[USN-5003-1] Linux kernel vulnerabilities

Severity High
Affected Packages 50
CVEs 3

Several security issues were fixed in the Linux kernel.

Norbert Slusarek discovered a race condition in the CAN BCM networking
protocol of the Linux kernel leading to multiple use-after-free
vulnerabilities. A local attacker could use this issue to execute arbitrary
code. (CVE-2021-3609)

It was discovered that the eBPF implementation in the Linux kernel did not
properly track bounds information for 32 bit registers when performing div
and mod operations. A local attacker could use this to possibly execute
arbitrary code. (CVE-2021-3600)

Or Cohen discovered that the SCTP implementation in the Linux kernel
contained a race condition in some situations, leading to a use-after-free
condition. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2021-23133)

Package Affected Version
pkg:deb/ubuntu/linux-image-virtual?distro=bionic < 4.15.0.147.134
pkg:deb/ubuntu/linux-image-virtual-hwe-16.04?distro=xenial < 4.15.0.147.143
pkg:deb/ubuntu/linux-image-virtual-hwe-16.04?distro=bionic < 4.15.0.147.134
pkg:deb/ubuntu/linux-image-virtual-hwe-16.04-edge?distro=xenial < 4.15.0.147.143
pkg:deb/ubuntu/linux-image-virtual-hwe-16.04-edge?distro=bionic < 4.15.0.147.134
pkg:deb/ubuntu/linux-image-snapdragon?distro=bionic < 4.15.0.1106.109
pkg:deb/ubuntu/linux-image-raspi2?distro=bionic < 4.15.0.1089.86
pkg:deb/ubuntu/linux-image-oracle?distro=xenial < 4.15.0.1075.63
pkg:deb/ubuntu/linux-image-oracle-lts-18.04?distro=bionic < 4.15.0.1075.85
pkg:deb/ubuntu/linux-image-oem?distro=xenial < 4.15.0.147.143
pkg:deb/ubuntu/linux-image-lowlatency?distro=bionic < 4.15.0.147.134
pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04?distro=xenial < 4.15.0.147.143
pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04?distro=bionic < 4.15.0.147.134
pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04-edge?distro=xenial < 4.15.0.147.143
pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04-edge?distro=bionic < 4.15.0.147.134
pkg:deb/ubuntu/linux-image-gke?distro=xenial < 4.15.0.1103.104
pkg:deb/ubuntu/linux-image-generic?distro=bionic < 4.15.0.147.134
pkg:deb/ubuntu/linux-image-generic-lpae?distro=bionic < 4.15.0.147.134
pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04?distro=bionic < 4.15.0.147.134
pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04-edge?distro=bionic < 4.15.0.147.134
pkg:deb/ubuntu/linux-image-generic-hwe-16.04?distro=xenial < 4.15.0.147.143
pkg:deb/ubuntu/linux-image-generic-hwe-16.04?distro=bionic < 4.15.0.147.134
pkg:deb/ubuntu/linux-image-generic-hwe-16.04-edge?distro=xenial < 4.15.0.147.143
pkg:deb/ubuntu/linux-image-generic-hwe-16.04-edge?distro=bionic < 4.15.0.147.134
pkg:deb/ubuntu/linux-image-gcp?distro=xenial < 4.15.0.1103.104
pkg:deb/ubuntu/linux-image-gcp-lts-18.04?distro=bionic < 4.15.0.1103.121
pkg:deb/ubuntu/linux-image-dell300x?distro=bionic < 4.15.0.1022.24
pkg:deb/ubuntu/linux-image-azure?distro=xenial < 4.15.0.1118.109
pkg:deb/ubuntu/linux-image-azure?distro=trusty < 4.15.0.1118.91
pkg:deb/ubuntu/linux-image-azure-lts-18.04?distro=bionic < 4.15.0.1118.91
pkg:deb/ubuntu/linux-image-azure-edge?distro=xenial < 4.15.0.1118.109
pkg:deb/ubuntu/linux-image-aws-lts-18.04?distro=bionic < 4.15.0.1106.109
pkg:deb/ubuntu/linux-image-aws-hwe?distro=xenial < 4.15.0.1106.97
pkg:deb/ubuntu/linux-image-4.15.0-147-lowlatency?distro=xenial < 4.15.0-147.151~16.04.1
pkg:deb/ubuntu/linux-image-4.15.0-147-lowlatency?distro=bionic < 4.15.0-147.151
pkg:deb/ubuntu/linux-image-4.15.0-147-generic?distro=xenial < 4.15.0-147.151~16.04.1
pkg:deb/ubuntu/linux-image-4.15.0-147-generic?distro=bionic < 4.15.0-147.151
pkg:deb/ubuntu/linux-image-4.15.0-147-generic-lpae?distro=bionic < 4.15.0-147.151
pkg:deb/ubuntu/linux-image-4.15.0-1118-azure?distro=xenial < 4.15.0-1118.131~16.04.1
