[USN-4678-1] Linux kernel vulnerabilities

Severity Medium
Affected Packages 46
CVEs 2

Several security issues were fixed in the Linux kernel.

It was discovered that the AMD Running Average Power Limit (RAPL) driver in
the Linux kernel did not properly restrict access to power data. A local
attacker could possibly use this to expose sensitive information.
(CVE-2020-12912)

Jann Horn discovered that the io_uring subsystem in the Linux kernel did
not properly perform reference counting in some situations. A local
attacker could use this to expose sensitive information or possibly
escalate privileges. (CVE-2020-29534)

Package Affected Version
pkg:deb/ubuntu/linux-image-virtual?distro=groovy < 5.8.0.34.39
pkg:deb/ubuntu/linux-image-virtual-hwe-20.04?distro=groovy < 5.8.0.34.39
pkg:deb/ubuntu/linux-image-virtual-hwe-20.04?distro=focal < 5.8.0.34.37~20.04.20
pkg:deb/ubuntu/linux-image-virtual-hwe-20.04-edge?distro=groovy < 5.8.0.34.39
pkg:deb/ubuntu/linux-image-virtual-hwe-20.04-edge?distro=focal < 5.8.0.34.37~20.04.20
pkg:deb/ubuntu/linux-image-raspi?distro=groovy < 5.8.0.1011.14
pkg:deb/ubuntu/linux-image-raspi-nolpae?distro=groovy < 5.8.0.1011.14
pkg:deb/ubuntu/linux-image-oracle?distro=groovy < 5.8.0.1014.14
pkg:deb/ubuntu/linux-image-oem-20.04?distro=groovy < 5.8.0.34.39
pkg:deb/ubuntu/linux-image-lowlatency?distro=groovy < 5.8.0.34.39
pkg:deb/ubuntu/linux-image-lowlatency-hwe-20.04?distro=groovy < 5.8.0.34.39
pkg:deb/ubuntu/linux-image-lowlatency-hwe-20.04?distro=focal < 5.8.0.34.37~20.04.20
pkg:deb/ubuntu/linux-image-lowlatency-hwe-20.04-edge?distro=groovy < 5.8.0.34.39
pkg:deb/ubuntu/linux-image-lowlatency-hwe-20.04-edge?distro=focal < 5.8.0.34.37~20.04.20
pkg:deb/ubuntu/linux-image-kvm?distro=groovy < 5.8.0.1014.16
pkg:deb/ubuntu/linux-image-gke?distro=groovy < 5.8.0.1015.15
pkg:deb/ubuntu/linux-image-generic?distro=groovy < 5.8.0.34.39
pkg:deb/ubuntu/linux-image-generic-lpae?distro=groovy < 5.8.0.34.39
pkg:deb/ubuntu/linux-image-generic-lpae-hwe-20.04?distro=groovy < 5.8.0.34.39
pkg:deb/ubuntu/linux-image-generic-lpae-hwe-20.04?distro=focal < 5.8.0.34.37~20.04.20
pkg:deb/ubuntu/linux-image-generic-lpae-hwe-20.04-edge?distro=groovy < 5.8.0.34.39
pkg:deb/ubuntu/linux-image-generic-lpae-hwe-20.04-edge?distro=focal < 5.8.0.34.37~20.04.20
pkg:deb/ubuntu/linux-image-generic-hwe-20.04?distro=groovy < 5.8.0.34.39
pkg:deb/ubuntu/linux-image-generic-hwe-20.04?distro=focal < 5.8.0.34.37~20.04.20
pkg:deb/ubuntu/linux-image-generic-hwe-20.04-edge?distro=groovy < 5.8.0.34.39
pkg:deb/ubuntu/linux-image-generic-hwe-20.04-edge?distro=focal < 5.8.0.34.37~20.04.20
pkg:deb/ubuntu/linux-image-generic-64k?distro=groovy < 5.8.0.34.39
pkg:deb/ubuntu/linux-image-generic-64k-hwe-20.04?distro=groovy < 5.8.0.34.39
pkg:deb/ubuntu/linux-image-generic-64k-hwe-20.04-edge?distro=groovy < 5.8.0.34.39
pkg:deb/ubuntu/linux-image-gcp?distro=groovy < 5.8.0.1015.15
pkg:deb/ubuntu/linux-image-azure?distro=groovy < 5.8.0.1016.16
pkg:deb/ubuntu/linux-image-aws?distro=groovy < 5.8.0.1017.19
pkg:deb/ubuntu/linux-image-5.8.0-34-lowlatency?distro=groovy < 5.8.0-34.37
pkg:deb/ubuntu/linux-image-5.8.0-34-lowlatency?distro=focal < 5.8.0-34.37~20.04.2
pkg:deb/ubuntu/linux-image-5.8.0-34-generic?distro=groovy < 5.8.0-34.37
pkg:deb/ubuntu/linux-image-5.8.0-34-generic?distro=focal < 5.8.0-34.37~20.04.2
pkg:deb/ubuntu/linux-image-5.8.0-34-generic-lpae?distro=groovy < 5.8.0-34.37
