[USN-4946-1] Linux kernel vulnerabilities

Severity Medium
Affected Packages 49
CVEs 9

Several security issues were fixed in the Linux kernel.

It was discovered that the DRM subsystem in the Linux kernel contained
double-free vulnerabilities. A privileged attacker could possibly use this
to cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2021-20292)

Olivier Benjamin, Norbert Manthey, Martin Mazein, and Jan H. Schönherr
discovered that the Xen paravirtualization backend in the Linux kernel did
not properly propagate errors to frontend drivers in some situations. An
attacker in a guest VM could possibly use this to cause a denial of service
(host domain crash). (CVE-2021-26930)

Jan Beulich discovered that multiple Xen backends in the Linux kernel did
not properly handle certain error conditions under paravirtualization. An
attacker in a guest VM could possibly use this to cause a denial of service
(host domain crash). (CVE-2021-26931)

Jan Beulich discovered that the Xen netback backend in the Linux kernel did
not properly handle certain error conditions under paravirtualization. An
attacker in a guest VM could possibly use this to cause a denial of service
(host domain crash). (CVE-2021-28038)

It was discovered that the Xen paravirtualization backend in the Linux
kernel did not properly deallocate memory in some situations. A local
attacker could use this to cause a denial of service (memory exhaustion).
(CVE-2021-28688)

It was discovered that the Freescale Gianfar Ethernet driver for the Linux
kernel did not properly handle receive queue overrun when jumbo frames were
enabled in some situations. An attacker could use this to cause a denial of
service (system crash). (CVE-2021-29264)

It was discovered that the USB/IP driver in the Linux kernel contained race
conditions during the update of local and shared status. An attacker could
use this to cause a denial of service (system crash). (CVE-2021-29265)

It was discovered that a race condition existed in the netfilter subsystem
of the Linux kernel when replacing tables. A local attacker could use this
to cause a denial of service (system crash). (CVE-2021-29650)

Arnd Bergmann discovered that the video4linux subsystem in the Linux kernel
did not properly deallocate memory in some situations. A local attacker
could use this to cause a denial of service (memory exhaustion).
(CVE-2021-30002)

