[USN-5863-1] Linux kernel (Azure) vulnerabilities

Severity High
Affected Packages 27
CVEs 4

Several security issues were fixed in the Linux kernel.

It was discovered that the NFSD implementation in the Linux kernel did not
properly handle some RPC messages, leading to a buffer overflow. A remote
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2022-43945)

Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation
in the Linux kernel contained multiple use-after-free vulnerabilities. A
physically proximate attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2022-42896)

It was discovered that the Xen netback driver in the Linux kernel did not
properly handle packets structured in certain ways. An attacker in a guest
VM could possibly use this to cause a denial of service (host NIC
availability). (CVE-2022-3643)

It was discovered that an integer overflow vulnerability existed in the
Bluetooth subsystem in the Linux kernel. A physically proximate attacker
could use this to cause a denial of service (system crash).
(CVE-2022-45934)

Package Affected Version
pkg:deb/ubuntu/linux-tools-azure?distro=xenial < 4.15.0.1159.144
pkg:deb/ubuntu/linux-tools-azure-edge?distro=xenial < 4.15.0.1159.144
pkg:deb/ubuntu/linux-tools-4.15.0-1159-azure?distro=xenial < 4.15.0-1159.174~16.04.1
pkg:deb/ubuntu/linux-signed-image-azure?distro=xenial < 4.15.0.1159.144
pkg:deb/ubuntu/linux-signed-image-azure-edge?distro=xenial < 4.15.0.1159.144
pkg:deb/ubuntu/linux-signed-azure?distro=xenial < 4.15.0.1159.144
pkg:deb/ubuntu/linux-signed-azure-edge?distro=xenial < 4.15.0.1159.144
pkg:deb/ubuntu/linux-modules-extra-azure?distro=xenial < 4.15.0.1159.144
pkg:deb/ubuntu/linux-modules-extra-azure-edge?distro=xenial < 4.15.0.1159.144
pkg:deb/ubuntu/linux-modules-extra-4.15.0-1159-azure?distro=xenial < 4.15.0-1159.174~16.04.1
pkg:deb/ubuntu/linux-modules-4.15.0-1159-azure?distro=xenial < 4.15.0-1159.174~16.04.1
pkg:deb/ubuntu/linux-image-unsigned-4.15.0-1159-azure?distro=xenial < 4.15.0-1159.174~16.04.1
pkg:deb/ubuntu/linux-image-azure?distro=xenial < 4.15.0.1159.144
pkg:deb/ubuntu/linux-image-azure-edge?distro=xenial < 4.15.0.1159.144
pkg:deb/ubuntu/linux-image-4.15.0-1159-azure?distro=xenial < 4.15.0-1159.174~16.04.1
pkg:deb/ubuntu/linux-headers-azure?distro=xenial < 4.15.0.1159.144
pkg:deb/ubuntu/linux-headers-azure-edge?distro=xenial < 4.15.0.1159.144
pkg:deb/ubuntu/linux-headers-4.15.0-1159-azure?distro=xenial < 4.15.0-1159.174~16.04.1
pkg:deb/ubuntu/linux-cloud-tools-azure?distro=xenial < 4.15.0.1159.144
pkg:deb/ubuntu/linux-cloud-tools-azure-edge?distro=xenial < 4.15.0.1159.144
pkg:deb/ubuntu/linux-cloud-tools-4.15.0-1159-azure?distro=xenial < 4.15.0-1159.174~16.04.1
pkg:deb/ubuntu/linux-buildinfo-4.15.0-1159-azure?distro=xenial < 4.15.0-1159.174~16.04.1
pkg:deb/ubuntu/linux-azure?distro=xenial < 4.15.0.1159.144
pkg:deb/ubuntu/linux-azure-tools-4.15.0-1159?distro=xenial < 4.15.0-1159.174~16.04.1
pkg:deb/ubuntu/linux-azure-headers-4.15.0-1159?distro=xenial < 4.15.0-1159.174~16.04.1
pkg:deb/ubuntu/linux-azure-edge?distro=xenial < 4.15.0.1159.144
pkg:deb/ubuntu/linux-azure-cloud-tools-4.15.0-1159?distro=xenial < 4.15.0-1159.174~16.04.1
ID
USN-5863-1
Severity
high
Severity from
CVE-2022-42896
URL
https://ubuntu.com/security/notices/USN-5863-1
Published
2023-02-09T23:17:58
(19 months ago)
Modified
2023-02-09T23:17:58
(19 months ago)
Other Advisories
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:deb/ubuntu/linux-tools-azure?distro=xenial ubuntu linux-tools-azure < 4.15.0.1159.144 xenial
