USN-4713-2

Source
https://ubuntu.com/security/notices/USN-4713-2
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4713-2.json
JSON Data
https://api.osv.dev/v1/vulns/USN-4713-2
Related
Published
2021-02-10T01:17:36.507048Z
Modified
2021-02-10T01:17:36.507048Z
Summary
linux, linux-gke-5.0, linux-gke-5.3, linux-hwe, linux-raspi2-5.3 vulnerability
Details

It was discovered that the LIO SCSI target implementation in the Linux kernel performed insufficient identifier checking in certain XCOPY requests. An attacker with access to at least one LUN in a multiple backstore environment could use this to expose sensitive information or modify data.

References

Affected packages

Ubuntu:14.04:LTS / linux

Package

Name
linux
Purl
pkg:deb/ubuntu/linux?arch=src?distro=trusty

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.13.0-184.235

Affected versions

3.*

3.11.0-12.19
3.12.0-1.3
3.12.0-2.5
3.12.0-2.7
3.12.0-3.8
3.12.0-3.9
3.12.0-4.10
3.12.0-4.12
3.12.0-5.13
3.12.0-7.15
3.13.0-1.16
3.13.0-2.17
3.13.0-3.18
3.13.0-4.19
3.13.0-5.20
3.13.0-6.23
3.13.0-7.25
3.13.0-7.26
3.13.0-8.27
3.13.0-8.28
3.13.0-10.30
3.13.0-11.31
3.13.0-12.32
3.13.0-13.33
3.13.0-14.34
3.13.0-15.35
3.13.0-16.36
3.13.0-17.37
3.13.0-18.38
3.13.0-19.39
3.13.0-19.40
3.13.0-20.42
3.13.0-21.43
3.13.0-22.44
3.13.0-23.45
3.13.0-24.46
3.13.0-24.47
3.13.0-27.50
3.13.0-29.53
3.13.0-30.54
3.13.0-30.55
3.13.0-32.57
3.13.0-33.58
3.13.0-34.60
3.13.0-35.62
3.13.0-36.63
3.13.0-37.64
3.13.0-39.66
3.13.0-40.69
3.13.0-41.70
3.13.0-43.72
3.13.0-44.73
3.13.0-45.74
3.13.0-46.75
3.13.0-46.76
3.13.0-46.77
3.13.0-46.79
3.13.0-48.80
3.13.0-49.81
3.13.0-49.83
3.13.0-51.84
3.13.0-52.85
3.13.0-52.86
3.13.0-53.88
3.13.0-53.89
3.13.0-54.91
3.13.0-55.92
3.13.0-55.94
3.13.0-57.95
3.13.0-58.97
3.13.0-59.98
3.13.0-61.100
3.13.0-62.102
3.13.0-63.103
3.13.0-65.105
3.13.0-65.106
3.13.0-66.108
3.13.0-67.110
3.13.0-68.111
3.13.0-70.113
3.13.0-71.114
3.13.0-73.116
3.13.0-74.118
3.13.0-76.120
3.13.0-77.121
3.13.0-79.123
3.13.0-83.127
3.13.0-85.129
3.13.0-86.130
3.13.0-86.131
3.13.0-87.133
3.13.0-88.135
3.13.0-91.138
3.13.0-92.139
3.13.0-93.140
3.13.0-95.142
3.13.0-96.143
3.13.0-98.145
3.13.0-100.147
3.13.0-101.148
3.13.0-103.150
3.13.0-105.152
3.13.0-106.153
3.13.0-107.154
3.13.0-108.155
3.13.0-109.156
3.13.0-110.157
3.13.0-111.158
3.13.0-112.159
3.13.0-113.160
3.13.0-115.162
3.13.0-116.163
3.13.0-117.164
3.13.0-119.166
3.13.0-121.170
3.13.0-123.172
3.13.0-125.174
3.13.0-126.175
3.13.0-128.177
3.13.0-129.178
3.13.0-132.181
3.13.0-133.182
3.13.0-135.184
3.13.0-137.186
3.13.0-139.188
3.13.0-141.190
3.13.0-142.191
3.13.0-143.192
3.13.0-144.193
3.13.0-145.194
3.13.0-147.196
3.13.0-149.199
3.13.0-151.201
3.13.0-153.203
3.13.0-155.205
3.13.0-156.206
3.13.0-157.207
3.13.0-158.208
3.13.0-160.210
3.13.0-161.211
3.13.0-162.212
3.13.0-163.213
3.13.0-164.214
3.13.0-165.215
3.13.0-166.216
3.13.0-167.217
3.13.0-168.218
3.13.0-169.219
3.13.0-170.220