Package Affected Version
pkg:deb/ubuntu/linux-image-virtual?distro=bionic < 4.15.0.143.130
pkg:deb/ubuntu/linux-image-virtual-hwe-16.04?distro=xenial < 4.15.0.143.139
pkg:deb/ubuntu/linux-image-virtual-hwe-16.04?distro=bionic < 4.15.0.143.130
pkg:deb/ubuntu/linux-image-virtual-hwe-16.04-edge?distro=xenial < 4.15.0.143.139
pkg:deb/ubuntu/linux-image-virtual-hwe-16.04-edge?distro=bionic < 4.15.0.143.130
pkg:deb/ubuntu/linux-image-snapdragon?distro=bionic < 4.15.0.1102.105
pkg:deb/ubuntu/linux-image-raspi2?distro=bionic < 4.15.0.1085.82
pkg:deb/ubuntu/linux-image-oracle?distro=xenial < 4.15.0.1071.59
pkg:deb/ubuntu/linux-image-oracle-lts-18.04?distro=bionic < 4.15.0.1071.81
pkg:deb/ubuntu/linux-image-oem?distro=xenial < 4.15.0.143.139
pkg:deb/ubuntu/linux-image-lowlatency?distro=bionic < 4.15.0.143.130
pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04?distro=xenial < 4.15.0.143.139
pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04?distro=bionic < 4.15.0.143.130
pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04-edge?distro=xenial < 4.15.0.143.139
pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04-edge?distro=bionic < 4.15.0.143.130
pkg:deb/ubuntu/linux-image-kvm?distro=bionic < 4.15.0.1091.87
pkg:deb/ubuntu/linux-image-gke?distro=xenial < 4.15.0.1099.100
pkg:deb/ubuntu/linux-image-generic?distro=bionic < 4.15.0.143.130
pkg:deb/ubuntu/linux-image-generic-lpae?distro=bionic < 4.15.0.143.130
pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04?distro=bionic < 4.15.0.143.130
pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04-edge?distro=bionic < 4.15.0.143.130
pkg:deb/ubuntu/linux-image-generic-hwe-16.04?distro=xenial < 4.15.0.143.139
pkg:deb/ubuntu/linux-image-generic-hwe-16.04?distro=bionic < 4.15.0.143.130
pkg:deb/ubuntu/linux-image-generic-hwe-16.04-edge?distro=xenial < 4.15.0.143.139
pkg:deb/ubuntu/linux-image-generic-hwe-16.04-edge?distro=bionic < 4.15.0.143.130
pkg:deb/ubuntu/linux-image-gcp?distro=xenial < 4.15.0.1099.100
pkg:deb/ubuntu/linux-image-gcp-lts-18.04?distro=bionic < 4.15.0.1099.117
pkg:deb/ubuntu/linux-image-dell300x?distro=bionic < 4.15.0.1018.20
pkg:deb/ubuntu/linux-image-azure?distro=trusty < 4.15.0.1114.87
pkg:deb/ubuntu/linux-image-azure-lts-18.04?distro=bionic < 4.15.0.1114.87
pkg:deb/ubuntu/linux-image-aws-lts-18.04?distro=bionic < 4.15.0.1102.105
pkg:deb/ubuntu/linux-image-aws-hwe?distro=xenial < 4.15.0.1102.93
pkg:deb/ubuntu/linux-image-4.15.0-143-lowlatency?distro=xenial < 4.15.0-143.147~16.04.3
pkg:deb/ubuntu/linux-image-4.15.0-143-lowlatency?distro=bionic < 4.15.0-143.147
pkg:deb/ubuntu/linux-image-4.15.0-143-generic?distro=xenial < 4.15.0-143.147~16.04.3
pkg:deb/ubuntu/linux-image-4.15.0-143-generic?distro=bionic < 4.15.0-143.147
pkg:deb/ubuntu/linux-image-4.15.0-143-generic-lpae?distro=bionic < 4.15.0-143.147
pkg:deb/ubuntu/linux-image-4.15.0-1114-azure?distro=trusty < 4.15.0-1114.127~14.04.1
pkg:deb/ubuntu/linux-image-4.15.0-1114-azure?distro=bionic < 4.15.0-1114.127
pkg:deb/ubuntu/linux-image-4.15.0-1102-snapdragon?distro=bionic < 4.15.0-1102.111
pkg:deb/ubuntu/linux-image-4.15.0-1102-aws?distro=xenial < 4.15.0-1102.109~16.04.1
pkg:deb/ubuntu/linux-image-4.15.0-1102-aws?distro=bionic < 4.15.0-1102.109
pkg:deb/ubuntu/linux-image-4.15.0-1099-gcp?distro=xenial < 4.15.0-1099.112~16.04.1
pkg:deb/ubuntu/linux-image-4.15.0-1099-gcp?distro=bionic < 4.15.0-1099.112
pkg:deb/ubuntu/linux-image-4.15.0-1091-kvm?distro=bionic < 4.15.0-1091.93
pkg:deb/ubuntu/linux-image-4.15.0-1085-raspi2?distro=bionic < 4.15.0-1085.90
pkg:deb/ubuntu/linux-image-4.15.0-1071-oracle?distro=xenial < 4.15.0-1071.79~16.04.1
pkg:deb/ubuntu/linux-image-4.15.0-1071-oracle?distro=bionic < 4.15.0-1071.79
pkg:deb/ubuntu/linux-image-4.15.0-1018-dell300x?distro=bionic < 4.15.0-1018.22
ID
USN-4946-1
Severity
medium
URL
https://ubuntu.com/security/notices/USN-4946-1
Published
2021-05-11T21:53:16
(3 years ago)
Modified
2021-05-11T21:53:16
(3 years ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/linux-image-virtual?distro=bionic ubuntu linux-image-virtual < 4.15.0.143.130 bionic
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-16.04?distro=xenial ubuntu linux-image-virtual-hwe-16.04 < 4.15.0.143.139 xenial
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-16.04?distro=bionic ubuntu linux-image-virtual-hwe-16.04 < 4.15.0.143.130 bionic
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-16.04-edge?distro=xenial ubuntu linux-image-virtual-hwe-16.04-edge < 4.15.0.143.139 xenial
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-16.04-edge?distro=bionic ubuntu linux-image-virtual-hwe-16.04-edge < 4.15.0.143.130 bionic
Affected pkg:deb/ubuntu/linux-image-snapdragon?distro=bionic ubuntu linux-image-snapdragon < 4.15.0.1102.105 bionic
Affected pkg:deb/ubuntu/linux-image-raspi2?distro=bionic ubuntu linux-image-raspi2 < 4.15.0.1085.82 bionic
Affected pkg:deb/ubuntu/linux-image-oracle?distro=xenial ubuntu linux-image-oracle < 4.15.0.1071.59 xenial
Affected pkg:deb/ubuntu/linux-image-oracle-lts-18.04?distro=bionic ubuntu linux-image-oracle-lts-18.04 < 4.15.0.1071.81 bionic
Affected pkg:deb/ubuntu/linux-image-oem?distro=xenial ubuntu linux-image-oem < 4.15.0.143.139 xenial
