USN-4577-1

Source
https://ubuntu.com/security/notices/USN-4577-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4577-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-4577-1
Related
Published
2020-10-14T02:28:30.838263Z
Modified
2020-10-14T02:28:30.838263Z
Summary
linux-hwe, linux-gke-5.0, linux-gke-5.3, linux-oem-osp1, linux-raspi2-5.3 vulnerabilities
Details

Hadar Manor discovered that the DCCP protocol implementation in the Linux kernel improperly handled socket reuse, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-16119)

Giuseppe Scrivano discovered that the overlay file system in the Linux kernel did not properly perform permission checks in some situations. A local attacker could possibly use this to bypass intended restrictions and gain read access to restricted files. (CVE-2020-16120)

References

Affected packages

Ubuntu:18.04:LTS / linux-gke-5.0

Package

Name
linux-gke-5.0
Purl
pkg:deb/ubuntu/linux-gke-5.0?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.0-1049.50

Affected versions

5.*

5.0.0-1011.11~18.04.1
5.0.0-1013.13~18.04.1
5.0.0-1015.15~18.04.1
5.0.0-1017.17~18.04.1
5.0.0-1020.20~18.04.1
5.0.0-1022.22~18.04.3
5.0.0-1023.23~18.04.2
5.0.0-1025.26~18.04.1
5.0.0-1026.27~18.04.2
5.0.0-1027.28~18.04.1
5.0.0-1029.30~18.04.1
5.0.0-1030.31
5.0.0-1032.33
5.0.0-1033.34
5.0.0-1035.36
5.0.0-1037.38
5.0.0-1042.43
5.0.0-1043.44
5.0.0-1045.46
5.0.0-1046.47
5.0.0-1047.48

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "5.0.0-1049.50",
            "binary_name": "linux-buildinfo-5.0.0-1049-gke"
        },
        {
            "binary_version": "5.0.0-1049.50",
            "binary_name": "linux-gke-5.0-headers-5.0.0-1049"
        },
        {
            "binary_version": "5.0.0-1049.50",
            "binary_name": "linux-gke-5.0-tools-5.0.0-1049"
        },
        {
            "binary_version": "5.0.0-1049.50",
            "binary_name": "linux-headers-5.0.0-1049-gke"
        },
        {
            "binary_version": "5.0.0-1049.50",
            "binary_name": "linux-image-unsigned-5.0.0-1049-gke"
        },
        {
            "binary_version": "5.0.0-1049.50",
            "binary_name": "linux-image-unsigned-5.0.0-1049-gke-dbgsym"
        },
        {
            "binary_version": "5.0.0-1049.50",
            "binary_name": "linux-modules-5.0.0-1049-gke"
        },
        {
            "binary_version": "5.0.0-1049.50",
            "binary_name": "linux-modules-extra-5.0.0-1049-gke"
        },
        {
            "binary_version": "5.0.0-1049.50",
            "binary_name": "linux-tools-5.0.0-1049-gke"
        }
    ]
}

Ubuntu:18.04:LTS / linux-gke-5.3

Package

Name
linux-gke-5.3
Purl
pkg:deb/ubuntu/linux-gke-5.3?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.3.0-1038.40

Affected versions

5.*

5.3.0-1011.12~18.04.1
5.3.0-1012.13~18.04.1
5.3.0-1014.15~18.04.1
5.3.0-1016.17~18.04.1
5.3.0-1017.18~18.04.1
5.3.0-1018.19~18.04.1
5.3.0-1020.22~18.04.1
5.3.0-1026.28~18.04.1
5.3.0-1030.32~18.04.1
5.3.0-1032.34~18.04.1
5.3.0-1033.35
5.3.0-1034.36
5.3.0-1036.38

