USN-4367-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-4367-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4367-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-4367-1
Related
Published
2020-05-24T02:16:45.652070Z
Modified
2020-05-24T02:16:45.652070Z
Summary
linux, linux-aws, linux-azure, linux-gcp, linux-kvm, linux-oracle, linux-raspi, linux-riscv vulnerabilities
Details

It was discovered that the btrfs implementation in the Linux kernel did not properly detect that a block was marked dirty in some situations. An attacker could use this to specially craft a file system image that, when unmounted, could cause a denial of service (system crash). (CVE-2019-19377)

It was discovered that the linux kernel did not properly validate certain mount options to the tmpfs virtual memory file system. A local attacker with the ability to specify mount options could use this to cause a denial of service (system crash). (CVE-2020-11565)

It was discovered that the block layer in the Linux kernel contained a race condition leading to a use-after-free vulnerability. A local attacker could possibly use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2020-12657)

References

Affected packages

Ubuntu:20.04:LTS / linux

Package

Name
linux
Purl
pkg:deb/ubuntu/linux@5.4.0-31.35?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.0-31.35

Affected versions

5.*

5.3.0-18.19
5.3.0-24.26
5.4.0-9.12
5.4.0-18.22
5.4.0-21.25
5.4.0-24.28
5.4.0-25.29
5.4.0-26.30
5.4.0-28.32
5.4.0-29.33

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "multipath-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "plip-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "fs-secondary-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "linux-image-unsigned-5.4.0-31-lowlatency": "5.4.0-31.35",
            "storage-core-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "linux-modules-5.4.0-31-generic": "5.4.0-31.35",
            "linux-image-5.4.0-31-generic-dbgsym": "5.4.0-31.35",
            "linux-image-unsigned-5.4.0-31-lowlatency-dbgsym": "5.4.0-31.35",
            "fat-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "kernel-image-5.4.0-31-generic-di": "5.4.0-31.35",
            "mouse-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "multipath-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "nfs-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "fb-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "linux-udebs-generic": "5.4.0-31.35",
            "ipmi-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "kernel-image-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "ppp-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "ppp-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "firewire-core-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "linux-cloud-tools-5.4.0-31-generic": "5.4.0-31.35",
            "parport-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "floppy-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "block-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "dasd-extra-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "linux-image-unsigned-5.4.0-31-generic-dbgsym": "5.4.0-31.35",
            "linux-cloud-tools-5.4.0-31": "5.4.0-31.35",
            "md-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "linux-image-unsigned-5.4.0-31-generic": "5.4.0-31.35",
            "crypto-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "linux-buildinfo-5.4.0-31-generic": "5.4.0-31.35",
            "fs-secondary-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "fs-core-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "crypto-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "linux-tools-5.4.0-31-lowlatency": "5.4.0-31.35",
            "nic-shared-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "ipmi-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "linux-buildinfo-5.4.0-31-lowlatency": "5.4.0-31.35",
            "mouse-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "usb-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "input-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "serial-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "sata-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "nic-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "nic-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "nic-usb-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "nfs-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "scsi-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "pata-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "linux-cloud-tools-common": "5.4.0-31.35",
            "linux-libc-dev": "5.4.0-31.35",
            "linux-cloud-tools-5.4.0-31-lowlatency": "5.4.0-31.35",
            "linux-modules-5.4.0-31-generic-lpae": "5.4.0-31.35",
            "pcmcia-storage-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "linux-doc": "5.4.0-31.35",
            "input-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "linux-image-5.4.0-31-generic-lpae": "5.4.0-31.35",
            "fs-core-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "nic-shared-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "linux-tools-5.4.0-31-generic-lpae": "5.4.0-31.35",
            "linux-source-5.4.0": "5.4.0-31.35",
            "linux-headers-5.4.0-31-generic-lpae": "5.4.0-31.35",
            "linux-headers-5.4.0-31-lowlatency": "5.4.0-31.35",
            "linux-tools-5.4.0-31-generic": "5.4.0-31.35",
            "vlan-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "linux-image-5.4.0-31-generic": "5.4.0-31.35",
            "scsi-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "block-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "vlan-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "linux-image-5.4.0-31-generic-lpae-dbgsym": "5.4.0-31.35",
            "linux-tools-host": "5.4.0-31.35",
            "fat-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "linux-buildinfo-5.4.0-31-generic-lpae": "5.4.0-31.35",
            "linux-modules-extra-5.4.0-31-generic": "5.4.0-31.35",
            "nic-pcmcia-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "md-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "linux-headers-5.4.0-31-generic": "5.4.0-31.35",
            "linux-udebs-generic-lpae": "5.4.0-31.35",
            "virtio-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "linux-headers-5.4.0-31": "5.4.0-31.35",
            "usb-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "pcmcia-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "linux-tools-5.4.0-31": "5.4.0-31.35",
            "message-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "parport-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "linux-tools-common": "5.4.0-31.35",
            "nic-usb-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "dasd-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "storage-core-modules-5.4.0-31-generic-di": "5.4.0-31.35",
            "plip-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35",
            "linux-modules-5.4.0-31-lowlatency": "5.4.0-31.35",
            "sata-modules-5.4.0-31-generic-lpae-di": "5.4.0-31.35"
        }
    ]
}