Affected pkg:deb/ubuntu/linux-image-lowlatency?distro=bionic ubuntu linux-image-lowlatency < 4.15.0.143.130 bionic
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04?distro=xenial ubuntu linux-image-lowlatency-hwe-16.04 < 4.15.0.143.139 xenial
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04?distro=bionic ubuntu linux-image-lowlatency-hwe-16.04 < 4.15.0.143.130 bionic
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04-edge?distro=xenial ubuntu linux-image-lowlatency-hwe-16.04-edge < 4.15.0.143.139 xenial
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04-edge?distro=bionic ubuntu linux-image-lowlatency-hwe-16.04-edge < 4.15.0.143.130 bionic
Affected pkg:deb/ubuntu/linux-image-kvm?distro=bionic ubuntu linux-image-kvm < 4.15.0.1091.87 bionic
Affected pkg:deb/ubuntu/linux-image-gke?distro=xenial ubuntu linux-image-gke < 4.15.0.1099.100 xenial
Affected pkg:deb/ubuntu/linux-image-generic?distro=bionic ubuntu linux-image-generic < 4.15.0.143.130 bionic
Affected pkg:deb/ubuntu/linux-image-generic-lpae?distro=bionic ubuntu linux-image-generic-lpae < 4.15.0.143.130 bionic
Affected pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04?distro=bionic ubuntu linux-image-generic-lpae-hwe-16.04 < 4.15.0.143.130 bionic
Affected pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04-edge?distro=bionic ubuntu linux-image-generic-lpae-hwe-16.04-edge < 4.15.0.143.130 bionic
Affected pkg:deb/ubuntu/linux-image-generic-hwe-16.04?distro=xenial ubuntu linux-image-generic-hwe-16.04 < 4.15.0.143.139 xenial
Affected pkg:deb/ubuntu/linux-image-generic-hwe-16.04?distro=bionic ubuntu linux-image-generic-hwe-16.04 < 4.15.0.143.130 bionic
Affected pkg:deb/ubuntu/linux-image-generic-hwe-16.04-edge?distro=xenial ubuntu linux-image-generic-hwe-16.04-edge < 4.15.0.143.139 xenial
Affected pkg:deb/ubuntu/linux-image-generic-hwe-16.04-edge?distro=bionic ubuntu linux-image-generic-hwe-16.04-edge < 4.15.0.143.130 bionic
Affected pkg:deb/ubuntu/linux-image-gcp?distro=xenial ubuntu linux-image-gcp < 4.15.0.1099.100 xenial
Affected pkg:deb/ubuntu/linux-image-gcp-lts-18.04?distro=bionic ubuntu linux-image-gcp-lts-18.04 < 4.15.0.1099.117 bionic
Affected pkg:deb/ubuntu/linux-image-dell300x?distro=bionic ubuntu linux-image-dell300x < 4.15.0.1018.20 bionic
Affected pkg:deb/ubuntu/linux-image-azure?distro=trusty ubuntu linux-image-azure < 4.15.0.1114.87 trusty
Affected pkg:deb/ubuntu/linux-image-azure-lts-18.04?distro=bionic ubuntu linux-image-azure-lts-18.04 < 4.15.0.1114.87 bionic
Affected pkg:deb/ubuntu/linux-image-aws-lts-18.04?distro=bionic ubuntu linux-image-aws-lts-18.04 < 4.15.0.1102.105 bionic
Affected pkg:deb/ubuntu/linux-image-aws-hwe?distro=xenial ubuntu linux-image-aws-hwe < 4.15.0.1102.93 xenial
Affected pkg:deb/ubuntu/linux-image-4.15.0-143-lowlatency?distro=xenial ubuntu linux-image-4.15.0-143-lowlatency < 4.15.0-143.147~16.04.3 xenial
Affected pkg:deb/ubuntu/linux-image-4.15.0-143-lowlatency?distro=bionic ubuntu linux-image-4.15.0-143-lowlatency < 4.15.0-143.147 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-143-generic?distro=xenial ubuntu linux-image-4.15.0-143-generic < 4.15.0-143.147~16.04.3 xenial
Affected pkg:deb/ubuntu/linux-image-4.15.0-143-generic?distro=bionic ubuntu linux-image-4.15.0-143-generic < 4.15.0-143.147 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-143-generic-lpae?distro=bionic ubuntu linux-image-4.15.0-143-generic-lpae < 4.15.0-143.147 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1114-azure?distro=trusty ubuntu linux-image-4.15.0-1114-azure < 4.15.0-1114.127~14.04.1 trusty
Affected pkg:deb/ubuntu/linux-image-4.15.0-1114-azure?distro=bionic ubuntu linux-image-4.15.0-1114-azure < 4.15.0-1114.127 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1102-snapdragon?distro=bionic ubuntu linux-image-4.15.0-1102-snapdragon < 4.15.0-1102.111 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1102-aws?distro=xenial ubuntu linux-image-4.15.0-1102-aws < 4.15.0-1102.109~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-image-4.15.0-1102-aws?distro=bionic ubuntu linux-image-4.15.0-1102-aws < 4.15.0-1102.109 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1099-gcp?distro=xenial ubuntu linux-image-4.15.0-1099-gcp < 4.15.0-1099.112~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-image-4.15.0-1099-gcp?distro=bionic ubuntu linux-image-4.15.0-1099-gcp < 4.15.0-1099.112 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1091-kvm?distro=bionic ubuntu linux-image-4.15.0-1091-kvm < 4.15.0-1091.93 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1085-raspi2?distro=bionic ubuntu linux-image-4.15.0-1085-raspi2 < 4.15.0-1085.90 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1071-oracle?distro=xenial ubuntu linux-image-4.15.0-1071-oracle < 4.15.0-1071.79~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-image-4.15.0-1071-oracle?distro=bionic ubuntu linux-image-4.15.0-1071-oracle < 4.15.0-1071.79 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1018-dell300x?distro=bionic ubuntu linux-image-4.15.0-1018-dell300x < 4.15.0-1018.22 bionic
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...