pkg:deb/ubuntu/linux-image-5.8.0-34-generic-lpae?distro=focal < 5.8.0-34.37~20.04.2
pkg:deb/ubuntu/linux-image-5.8.0-34-generic-64k?distro=groovy < 5.8.0-34.37
pkg:deb/ubuntu/linux-image-5.8.0-1017-aws?distro=groovy < 5.8.0-1017.18
pkg:deb/ubuntu/linux-image-5.8.0-1016-azure?distro=groovy < 5.8.0-1016.17
pkg:deb/ubuntu/linux-image-5.8.0-1015-gcp?distro=groovy < 5.8.0-1015.15
pkg:deb/ubuntu/linux-image-5.8.0-1014-oracle?distro=groovy < 5.8.0-1014.14
pkg:deb/ubuntu/linux-image-5.8.0-1014-kvm?distro=groovy < 5.8.0-1014.15
pkg:deb/ubuntu/linux-image-5.8.0-1011-raspi?distro=groovy < 5.8.0-1011.14
pkg:deb/ubuntu/linux-image-5.8.0-1011-raspi-nolpae?distro=groovy < 5.8.0-1011.14
ID
USN-4678-1
Severity
medium
URL
https://ubuntu.com/security/notices/USN-4678-1
Published
2021-01-06T22:27:04
(3 years ago)
Modified
2021-01-06T22:27:04
(3 years ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/linux-image-virtual?distro=groovy ubuntu linux-image-virtual < 5.8.0.34.39 groovy
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-20.04?distro=groovy ubuntu linux-image-virtual-hwe-20.04 < 5.8.0.34.39 groovy
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-20.04?distro=focal ubuntu linux-image-virtual-hwe-20.04 < 5.8.0.34.37~20.04.20 focal
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-20.04-edge?distro=groovy ubuntu linux-image-virtual-hwe-20.04-edge < 5.8.0.34.39 groovy
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-20.04-edge?distro=focal ubuntu linux-image-virtual-hwe-20.04-edge < 5.8.0.34.37~20.04.20 focal
Affected pkg:deb/ubuntu/linux-image-raspi?distro=groovy ubuntu linux-image-raspi < 5.8.0.1011.14 groovy
Affected pkg:deb/ubuntu/linux-image-raspi-nolpae?distro=groovy ubuntu linux-image-raspi-nolpae < 5.8.0.1011.14 groovy
Affected pkg:deb/ubuntu/linux-image-oracle?distro=groovy ubuntu linux-image-oracle < 5.8.0.1014.14 groovy
Affected pkg:deb/ubuntu/linux-image-oem-20.04?distro=groovy ubuntu linux-image-oem-20.04 < 5.8.0.34.39 groovy
Affected pkg:deb/ubuntu/linux-image-lowlatency?distro=groovy ubuntu linux-image-lowlatency < 5.8.0.34.39 groovy
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-20.04?distro=groovy ubuntu linux-image-lowlatency-hwe-20.04 < 5.8.0.34.39 groovy
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-20.04?distro=focal ubuntu linux-image-lowlatency-hwe-20.04 < 5.8.0.34.37~20.04.20 focal
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-20.04-edge?distro=groovy ubuntu linux-image-lowlatency-hwe-20.04-edge < 5.8.0.34.39 groovy
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-20.04-edge?distro=focal ubuntu linux-image-lowlatency-hwe-20.04-edge < 5.8.0.34.37~20.04.20 focal
Affected pkg:deb/ubuntu/linux-image-kvm?distro=groovy ubuntu linux-image-kvm < 5.8.0.1014.16 groovy
Affected pkg:deb/ubuntu/linux-image-gke?distro=groovy ubuntu linux-image-gke < 5.8.0.1015.15 groovy
Affected pkg:deb/ubuntu/linux-image-generic?distro=groovy ubuntu linux-image-generic < 5.8.0.34.39 groovy
Affected pkg:deb/ubuntu/linux-image-generic-lpae?distro=groovy ubuntu linux-image-generic-lpae < 5.8.0.34.39 groovy
Affected pkg:deb/ubuntu/linux-image-generic-lpae-hwe-20.04?distro=groovy ubuntu linux-image-generic-lpae-hwe-20.04 < 5.8.0.34.39 groovy
Affected pkg:deb/ubuntu/linux-image-generic-lpae-hwe-20.04?distro=focal ubuntu linux-image-generic-lpae-hwe-20.04 < 5.8.0.34.37~20.04.20 focal