Affected pkg:deb/ubuntu/linux-tools-azure-edge?distro=xenial ubuntu linux-tools-azure-edge < 4.15.0.1159.144 xenial
Affected pkg:deb/ubuntu/linux-tools-4.15.0-1159-azure?distro=xenial ubuntu linux-tools-4.15.0-1159-azure < 4.15.0-1159.174~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-signed-image-azure?distro=xenial ubuntu linux-signed-image-azure < 4.15.0.1159.144 xenial
Affected pkg:deb/ubuntu/linux-signed-image-azure-edge?distro=xenial ubuntu linux-signed-image-azure-edge < 4.15.0.1159.144 xenial
Affected pkg:deb/ubuntu/linux-signed-azure?distro=xenial ubuntu linux-signed-azure < 4.15.0.1159.144 xenial
Affected pkg:deb/ubuntu/linux-signed-azure-edge?distro=xenial ubuntu linux-signed-azure-edge < 4.15.0.1159.144 xenial
Affected pkg:deb/ubuntu/linux-modules-extra-azure?distro=xenial ubuntu linux-modules-extra-azure < 4.15.0.1159.144 xenial
Affected pkg:deb/ubuntu/linux-modules-extra-azure-edge?distro=xenial ubuntu linux-modules-extra-azure-edge < 4.15.0.1159.144 xenial
Affected pkg:deb/ubuntu/linux-modules-extra-4.15.0-1159-azure?distro=xenial ubuntu linux-modules-extra-4.15.0-1159-azure < 4.15.0-1159.174~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-modules-4.15.0-1159-azure?distro=xenial ubuntu linux-modules-4.15.0-1159-azure < 4.15.0-1159.174~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-image-unsigned-4.15.0-1159-azure?distro=xenial ubuntu linux-image-unsigned-4.15.0-1159-azure < 4.15.0-1159.174~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-image-azure?distro=xenial ubuntu linux-image-azure < 4.15.0.1159.144 xenial
Affected pkg:deb/ubuntu/linux-image-azure-edge?distro=xenial ubuntu linux-image-azure-edge < 4.15.0.1159.144 xenial
Affected pkg:deb/ubuntu/linux-image-4.15.0-1159-azure?distro=xenial ubuntu linux-image-4.15.0-1159-azure < 4.15.0-1159.174~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-headers-azure?distro=xenial ubuntu linux-headers-azure < 4.15.0.1159.144 xenial
Affected pkg:deb/ubuntu/linux-headers-azure-edge?distro=xenial ubuntu linux-headers-azure-edge < 4.15.0.1159.144 xenial
Affected pkg:deb/ubuntu/linux-headers-4.15.0-1159-azure?distro=xenial ubuntu linux-headers-4.15.0-1159-azure < 4.15.0-1159.174~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-cloud-tools-azure?distro=xenial ubuntu linux-cloud-tools-azure < 4.15.0.1159.144 xenial
Affected pkg:deb/ubuntu/linux-cloud-tools-azure-edge?distro=xenial ubuntu linux-cloud-tools-azure-edge < 4.15.0.1159.144 xenial
Affected pkg:deb/ubuntu/linux-cloud-tools-4.15.0-1159-azure?distro=xenial ubuntu linux-cloud-tools-4.15.0-1159-azure < 4.15.0-1159.174~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-buildinfo-4.15.0-1159-azure?distro=xenial ubuntu linux-buildinfo-4.15.0-1159-azure < 4.15.0-1159.174~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-azure?distro=xenial ubuntu linux-azure < 4.15.0.1159.144 xenial
Affected pkg:deb/ubuntu/linux-azure-tools-4.15.0-1159?distro=xenial ubuntu linux-azure-tools-4.15.0-1159 < 4.15.0-1159.174~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-azure-headers-4.15.0-1159?distro=xenial ubuntu linux-azure-headers-4.15.0-1159 < 4.15.0-1159.174~16.04.1 xenial
Affected pkg:deb/ubuntu/linux-azure-edge?distro=xenial ubuntu linux-azure-edge < 4.15.0.1159.144 xenial
Affected pkg:deb/ubuntu/linux-azure-cloud-tools-4.15.0-1159?distro=xenial ubuntu linux-azure-cloud-tools-4.15.0-1159 < 4.15.0-1159.174~16.04.1 xenial
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...