[USN-4411-1] Linux kernel vulnerabilities

Severity Low
Affected Packages 35
CVEs 5

Several security issues were fixed in the Linux kernel.

It was discovered that the elf handling code in the Linux kernel did not
initialize memory before using it in certain situations. A local attacker
could use this to possibly expose sensitive information (kernel memory).
(CVE-2020-10732)

Matthew Sheets discovered that the SELinux network label handling
implementation in the Linux kernel could be coerced into de-referencing a
NULL pointer. A remote attacker could use this to cause a denial of service
(system crash). (CVE-2020-10711)

It was discovered that the SCSI generic (sg) driver in the Linux kernel did
not properly handle certain error conditions correctly. A local privileged
attacker could use this to cause a denial of service (system crash).
(CVE-2020-12770)

It was discovered that the USB Gadget device driver in the Linux kernel did
not validate arguments passed from configfs in some situations. A local
attacker could possibly use this to cause a denial of service (system
crash) or possibly expose sensitive information. (CVE-2020-13143)

It was discovered that the KVM implementation in the Linux kernel did not
properly deallocate memory on initialization for some processors. A local
attacker could possibly use this to cause a denial of service.
(CVE-2020-12768)

Package Affected Version
pkg:deb/ubuntu/linux-image-virtual?distro=focal < 5.4.0.40.43
pkg:deb/ubuntu/linux-image-virtual-hwe-20.04?distro=focal < 5.4.0.40.43
pkg:deb/ubuntu/linux-image-virtual-hwe-18.04?distro=focal < 5.4.0.40.43
pkg:deb/ubuntu/linux-image-virtual-hwe-18.04-edge?distro=focal < 5.4.0.40.43
pkg:deb/ubuntu/linux-image-raspi?distro=focal < 5.4.0.1013.13
pkg:deb/ubuntu/linux-image-raspi2?distro=focal < 5.4.0.1013.13
pkg:deb/ubuntu/linux-image-oracle?distro=focal < 5.4.0.1019.17
pkg:deb/ubuntu/linux-image-oem?distro=focal < 5.4.0.40.43
pkg:deb/ubuntu/linux-image-oem-osp1?distro=focal < 5.4.0.40.43
pkg:deb/ubuntu/linux-image-lowlatency?distro=focal < 5.4.0.40.43
pkg:deb/ubuntu/linux-image-lowlatency-hwe-20.04?distro=focal < 5.4.0.40.43
pkg:deb/ubuntu/linux-image-lowlatency-hwe-18.04?distro=focal < 5.4.0.40.43
pkg:deb/ubuntu/linux-image-lowlatency-hwe-18.04-edge?distro=focal < 5.4.0.40.43
pkg:deb/ubuntu/linux-image-kvm?distro=focal < 5.4.0.1018.17
pkg:deb/ubuntu/linux-image-gke?distro=focal < 5.4.0.1019.17
pkg:deb/ubuntu/linux-image-generic?distro=focal < 5.4.0.40.43
pkg:deb/ubuntu/linux-image-generic-lpae?distro=focal < 5.4.0.40.43
pkg:deb/ubuntu/linux-image-generic-lpae-hwe-20.04?distro=focal < 5.4.0.40.43
pkg:deb/ubuntu/linux-image-generic-lpae-hwe-18.04?distro=focal < 5.4.0.40.43
pkg:deb/ubuntu/linux-image-generic-lpae-hwe-18.04-edge?distro=focal < 5.4.0.40.43
pkg:deb/ubuntu/linux-image-generic-hwe-20.04?distro=focal < 5.4.0.40.43
pkg:deb/ubuntu/linux-image-generic-hwe-18.04?distro=focal < 5.4.0.40.43
pkg:deb/ubuntu/linux-image-generic-hwe-18.04-edge?distro=focal < 5.4.0.40.43
pkg:deb/ubuntu/linux-image-gcp?distro=focal < 5.4.0.1019.17
pkg:deb/ubuntu/linux-image-azure?distro=focal < 5.4.0.1020.19
pkg:deb/ubuntu/linux-image-aws?distro=focal < 5.4.0.1018.19
pkg:deb/ubuntu/linux-image-5.4.0-40-lowlatency?distro=focal < 5.4.0-40.44
pkg:deb/ubuntu/linux-image-5.4.0-40-generic?distro=focal < 5.4.0-40.44
pkg:deb/ubuntu/linux-image-5.4.0-40-generic-lpae?distro=focal < 5.4.0-40.44
pkg:deb/ubuntu/linux-image-5.4.0-28-generic?distro=focal < 5.4.0-28.32
pkg:deb/ubuntu/linux-image-5.4.0-1020-azure?distro=focal < 5.4.0-1020.20
pkg:deb/ubuntu/linux-image-5.4.0-1019-oracle?distro=focal < 5.4.0-1019.19
pkg:deb/ubuntu/linux-image-5.4.0-1019-gcp?distro=focal < 5.4.0-1019.19
pkg:deb/ubuntu/linux-image-5.4.0-1018-aws?distro=focal < 5.4.0-1018.18
pkg:deb/ubuntu/linux-image-5.4.0-1013-raspi?distro=focal < 5.4.0-1013.13
ID
USN-4411-1
Severity
low
URL
https://ubuntu.com/security/notices/USN-4411-1
Published
2020-07-06T19:29:23
(4 years ago)
Modified
2020-07-06T19:29:23
(4 years ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/linux-image-virtual?distro=focal ubuntu linux-image-virtual < 5.4.0.40.43 focal