pkg:deb/ubuntu/linux-image-4.15.0-1118-azure?distro=trusty < 4.15.0-1118.131~14.04.1
pkg:deb/ubuntu/linux-image-4.15.0-1118-azure?distro=bionic < 4.15.0-1118.131
pkg:deb/ubuntu/linux-image-4.15.0-1106-snapdragon?distro=bionic < 4.15.0-1106.115
pkg:deb/ubuntu/linux-image-4.15.0-1106-aws?distro=xenial < 4.15.0-1106.113~16.04.1
pkg:deb/ubuntu/linux-image-4.15.0-1106-aws?distro=bionic < 4.15.0-1106.113
pkg:deb/ubuntu/linux-image-4.15.0-1103-gcp?distro=xenial < 4.15.0-1103.116~16.04.1
pkg:deb/ubuntu/linux-image-4.15.0-1103-gcp?distro=bionic < 4.15.0-1103.116
pkg:deb/ubuntu/linux-image-4.15.0-1089-raspi2?distro=bionic < 4.15.0-1089.94
pkg:deb/ubuntu/linux-image-4.15.0-1075-oracle?distro=xenial < 4.15.0-1075.83~16.04.1
pkg:deb/ubuntu/linux-image-4.15.0-1075-oracle?distro=bionic < 4.15.0-1075.83
pkg:deb/ubuntu/linux-image-4.15.0-1022-dell300x?distro=bionic < 4.15.0-1022.26
ID
USN-5003-1
Severity
high
URL
https://ubuntu.com/security/notices/USN-5003-1
Published
2021-06-23T05:10:11
(3 years ago)
Modified
2021-06-23T05:10:11
(3 years ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/linux-image-virtual?distro=bionic ubuntu linux-image-virtual < 4.15.0.147.134 bionic
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-16.04?distro=xenial ubuntu linux-image-virtual-hwe-16.04 < 4.15.0.147.143 xenial
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-16.04?distro=bionic ubuntu linux-image-virtual-hwe-16.04 < 4.15.0.147.134 bionic
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-16.04-edge?distro=xenial ubuntu linux-image-virtual-hwe-16.04-edge < 4.15.0.147.143 xenial
Affected pkg:deb/ubuntu/linux-image-virtual-hwe-16.04-edge?distro=bionic ubuntu linux-image-virtual-hwe-16.04-edge < 4.15.0.147.134 bionic
Affected pkg:deb/ubuntu/linux-image-snapdragon?distro=bionic ubuntu linux-image-snapdragon < 4.15.0.1106.109 bionic
Affected pkg:deb/ubuntu/linux-image-raspi2?distro=bionic ubuntu linux-image-raspi2 < 4.15.0.1089.86 bionic
Affected pkg:deb/ubuntu/linux-image-oracle?distro=xenial ubuntu linux-image-oracle < 4.15.0.1075.63 xenial
Affected pkg:deb/ubuntu/linux-image-oracle-lts-18.04?distro=bionic ubuntu linux-image-oracle-lts-18.04 < 4.15.0.1075.85 bionic
Affected pkg:deb/ubuntu/linux-image-oem?distro=xenial ubuntu linux-image-oem < 4.15.0.147.143 xenial
Affected pkg:deb/ubuntu/linux-image-lowlatency?distro=bionic ubuntu linux-image-lowlatency < 4.15.0.147.134 bionic
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04?distro=xenial ubuntu linux-image-lowlatency-hwe-16.04 < 4.15.0.147.143 xenial
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04?distro=bionic ubuntu linux-image-lowlatency-hwe-16.04 < 4.15.0.147.134 bionic
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04-edge?distro=xenial ubuntu linux-image-lowlatency-hwe-16.04-edge < 4.15.0.147.143 xenial
Affected pkg:deb/ubuntu/linux-image-lowlatency-hwe-16.04-edge?distro=bionic ubuntu linux-image-lowlatency-hwe-16.04-edge < 4.15.0.147.134 bionic
Affected pkg:deb/ubuntu/linux-image-gke?distro=xenial ubuntu linux-image-gke < 4.15.0.1103.104 xenial
Affected pkg:deb/ubuntu/linux-image-generic?distro=bionic ubuntu linux-image-generic < 4.15.0.147.134 bionic
Affected pkg:deb/ubuntu/linux-image-generic-lpae?distro=bionic ubuntu linux-image-generic-lpae < 4.15.0.147.134 bionic
Affected pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04?distro=bionic ubuntu linux-image-generic-lpae-hwe-16.04 < 4.15.0.147.134 bionic
Affected pkg:deb/ubuntu/linux-image-generic-lpae-hwe-16.04-edge?distro=bionic ubuntu linux-image-generic-lpae-hwe-16.04-edge < 4.15.0.147.134 bionic
Affected pkg:deb/ubuntu/linux-image-generic-hwe-16.04?distro=xenial ubuntu linux-image-generic-hwe-16.04 < 4.15.0.147.143 xenial