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "5.3.0-1038.40",
            "binary_name": "linux-buildinfo-5.3.0-1038-gke"
        },
        {
            "binary_version": "5.3.0-1038.40",
            "binary_name": "linux-gke-5.3-headers-5.3.0-1038"
        },
        {
            "binary_version": "5.3.0-1038.40",
            "binary_name": "linux-gke-5.3-tools-5.3.0-1038"
        },
        {
            "binary_version": "5.3.0-1038.40",
            "binary_name": "linux-headers-5.3.0-1038-gke"
        },
        {
            "binary_version": "5.3.0-1038.40",
            "binary_name": "linux-image-unsigned-5.3.0-1038-gke"
        },
        {
            "binary_version": "5.3.0-1038.40",
            "binary_name": "linux-image-unsigned-5.3.0-1038-gke-dbgsym"
        },
        {
            "binary_version": "5.3.0-1038.40",
            "binary_name": "linux-modules-5.3.0-1038-gke"
        },
        {
            "binary_version": "5.3.0-1038.40",
            "binary_name": "linux-modules-extra-5.3.0-1038-gke"
        },
        {
            "binary_version": "5.3.0-1038.40",
            "binary_name": "linux-tools-5.3.0-1038-gke"
        }
    ]
}

Ubuntu:18.04:LTS / linux-hwe

Package

Name
linux-hwe
Purl
pkg:deb/ubuntu/linux-hwe?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.3.0-68.63

Affected versions

4.*

4.18.0-13.14~18.04.1
4.18.0-14.15~18.04.1
4.18.0-15.16~18.04.1
4.18.0-16.17~18.04.1
4.18.0-17.18~18.04.1
4.18.0-18.19~18.04.1
4.18.0-20.21~18.04.1
4.18.0-21.22~18.04.1
4.18.0-22.23~18.04.1
4.18.0-24.25~18.04.1
4.18.0-25.26~18.04.1

5.*

5.0.0-23.24~18.04.1
5.0.0-25.26~18.04.1
5.0.0-27.28~18.04.1
5.0.0-29.31~18.04.1
5.0.0-31.33~18.04.1
5.0.0-32.34~18.04.2
5.0.0-35.38~18.04.1
5.0.0-36.39~18.04.1
5.0.0-37.40~18.04.1
5.3.0-26.28~18.04.1
5.3.0-28.30~18.04.1
5.3.0-40.32~18.04.1
5.3.0-42.34~18.04.1
5.3.0-45.37~18.04.1
5.3.0-46.38~18.04.1
5.3.0-51.44~18.04.2
5.3.0-53.47~18.04.1
5.3.0-59.53~18.04.1
5.3.0-61.55~18.04.1
5.3.0-62.56~18.04.1
5.3.0-64.58~18.04.1
5.3.0-65.59
5.3.0-66.60
5.3.0-67.61

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "block-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "crypto-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "fat-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "fb-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "firewire-core-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "floppy-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "fs-core-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "fs-secondary-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "input-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "ipmi-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "kernel-image-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-buildinfo-5.3.0-68-generic"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-buildinfo-5.3.0-68-lowlatency"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-cloud-tools-5.3.0-68-generic"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-cloud-tools-5.3.0-68-lowlatency"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-headers-5.3.0-68-generic"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-headers-5.3.0-68-lowlatency"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-hwe-cloud-tools-5.3.0-68"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-hwe-headers-5.3.0-68"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-hwe-tools-5.3.0-68"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-hwe-udebs-generic"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-image-5.3.0-68-generic"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-image-5.3.0-68-generic-dbgsym"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-image-5.3.0-68-lowlatency"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-image-5.3.0-68-lowlatency-dbgsym"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-image-unsigned-5.3.0-68-generic"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-image-unsigned-5.3.0-68-generic-dbgsym"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-image-unsigned-5.3.0-68-lowlatency"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-image-unsigned-5.3.0-68-lowlatency-dbgsym"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-modules-5.3.0-68-generic"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-modules-5.3.0-68-lowlatency"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-modules-extra-5.3.0-68-generic"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-source-5.3.0"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-tools-5.3.0-68-generic"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "linux-tools-5.3.0-68-lowlatency"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "md-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "message-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "mouse-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "multipath-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "nfs-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "nic-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "nic-pcmcia-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "nic-shared-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "nic-usb-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "parport-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "pata-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "pcmcia-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "pcmcia-storage-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "plip-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "ppp-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "sata-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "scsi-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "serial-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "storage-core-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "usb-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "virtio-modules-5.3.0-68-generic-di"
        },
        {
            "binary_version": "5.3.0-68.63",
            "binary_name": "vlan-modules-5.3.0-68-generic-di"
        }
    ]
}

