
Affected pkg:deb/ubuntu/linux-image-5.3.0-45-generic-lpae?distro=bionic ubuntu linux-image-5.3.0-45-generic-lpae < 5.3.0-45.37~18.04.1 bionic
Affected pkg:deb/ubuntu/linux-image-5.3.0-1021-raspi2?distro=eoan ubuntu linux-image-5.3.0-1021-raspi2 < 5.3.0-1021.23 eoan
Affected pkg:deb/ubuntu/linux-image-5.3.0-1021-raspi2?distro=bionic ubuntu linux-image-5.3.0-1021-raspi2 < 5.3.0-1021.23~18.04.1 bionic
Affected pkg:deb/ubuntu/linux-image-5.3.0-1018-azure?distro=eoan ubuntu linux-image-5.3.0-1018-azure < 5.3.0-1018.19 eoan
Affected pkg:deb/ubuntu/linux-image-5.3.0-1018-azure?distro=bionic ubuntu linux-image-5.3.0-1018-azure < 5.3.0-1018.19~18.04.1 bionic
Affected pkg:deb/ubuntu/linux-image-5.3.0-1016-gke?distro=bionic ubuntu linux-image-5.3.0-1016-gke < 5.3.0-1016.17~18.04.1 bionic
Affected pkg:deb/ubuntu/linux-image-5.3.0-1016-gcp?distro=eoan ubuntu linux-image-5.3.0-1016-gcp < 5.3.0-1016.17 eoan
Affected pkg:deb/ubuntu/linux-image-5.3.0-1016-gcp?distro=bionic ubuntu linux-image-5.3.0-1016-gcp < 5.3.0-1016.17~18.04.1 bionic
Affected pkg:deb/ubuntu/linux-image-5.3.0-1015-aws?distro=eoan ubuntu linux-image-5.3.0-1015-aws < 5.3.0-1015.16 eoan
Affected pkg:deb/ubuntu/linux-image-5.3.0-1014-kvm?distro=eoan ubuntu linux-image-5.3.0-1014-kvm < 5.3.0-1014.15 eoan
Affected pkg:deb/ubuntu/linux-image-5.3.0-1013-oracle?distro=eoan ubuntu linux-image-5.3.0-1013-oracle < 5.3.0-1013.14 eoan
Affected pkg:deb/ubuntu/linux-image-5.3.0-1013-oracle?distro=bionic ubuntu linux-image-5.3.0-1013-oracle < 5.3.0-1013.14~18.04.1 bionic
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...