[USN-5794-1] Linux kernel (AWS) vulnerabilities

Severity High
Affected Packages 15
CVEs 4

Several security issues were fixed in the Linux kernel.

It was discovered that the NFSD implementation in the Linux kernel did not
properly handle some RPC messages, leading to a buffer overflow. A remote
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2022-43945)

Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation
in the Linux kernel contained multiple use-after-free vulnerabilities. A
physically proximate attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2022-42896)

It was discovered that the Xen netback driver in the Linux kernel did not
properly handle packets structured in certain ways. An attacker in a guest
VM could possibly use this to cause a denial of service (host NIC
availability). (CVE-2022-3643)

It was discovered that an integer overflow vulnerability existed in the
Bluetooth subsystem in the Linux kernel. A physically proximate attacker
could use this to cause a denial of service (system crash).
(CVE-2022-45934)

ID
USN-5794-1
Severity
high
Severity from
CVE-2022-42896
URL
https://ubuntu.com/security/notices/USN-5794-1
Published
2023-01-06T22:55:54
(20 months ago)
Modified
2023-01-06T22:55:54
(20 months ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/linux-tools-aws?distro=xenial ubuntu linux-tools-aws < 4.4.0.1153.157 xenial
Affected pkg:deb/ubuntu/linux-tools-4.4.0-1153-aws?distro=xenial ubuntu linux-tools-4.4.0-1153-aws < 4.4.0-1153.168 xenial
Affected pkg:deb/ubuntu/linux-modules-extra-aws?distro=xenial ubuntu linux-modules-extra-aws < 4.4.0.1153.157 xenial
Affected pkg:deb/ubuntu/linux-modules-extra-4.4.0-1153-aws?distro=xenial ubuntu linux-modules-extra-4.4.0-1153-aws < 4.4.0-1153.168 xenial
Affected pkg:deb/ubuntu/linux-modules-4.4.0-1153-aws?distro=xenial ubuntu linux-modules-4.4.0-1153-aws < 4.4.0-1153.168 xenial
Affected pkg:deb/ubuntu/linux-image-aws?distro=xenial ubuntu linux-image-aws < 4.4.0.1153.157 xenial
Affected pkg:deb/ubuntu/linux-image-4.4.0-1153-aws?distro=xenial ubuntu linux-image-4.4.0-1153-aws < 4.4.0-1153.168 xenial
Affected pkg:deb/ubuntu/linux-headers-aws?distro=xenial ubuntu linux-headers-aws < 4.4.0.1153.157 xenial
Affected pkg:deb/ubuntu/linux-headers-4.4.0-1153-aws?distro=xenial ubuntu linux-headers-4.4.0-1153-aws < 4.4.0-1153.168 xenial
Affected pkg:deb/ubuntu/linux-cloud-tools-4.4.0-1153-aws?distro=xenial ubuntu linux-cloud-tools-4.4.0-1153-aws < 4.4.0-1153.168 xenial
Affected pkg:deb/ubuntu/linux-buildinfo-4.4.0-1153-aws?distro=xenial ubuntu linux-buildinfo-4.4.0-1153-aws < 4.4.0-1153.168 xenial
Affected pkg:deb/ubuntu/linux-aws?distro=xenial ubuntu linux-aws < 4.4.0.1153.157 xenial
Affected pkg:deb/ubuntu/linux-aws-tools-4.4.0-1153?distro=xenial ubuntu linux-aws-tools-4.4.0-1153 < 4.4.0-1153.168 xenial
Affected pkg:deb/ubuntu/linux-aws-headers-4.4.0-1153?distro=xenial ubuntu linux-aws-headers-4.4.0-1153 < 4.4.0-1153.168 xenial
Affected pkg:deb/ubuntu/linux-aws-cloud-tools-4.4.0-1153?distro=xenial ubuntu linux-aws-cloud-tools-4.4.0-1153 < 4.4.0-1153.168 xenial
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...