Ubuntu:18.04:LTS / linux-oem-osp1

Package

Name
linux-oem-osp1
Purl
pkg:deb/ubuntu/linux-oem-osp1?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.0-1069.75

Affected versions

5.*

5.0.0-1010.11
5.0.0-1012.13
5.0.0-1015.16
5.0.0-1018.20
5.0.0-1020.22
5.0.0-1022.24
5.0.0-1024.27
5.0.0-1025.28
5.0.0-1027.31
5.0.0-1028.32
5.0.0-1030.34
5.0.0-1033.38
5.0.0-1037.42
5.0.0-1039.44
5.0.0-1040.45
5.0.0-1043.48
5.0.0-1046.51
5.0.0-1047.52
5.0.0-1050.55
5.0.0-1052.57
5.0.0-1059.64
5.0.0-1062.67
5.0.0-1063.68
5.0.0-1065.70
5.0.0-1067.72
5.0.0-1068.73

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "block-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "crypto-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "fat-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "fb-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "firewire-core-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "floppy-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "fs-core-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "fs-secondary-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "input-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "ipmi-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "kernel-image-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "linux-buildinfo-5.0.0-1069-oem-osp1"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "linux-headers-5.0.0-1069-oem-osp1"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "linux-image-unsigned-5.0.0-1069-oem-osp1"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "linux-image-unsigned-5.0.0-1069-oem-osp1-dbgsym"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "linux-modules-5.0.0-1069-oem-osp1"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "linux-oem-osp1-headers-5.0.0-1069"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "linux-oem-osp1-tools-5.0.0-1069"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "linux-oem-osp1-tools-host"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "linux-tools-5.0.0-1069-oem-osp1"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "linux-udebs-oem-osp1"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "md-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "message-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "mouse-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "multipath-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "nfs-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "nic-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "nic-pcmcia-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "nic-shared-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "nic-usb-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "parport-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "pata-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "pcmcia-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "pcmcia-storage-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "plip-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "ppp-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "sata-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "scsi-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "serial-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "storage-core-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "usb-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "virtio-modules-5.0.0-1069-oem-osp1-di"
        },
        {
            "binary_version": "5.0.0-1069.75",
            "binary_name": "vlan-modules-5.0.0-1069-oem-osp1-di"
        }
    ]
}

Ubuntu:18.04:LTS / linux-raspi2-5.3

Package

Name
linux-raspi2-5.3
Purl
pkg:deb/ubuntu/linux-raspi2-5.3?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.3.0-1035.37

Affected versions

5.*

5.3.0-1017.19~18.04.1
5.3.0-1018.20~18.04.1
5.3.0-1019.21~18.04.1
5.3.0-1021.23~18.04.1
5.3.0-1022.24~18.04.1
5.3.0-1023.25~18.04.1
5.3.0-1026.28~18.04.1
5.3.0-1027.29~18.04.1
5.3.0-1028.30~18.04.2
5.3.0-1030.32~18.04.2
5.3.0-1032.34
5.3.0-1033.35

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "5.3.0-1035.37",
            "binary_name": "linux-buildinfo-5.3.0-1035-raspi2"
        },
        {
            "binary_version": "5.3.0-1035.37",
            "binary_name": "linux-headers-5.3.0-1035-raspi2"
        },
        {
            "binary_version": "5.3.0-1035.37",
            "binary_name": "linux-image-5.3.0-1035-raspi2"
        },
        {
            "binary_version": "5.3.0-1035.37",
            "binary_name": "linux-image-5.3.0-1035-raspi2-dbgsym"
        },
        {
            "binary_version": "5.3.0-1035.37",
            "binary_name": "linux-modules-5.3.0-1035-raspi2"
        },
        {
            "binary_version": "5.3.0-1035.37",
            "binary_name": "linux-raspi2-5.3-headers-5.3.0-1035"
        },
        {
            "binary_version": "5.3.0-1035.37",
            "binary_name": "linux-raspi2-5.3-tools-5.3.0-1035"
        },
        {
            "binary_version": "5.3.0-1035.37",
            "binary_name": "linux-tools-5.3.0-1035-raspi2"
        }
    ]
}