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-20.04?distro=focal ubuntu linux-image-virtual-hwe-20.04 < 5.4.0.40.43 focal
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-18.04?distro=focal ubuntu linux-image-virtual-hwe-18.04 < 5.4.0.40.43 focal
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-18.04-edge?distro=focal ubuntu linux-image-virtual-hwe-18.04-edge < 5.4.0.40.43 focal
Affected pkg:deb/ubuntu/linux-image-raspi?distro=focal ubuntu linux-image-raspi < 5.4.0.1013.13 focal
Affected pkg:deb/ubuntu/linux-image-raspi2?distro=focal ubuntu linux-image-raspi2 < 5.4.0.1013.13 focal
Affected pkg:deb/ubuntu/linux-image-oracle?distro=focal ubuntu linux-image-oracle < 5.4.0.1019.17 focal
Affected pkg:deb/ubuntu/linux-image-oem?distro=focal ubuntu linux-image-oem < 5.4.0.40.43 focal
Affected pkg:deb/ubuntu/linux-image-oem-osp1?distro=focal ubuntu linux-image-oem-osp1 < 5.4.0.40.43 focal
Affected pkg:deb/ubuntu/linux-image-lowlatency?distro=focal ubuntu linux-image-lowlatency < 5.4.0.40.43 focal
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-20.04?distro=focal ubuntu linux-image-lowlatency-hwe-20.04 < 5.4.0.40.43 focal
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-18.04?distro=focal ubuntu linux-image-lowlatency-hwe-18.04 < 5.4.0.40.43 focal
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-18.04-edge?distro=focal ubuntu linux-image-lowlatency-hwe-18.04-edge < 5.4.0.40.43 focal
Affected pkg:deb/ubuntu/linux-image-kvm?distro=focal ubuntu linux-image-kvm < 5.4.0.1018.17 focal
Affected pkg:deb/ubuntu/linux-image-gke?distro=focal ubuntu linux-image-gke < 5.4.0.1019.17 focal
Affected pkg:deb/ubuntu/linux-image-generic?distro=focal ubuntu linux-image-generic < 5.4.0.40.43 focal
Affected pkg:deb/ubuntu/linux-image-generic-lpae?distro=focal ubuntu linux-image-generic-lpae < 5.4.0.40.43 focal
Affected pkg:deb/ubuntu/linux-image-generic-lpae-hwe-20.04?distro=focal ubuntu linux-image-generic-lpae-hwe-20.04 < 5.4.0.40.43 focal
Affected pkg:deb/ubuntu/linux-image-generic-lpae-hwe-18.04?distro=focal ubuntu linux-image-generic-lpae-hwe-18.04 < 5.4.0.40.43 focal
Affected pkg:deb/ubuntu/linux-image-generic-lpae-hwe-18.04-edge?distro=focal ubuntu linux-image-generic-lpae-hwe-18.04-edge < 5.4.0.40.43 focal
Affected pkg:deb/ubuntu/linux-image-generic-hwe-20.04?distro=focal ubuntu linux-image-generic-hwe-20.04 < 5.4.0.40.43 focal
Affected pkg:deb/ubuntu/linux-image-generic-hwe-18.04?distro=focal ubuntu linux-image-generic-hwe-18.04 < 5.4.0.40.43 focal
Affected pkg:deb/ubuntu/linux-image-generic-hwe-18.04-edge?distro=focal ubuntu linux-image-generic-hwe-18.04-edge < 5.4.0.40.43 focal
Affected pkg:deb/ubuntu/linux-image-gcp?distro=focal ubuntu linux-image-gcp < 5.4.0.1019.17 focal
Affected pkg:deb/ubuntu/linux-image-azure?distro=focal ubuntu linux-image-azure < 5.4.0.1020.19 focal
Affected pkg:deb/ubuntu/linux-image-aws?distro=focal ubuntu linux-image-aws < 5.4.0.1018.19 focal
Affected pkg:deb/ubuntu/linux-image-5.4.0-40-lowlatency?distro=focal ubuntu linux-image-5.4.0-40-lowlatency < 5.4.0-40.44 focal
Affected pkg:deb/ubuntu/linux-image-5.4.0-40-generic?distro=focal ubuntu linux-image-5.4.0-40-generic < 5.4.0-40.44 focal
Affected pkg:deb/ubuntu/linux-image-5.4.0-40-generic-lpae?distro=focal ubuntu linux-image-5.4.0-40-generic-lpae < 5.4.0-40.44 focal
Affected pkg:deb/ubuntu/linux-image-5.4.0-28-generic?distro=focal ubuntu linux-image-5.4.0-28-generic < 5.4.0-28.32 focal
Affected pkg:deb/ubuntu/linux-image-5.4.0-1020-azure?distro=focal ubuntu linux-image-5.4.0-1020-azure < 5.4.0-1020.20 focal
Affected pkg:deb/ubuntu/linux-image-5.4.0-1019-oracle?distro=focal ubuntu linux-image-5.4.0-1019-oracle < 5.4.0-1019.19 focal
Affected pkg:deb/ubuntu/linux-image-5.4.0-1019-gcp?distro=focal ubuntu linux-image-5.4.0-1019-gcp < 5.4.0-1019.19 focal
Affected pkg:deb/ubuntu/linux-image-5.4.0-1018-aws?distro=focal ubuntu linux-image-5.4.0-1018-aws < 5.4.0-1018.18 focal
Affected pkg:deb/ubuntu/linux-image-5.4.0-1013-raspi?distro=focal ubuntu linux-image-5.4.0-1013-raspi < 5.4.0-1013.13 focal
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...