[USN-5831-1] Linux kernel (Azure CVM) vulnerabilities

Severity High
Affected Packages 14
CVEs 4

Several security issues were fixed in the Linux kernel.

Kyle Zeng discovered that the sysctl implementation in the Linux kernel
contained a stack-based buffer overflow. A local attacker could use this to
cause a denial of service (system crash) or execute arbitrary code.
(CVE-2022-4378)

Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation
in the Linux kernel contained multiple use-after-free vulnerabilities. A
physically proximate attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2022-42896)

It was discovered that the Xen netback driver in the Linux kernel did not
properly handle packets structured in certain ways. An attacker in a guest
VM could possibly use this to cause a denial of service (host NIC
availability). (CVE-2022-3643)

It was discovered that an integer overflow vulnerability existed in the
Bluetooth subsystem in the Linux kernel. A physically proximate attacker
could use this to cause a denial of service (system crash).
(CVE-2022-45934)

ID
USN-5831-1
Severity
high
Severity from
CVE-2022-42896
URL
https://ubuntu.com/security/notices/USN-5831-1
Published
2023-01-27T19:01:20
(19 months ago)
Modified
2023-01-27T19:01:20
(19 months ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/linux-tools-azure-fde?distro=jammy ubuntu linux-tools-azure-fde < 5.15.0.1031.38.8 jammy
Affected pkg:deb/ubuntu/linux-tools-azure-fde-edge?distro=jammy ubuntu linux-tools-azure-fde-edge < 5.15.0.1031.38.8 jammy
Affected pkg:deb/ubuntu/linux-modules-extra-azure-fde?distro=jammy ubuntu linux-modules-extra-azure-fde < 5.15.0.1031.38.8 jammy
Affected pkg:deb/ubuntu/linux-modules-extra-azure-fde-edge?distro=jammy ubuntu linux-modules-extra-azure-fde-edge < 5.15.0.1031.38.8 jammy
Affected pkg:deb/ubuntu/linux-image-unsigned-5.15.0-1031-azure-fde?distro=jammy ubuntu linux-image-unsigned-5.15.0-1031-azure-fde < 5.15.0-1031.38.1 jammy
Affected pkg:deb/ubuntu/linux-image-azure-fde?distro=jammy ubuntu linux-image-azure-fde < 5.15.0.1031.38.8 jammy
Affected pkg:deb/ubuntu/linux-image-azure-fde-edge?distro=jammy ubuntu linux-image-azure-fde-edge < 5.15.0.1031.38.8 jammy
Affected pkg:deb/ubuntu/linux-image-5.15.0-1031-azure-fde?distro=jammy ubuntu linux-image-5.15.0-1031-azure-fde < 5.15.0-1031.38.1 jammy
Affected pkg:deb/ubuntu/linux-headers-azure-fde?distro=jammy ubuntu linux-headers-azure-fde < 5.15.0.1031.38.8 jammy
Affected pkg:deb/ubuntu/linux-headers-azure-fde-edge?distro=jammy ubuntu linux-headers-azure-fde-edge < 5.15.0.1031.38.8 jammy
Affected pkg:deb/ubuntu/linux-cloud-tools-azure-fde?distro=jammy ubuntu linux-cloud-tools-azure-fde < 5.15.0.1031.38.8 jammy
Affected pkg:deb/ubuntu/linux-cloud-tools-azure-fde-edge?distro=jammy ubuntu linux-cloud-tools-azure-fde-edge < 5.15.0.1031.38.8 jammy
Affected pkg:deb/ubuntu/linux-azure-fde?distro=jammy ubuntu linux-azure-fde < 5.15.0.1031.38.8 jammy
Affected pkg:deb/ubuntu/linux-azure-fde-edge?distro=jammy ubuntu linux-azure-fde-edge < 5.15.0.1031.38.8 jammy
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...