USN-4367-2

Source
https://ubuntu.com/security/notices/USN-4367-2
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4367-2.json
JSON Data
https://api.osv.dev/v1/vulns/USN-4367-2
Published
2020-05-28T22:46:00Z
Modified
2026-02-10T04:41:50Z
Summary
linux regression
Details

USN-4367-1 fixed vulnerabilities in the 5.4 Linux kernel. Unfortunately, that update introduced a regression in overlayfs. This update corrects the problem.

We apologize for the inconvenience.

Original advisory details:

It was discovered that the btrfs implementation in the Linux kernel did not properly detect that a block was marked dirty in some situations. An attacker could use this to specially craft a file system image that, when unmounted, could cause a denial of service (system crash). (CVE-2019-19377)

It was discovered that the linux kernel did not properly validate certain mount options to the tmpfs virtual memory file system. A local attacker with the ability to specify mount options could use this to cause a denial of service (system crash). (CVE-2020-11565)

It was discovered that the block layer in the Linux kernel contained a race condition leading to a use-after-free vulnerability. A local attacker could possibly use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2020-12657)

References

Affected packages

Ubuntu:20.04:LTS / linux

Package

Name
linux
Purl
pkg:deb/ubuntu/linux@5.4.0-33.37?arch=source&distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.0-33.37

Affected versions

5.*
5.3.0-18.19
5.3.0-24.26
5.4.0-9.12
5.4.0-18.22
5.4.0-21.25
5.4.0-24.28
5.4.0-25.29
5.4.0-26.30
5.4.0-28.32
5.4.0-29.33
5.4.0-31.35

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_name": "block-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "block-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "crypto-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "crypto-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "dasd-extra-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "dasd-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "fat-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "fat-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "fb-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "firewire-core-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "floppy-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "fs-core-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "fs-core-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "fs-secondary-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "fs-secondary-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "input-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "input-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "ipmi-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "ipmi-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "kernel-image-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "kernel-image-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-buildinfo-5.4.0-33-generic",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-buildinfo-5.4.0-33-generic-lpae",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-buildinfo-5.4.0-33-lowlatency",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-cloud-tools-5.4.0-33",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-cloud-tools-5.4.0-33-generic",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-cloud-tools-5.4.0-33-lowlatency",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-cloud-tools-common",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-headers-5.4.0-33",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-headers-5.4.0-33-generic",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-headers-5.4.0-33-generic-lpae",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-headers-5.4.0-33-lowlatency",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-image-5.4.0-33-generic",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-image-5.4.0-33-generic-lpae",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-image-unsigned-5.4.0-33-generic",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-image-unsigned-5.4.0-33-lowlatency",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-libc-dev",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-modules-5.4.0-33-generic",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-modules-5.4.0-33-generic-lpae",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-modules-5.4.0-33-lowlatency",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-modules-extra-5.4.0-33-generic",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-source-5.4.0",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-tools-5.4.0-33",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-tools-5.4.0-33-generic",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-tools-5.4.0-33-generic-lpae",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-tools-5.4.0-33-lowlatency",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-tools-common",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-tools-host",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-udebs-generic",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "linux-udebs-generic-lpae",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "md-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "md-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "message-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "mouse-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "mouse-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "multipath-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "multipath-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "nfs-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "nfs-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "nic-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "nic-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "nic-pcmcia-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "nic-shared-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "nic-shared-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "nic-usb-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "nic-usb-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "parport-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "parport-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "pata-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "pcmcia-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "pcmcia-storage-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "plip-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "plip-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "ppp-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "ppp-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "sata-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "sata-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "scsi-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "scsi-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "serial-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "storage-core-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "storage-core-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "usb-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "usb-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "virtio-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "vlan-modules-5.4.0-33-generic-di",
            "binary_version": "5.4.0-33.37"
        },
        {
            "binary_name": "vlan-modules-5.4.0-33-generic-lpae-di",
            "binary_version": "5.4.0-33.37"
        }
    ]
}

Database specific

source
"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4367-2.json"
cves_map
{
    "ecosystem": "Ubuntu:20.04:LTS",
    "cves": []
}