Ubuntu:20.04:LTS / linux-aws

Package

Name
linux-aws
Purl
pkg:deb/ubuntu/linux-aws@5.4.0-1011.11?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.0-1011.11

Affected versions

5.*

5.3.0-1003.3
5.3.0-1008.9
5.3.0-1009.10
5.3.0-1010.11
5.4.0-1005.5
5.4.0-1007.7
5.4.0-1008.8
5.4.0-1009.9

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-tools-5.4.0-1011-aws": "5.4.0-1011.11",
            "linux-aws-headers-5.4.0-1011": "5.4.0-1011.11",
            "linux-image-5.4.0-1011-aws-dbgsym": "5.4.0-1011.11",
            "linux-aws-cloud-tools-5.4.0-1011": "5.4.0-1011.11",
            "linux-image-5.4.0-1011-aws": "5.4.0-1011.11",
            "linux-modules-5.4.0-1011-aws": "5.4.0-1011.11",
            "linux-buildinfo-5.4.0-1011-aws": "5.4.0-1011.11",
            "linux-aws-tools-5.4.0-1011": "5.4.0-1011.11",
            "linux-cloud-tools-5.4.0-1011-aws": "5.4.0-1011.11",
            "linux-headers-5.4.0-1011-aws": "5.4.0-1011.11",
            "linux-modules-extra-5.4.0-1011-aws": "5.4.0-1011.11"
        }
    ]
}

Ubuntu:20.04:LTS / linux-azure

Package

Name
linux-azure
Purl
pkg:deb/ubuntu/linux-azure@5.4.0-1012.12?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.0-1012.12

Affected versions

5.*

5.3.0-1003.3
5.3.0-1008.9
5.3.0-1009.10
5.4.0-1006.6
5.4.0-1008.8
5.4.0-1009.9
5.4.0-1010.10

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-azure-headers-5.4.0-1012": "5.4.0-1012.12",
            "linux-image-unsigned-5.4.0-1012-azure": "5.4.0-1012.12",
            "linux-azure-cloud-tools-5.4.0-1012": "5.4.0-1012.12",
            "linux-buildinfo-5.4.0-1012-azure": "5.4.0-1012.12",
            "linux-azure-tools-5.4.0-1012": "5.4.0-1012.12",
            "linux-modules-5.4.0-1012-azure": "5.4.0-1012.12",
            "linux-image-unsigned-5.4.0-1012-azure-dbgsym": "5.4.0-1012.12",
            "linux-tools-5.4.0-1012-azure": "5.4.0-1012.12",
            "linux-modules-extra-5.4.0-1012-azure": "5.4.0-1012.12",
            "linux-cloud-tools-5.4.0-1012-azure": "5.4.0-1012.12",
            "linux-headers-5.4.0-1012-azure": "5.4.0-1012.12"
        }
    ]
}

Ubuntu:20.04:LTS / linux-gcp

Package

Name
linux-gcp
Purl
pkg:deb/ubuntu/linux-gcp@5.4.0-1011.11?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.0-1011.11

Affected versions

5.*

5.3.0-1004.4
5.3.0-1009.10
5.3.0-1011.12
5.4.0-1005.5
5.4.0-1007.7
5.4.0-1008.8
5.4.0-1009.9

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-image-unsigned-5.4.0-1011-gcp-dbgsym": "5.4.0-1011.11",
            "linux-buildinfo-5.4.0-1011-gcp": "5.4.0-1011.11",
            "linux-gcp-tools-5.4.0-1011": "5.4.0-1011.11",
            "linux-image-unsigned-5.4.0-1011-gcp": "5.4.0-1011.11",
            "linux-modules-5.4.0-1011-gcp": "5.4.0-1011.11",
            "linux-headers-5.4.0-1011-gcp": "5.4.0-1011.11",
            "linux-gcp-headers-5.4.0-1011": "5.4.0-1011.11",
            "linux-modules-extra-5.4.0-1011-gcp": "5.4.0-1011.11",
            "linux-tools-5.4.0-1011-gcp": "5.4.0-1011.11"
        }
    ]
}

Ubuntu:20.04:LTS / linux-kvm

Package

Name
linux-kvm
Purl
pkg:deb/ubuntu/linux-kvm@5.4.0-1011.11?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.0-1011.11