Affected pkg:deb/ubuntu/linux-image-generic-lpae-hwe-20.04-edge?distro=groovy ubuntu linux-image-generic-lpae-hwe-20.04-edge < 5.8.0.34.39 groovy
Affected pkg:deb/ubuntu/linux-image-generic-lpae-hwe-20.04-edge?distro=focal ubuntu linux-image-generic-lpae-hwe-20.04-edge < 5.8.0.34.37~20.04.20 focal
Affected pkg:deb/ubuntu/linux-image-generic-hwe-20.04?distro=groovy ubuntu linux-image-generic-hwe-20.04 < 5.8.0.34.39 groovy
Affected pkg:deb/ubuntu/linux-image-generic-hwe-20.04?distro=focal ubuntu linux-image-generic-hwe-20.04 < 5.8.0.34.37~20.04.20 focal
Affected pkg:deb/ubuntu/linux-image-generic-hwe-20.04-edge?distro=groovy ubuntu linux-image-generic-hwe-20.04-edge < 5.8.0.34.39 groovy
Affected pkg:deb/ubuntu/linux-image-generic-hwe-20.04-edge?distro=focal ubuntu linux-image-generic-hwe-20.04-edge < 5.8.0.34.37~20.04.20 focal
Affected pkg:deb/ubuntu/linux-image-generic-64k?distro=groovy ubuntu linux-image-generic-64k < 5.8.0.34.39 groovy
Affected pkg:deb/ubuntu/linux-image-generic-64k-hwe-20.04?distro=groovy ubuntu linux-image-generic-64k-hwe-20.04 < 5.8.0.34.39 groovy
Affected pkg:deb/ubuntu/linux-image-generic-64k-hwe-20.04-edge?distro=groovy ubuntu linux-image-generic-64k-hwe-20.04-edge < 5.8.0.34.39 groovy
Affected pkg:deb/ubuntu/linux-image-gcp?distro=groovy ubuntu linux-image-gcp < 5.8.0.1015.15 groovy
Affected pkg:deb/ubuntu/linux-image-azure?distro=groovy ubuntu linux-image-azure < 5.8.0.1016.16 groovy
Affected pkg:deb/ubuntu/linux-image-aws?distro=groovy ubuntu linux-image-aws < 5.8.0.1017.19 groovy
Affected pkg:deb/ubuntu/linux-image-5.8.0-34-lowlatency?distro=groovy ubuntu linux-image-5.8.0-34-lowlatency < 5.8.0-34.37 groovy
Affected pkg:deb/ubuntu/linux-image-5.8.0-34-lowlatency?distro=focal ubuntu linux-image-5.8.0-34-lowlatency < 5.8.0-34.37~20.04.2 focal
Affected pkg:deb/ubuntu/linux-image-5.8.0-34-generic?distro=groovy ubuntu linux-image-5.8.0-34-generic < 5.8.0-34.37 groovy
Affected pkg:deb/ubuntu/linux-image-5.8.0-34-generic?distro=focal ubuntu linux-image-5.8.0-34-generic < 5.8.0-34.37~20.04.2 focal
Affected pkg:deb/ubuntu/linux-image-5.8.0-34-generic-lpae?distro=groovy ubuntu linux-image-5.8.0-34-generic-lpae < 5.8.0-34.37 groovy
Affected pkg:deb/ubuntu/linux-image-5.8.0-34-generic-lpae?distro=focal ubuntu linux-image-5.8.0-34-generic-lpae < 5.8.0-34.37~20.04.2 focal
Affected pkg:deb/ubuntu/linux-image-5.8.0-34-generic-64k?distro=groovy ubuntu linux-image-5.8.0-34-generic-64k < 5.8.0-34.37 groovy
Affected pkg:deb/ubuntu/linux-image-5.8.0-1017-aws?distro=groovy ubuntu linux-image-5.8.0-1017-aws < 5.8.0-1017.18 groovy
Affected pkg:deb/ubuntu/linux-image-5.8.0-1016-azure?distro=groovy ubuntu linux-image-5.8.0-1016-azure < 5.8.0-1016.17 groovy
Affected pkg:deb/ubuntu/linux-image-5.8.0-1015-gcp?distro=groovy ubuntu linux-image-5.8.0-1015-gcp < 5.8.0-1015.15 groovy
Affected pkg:deb/ubuntu/linux-image-5.8.0-1014-oracle?distro=groovy ubuntu linux-image-5.8.0-1014-oracle < 5.8.0-1014.14 groovy
Affected pkg:deb/ubuntu/linux-image-5.8.0-1014-kvm?distro=groovy ubuntu linux-image-5.8.0-1014-kvm < 5.8.0-1014.15 groovy
Affected pkg:deb/ubuntu/linux-image-5.8.0-1011-raspi?distro=groovy ubuntu linux-image-5.8.0-1011-raspi < 5.8.0-1011.14 groovy
Affected pkg:deb/ubuntu/linux-image-5.8.0-1011-raspi-nolpae?distro=groovy ubuntu linux-image-5.8.0-1011-raspi-nolpae < 5.8.0-1011.14 groovy
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...