Affected pkg:deb/ubuntu/linux-image-generic-hwe-16.04?distro=bionic ubuntu linux-image-generic-hwe-16.04 < 4.15.0.147.134 bionic
Affected pkg:deb/ubuntu/linux-image-generic-hwe-16.04-edge?distro=xenial ubuntu linux-image-generic-hwe-16.04-edge < 4.15.0.147.143 xenial
Affected pkg:deb/ubuntu/linux-image-generic-hwe-16.04-edge?distro=bionic ubuntu linux-image-generic-hwe-16.04-edge < 4.15.0.147.134 bionic
Affected pkg:deb/ubuntu/linux-image-gcp?distro=xenial ubuntu linux-image-gcp < 4.15.0.1103.104 xenial
Affected pkg:deb/ubuntu/linux-image-gcp-lts-18.04?distro=bionic ubuntu linux-image-gcp-lts-18.04 < 4.15.0.1103.121 bionic
Affected pkg:deb/ubuntu/linux-image-dell300x?distro=bionic ubuntu linux-image-dell300x < 4.15.0.1022.24 bionic
Affected pkg:deb/ubuntu/linux-image-azure?distro=xenial ubuntu linux-image-azure < 4.15.0.1118.109 xenial
Affected pkg:deb/ubuntu/linux-image-azure?distro=trusty ubuntu linux-image-azure < 4.15.0.1118.91 trusty
Affected pkg:deb/ubuntu/linux-image-azure-lts-18.04?distro=bionic ubuntu linux-image-azure-lts-18.04 < 4.15.0.1118.91 bionic
Affected pkg:deb/ubuntu/linux-image-azure-edge?distro=xenial ubuntu linux-image-azure-edge < 4.15.0.1118.109 xenial
Affected pkg:deb/ubuntu/linux-image-aws-lts-18.04?distro=bionic ubuntu linux-image-aws-lts-18.04 < 4.15.0.1106.109 bionic
Affected pkg:deb/ubuntu/linux-image-aws-hwe?distro=xenial ubuntu linux-image-aws-hwe < 4.15.0.1106.97 xenial
Affected pkg:deb/ubuntu/linux-image-4.15.0-147-lowlatency?distro=xenial ubuntu linux-image-4.15.0-147-lowlatency < 4.15.0-147.151~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-image-4.15.0-147-lowlatency?distro=bionic ubuntu linux-image-4.15.0-147-lowlatency < 4.15.0-147.151 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-147-generic?distro=xenial ubuntu linux-image-4.15.0-147-generic < 4.15.0-147.151~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-image-4.15.0-147-generic?distro=bionic ubuntu linux-image-4.15.0-147-generic < 4.15.0-147.151 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-147-generic-lpae?distro=bionic ubuntu linux-image-4.15.0-147-generic-lpae < 4.15.0-147.151 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1118-azure?distro=xenial ubuntu linux-image-4.15.0-1118-azure < 4.15.0-1118.131~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-image-4.15.0-1118-azure?distro=trusty ubuntu linux-image-4.15.0-1118-azure < 4.15.0-1118.131~14.04.1 trusty
Affected pkg:deb/ubuntu/linux-image-4.15.0-1118-azure?distro=bionic ubuntu linux-image-4.15.0-1118-azure < 4.15.0-1118.131 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1106-snapdragon?distro=bionic ubuntu linux-image-4.15.0-1106-snapdragon < 4.15.0-1106.115 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1106-aws?distro=xenial ubuntu linux-image-4.15.0-1106-aws < 4.15.0-1106.113~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-image-4.15.0-1106-aws?distro=bionic ubuntu linux-image-4.15.0-1106-aws < 4.15.0-1106.113 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1103-gcp?distro=xenial ubuntu linux-image-4.15.0-1103-gcp < 4.15.0-1103.116~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-image-4.15.0-1103-gcp?distro=bionic ubuntu linux-image-4.15.0-1103-gcp < 4.15.0-1103.116 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1089-raspi2?distro=bionic ubuntu linux-image-4.15.0-1089-raspi2 < 4.15.0-1089.94 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1075-oracle?distro=xenial ubuntu linux-image-4.15.0-1075-oracle < 4.15.0-1075.83~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-image-4.15.0-1075-oracle?distro=bionic ubuntu linux-image-4.15.0-1075-oracle < 4.15.0-1075.83 bionic
Affected pkg:deb/ubuntu/linux-image-4.15.0-1022-dell300x?distro=bionic ubuntu linux-image-4.15.0-1022-dell300x < 4.15.0-1022.26 bionic
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...