Affected versions

5.*

5.3.0-1003.3
5.3.0-1008.9
5.3.0-1009.10
5.4.0-1004.4
5.4.0-1006.6
5.4.0-1007.7
5.4.0-1008.8
5.4.0-1009.9

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-buildinfo-5.4.0-1011-kvm": "5.4.0-1011.11",
            "linux-modules-5.4.0-1011-kvm": "5.4.0-1011.11",
            "linux-tools-5.4.0-1011-kvm": "5.4.0-1011.11",
            "linux-headers-5.4.0-1011-kvm": "5.4.0-1011.11",
            "linux-image-5.4.0-1011-kvm": "5.4.0-1011.11",
            "linux-kvm-tools-5.4.0-1011": "5.4.0-1011.11",
            "linux-kvm-headers-5.4.0-1011": "5.4.0-1011.11",
            "linux-image-5.4.0-1011-kvm-dbgsym": "5.4.0-1011.11"
        }
    ]
}

Ubuntu:20.04:LTS / linux-oracle

Package

Name
linux-oracle
Purl
pkg:deb/ubuntu/linux-oracle@5.4.0-1011.11?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.0-1011.11

Affected versions

5.*

5.3.0-1002.2
5.3.0-1007.8
5.3.0-1008.9
5.4.0-1005.5
5.4.0-1007.7
5.4.0-1008.8
5.4.0-1009.9

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-image-unsigned-5.4.0-1011-oracle": "5.4.0-1011.11",
            "linux-buildinfo-5.4.0-1011-oracle": "5.4.0-1011.11",
            "linux-image-unsigned-5.4.0-1011-oracle-dbgsym": "5.4.0-1011.11",
            "linux-modules-5.4.0-1011-oracle": "5.4.0-1011.11",
            "linux-modules-extra-5.4.0-1011-oracle": "5.4.0-1011.11",
            "linux-oracle-headers-5.4.0-1011": "5.4.0-1011.11",
            "linux-tools-5.4.0-1011-oracle": "5.4.0-1011.11",
            "linux-headers-5.4.0-1011-oracle": "5.4.0-1011.11",
            "linux-oracle-tools-5.4.0-1011": "5.4.0-1011.11"
        }
    ]
}

Ubuntu:20.04:LTS / linux-raspi

Package

Name
linux-raspi
Purl
pkg:deb/ubuntu/linux-raspi@5.4.0-1011.11?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.0-1011.11

Affected versions

5.*

5.4.0-1007.7
5.4.0-1008.8

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-tools-5.4.0-1011-raspi": "5.4.0-1011.11",
            "linux-headers-5.4.0-1011-raspi": "5.4.0-1011.11",
            "linux-image-5.4.0-1011-raspi-dbgsym": "5.4.0-1011.11",
            "linux-buildinfo-5.4.0-1011-raspi": "5.4.0-1011.11",
            "linux-image-5.4.0-1011-raspi": "5.4.0-1011.11",
            "linux-modules-5.4.0-1011-raspi": "5.4.0-1011.11",
            "linux-raspi-tools-5.4.0-1011": "5.4.0-1011.11",
            "linux-raspi-headers-5.4.0-1011": "5.4.0-1011.11"
        }
    ]
}

Ubuntu:20.04:LTS / linux-riscv

Package

Name
linux-riscv
Purl
pkg:deb/ubuntu/linux-riscv@5.4.0-26.30?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.0-26.30

Affected versions

5.*

5.4.0-24.28

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "parport-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "nic-shared-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "linux-riscv-tools-5.4.0-26": "5.4.0-26.30",
            "input-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "scsi-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "crypto-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "linux-libc-dev": "5.4.0-26.30",
            "fs-secondary-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "vlan-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "linux-udebs-generic": "5.4.0-26.30",
            "plip-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "fs-core-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "usb-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "virtio-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "linux-image-5.4.0-26-generic": "5.4.0-26.30",
            "multipath-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "linux-modules-5.4.0-26-generic": "5.4.0-26.30",
            "linux-headers-5.4.0-26-generic": "5.4.0-26.30",
            "firewire-core-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "message-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "linux-image-5.4.0-26-generic-dbgsym": "5.4.0-26.30",
            "linux-buildinfo-5.4.0-26-generic": "5.4.0-26.30",
            "mouse-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "linux-modules-extra-5.4.0-26-generic": "5.4.0-26.30",
            "linux-riscv-headers-5.4.0-26": "5.4.0-26.30",
            "linux-tools-5.4.0-26-generic": "5.4.0-26.30",
            "md-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "kernel-image-5.4.0-26-generic-di": "5.4.0-26.30",
            "block-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "sata-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "nic-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "nfs-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "nic-usb-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "pata-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "ppp-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "fat-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "storage-core-modules-5.4.0-26-generic-di": "5.4.0-26.30",
            "ipmi-modules-5.4.0-26-generic-di": "5.4.0-26.30"
        }
    ]
}