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "3.13.0-184.235",
            "binary_name": "linux-image-3.13.0-184-powerpc64-smp"
        },
        {
            "binary_version": "3.13.0-184.235",
            "binary_name": "linux-image-3.13.0-184-powerpc-smp"
        },
        {
            "binary_version": "3.13.0-184.235",
            "binary_name": "linux-image-3.13.0-184-powerpc-e500mc"
        },
        {
            "binary_version": "3.13.0-184.235",
            "binary_name": "linux-image-3.13.0-184-powerpc-e500"
        },
        {
            "binary_version": "3.13.0-184.235",
            "binary_name": "linux-image-3.13.0-184-powerpc64-emb"
        },
        {
            "binary_version": "3.13.0-184.235",
            "binary_name": "linux-image-3.13.0-184-generic-lpae"
        }
    ]
}

Ubuntu:18.04:LTS / linux-gke-5.0

Package

Name
linux-gke-5.0
Purl
pkg:deb/ubuntu/linux-gke-5.0?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.0-1051.53

Affected versions

5.*

5.0.0-1011.11~18.04.1
5.0.0-1013.13~18.04.1
5.0.0-1015.15~18.04.1
5.0.0-1017.17~18.04.1
5.0.0-1020.20~18.04.1
5.0.0-1022.22~18.04.3
5.0.0-1023.23~18.04.2
5.0.0-1025.26~18.04.1
5.0.0-1026.27~18.04.2
5.0.0-1027.28~18.04.1
5.0.0-1029.30~18.04.1
5.0.0-1030.31
5.0.0-1032.33
5.0.0-1033.34
5.0.0-1035.36
5.0.0-1037.38
5.0.0-1042.43
5.0.0-1043.44
5.0.0-1045.46
5.0.0-1046.47
5.0.0-1047.48
5.0.0-1049.50
5.0.0-1050.52

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "5.0.0-1051.53",
            "binary_name": "linux-buildinfo-5.0.0-1051-gke"
        },
        {
            "binary_version": "5.0.0-1051.53",
            "binary_name": "linux-gke-5.0-headers-5.0.0-1051"
        },
        {
            "binary_version": "5.0.0-1051.53",
            "binary_name": "linux-gke-5.0-tools-5.0.0-1051"
        },
        {
            "binary_version": "5.0.0-1051.53",
            "binary_name": "linux-headers-5.0.0-1051-gke"
        },
        {
            "binary_version": "5.0.0-1051.53",
            "binary_name": "linux-image-unsigned-5.0.0-1051-gke"
        },
        {
            "binary_version": "5.0.0-1051.53",
            "binary_name": "linux-image-unsigned-5.0.0-1051-gke-dbgsym"
        },
        {
            "binary_version": "5.0.0-1051.53",
            "binary_name": "linux-modules-5.0.0-1051-gke"
        },
        {
            "binary_version": "5.0.0-1051.53",
            "binary_name": "linux-modules-extra-5.0.0-1051-gke"
        },
        {
            "binary_version": "5.0.0-1051.53",
            "binary_name": "linux-tools-5.0.0-1051-gke"
        }
    ]
}

Ubuntu:18.04:LTS / linux-gke-5.3

Package

Name
linux-gke-5.3
Purl
pkg:deb/ubuntu/linux-gke-5.3?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.3.0-1040.43

Affected versions

5.*

5.3.0-1011.12~18.04.1
5.3.0-1012.13~18.04.1
5.3.0-1014.15~18.04.1
5.3.0-1016.17~18.04.1
5.3.0-1017.18~18.04.1
5.3.0-1018.19~18.04.1
5.3.0-1020.22~18.04.1
5.3.0-1026.28~18.04.1
5.3.0-1030.32~18.04.1
5.3.0-1032.34~18.04.1
5.3.0-1033.35
5.3.0-1034.36
5.3.0-1036.38
5.3.0-1038.40
5.3.0-1039.42

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "5.3.0-1040.43",
            "binary_name": "linux-buildinfo-5.3.0-1040-gke"
        },
        {
            "binary_version": "5.3.0-1040.43",
            "binary_name": "linux-gke-5.3-headers-5.3.0-1040"
        },
        {
            "binary_version": "5.3.0-1040.43",
            "binary_name": "linux-gke-5.3-tools-5.3.0-1040"
        },
        {
            "binary_version": "5.3.0-1040.43",
            "binary_name": "linux-headers-5.3.0-1040-gke"
        },
        {
            "binary_version": "5.3.0-1040.43",
            "binary_name": "linux-image-unsigned-5.3.0-1040-gke"
        },
        {
            "binary_version": "5.3.0-1040.43",
            "binary_name": "linux-image-unsigned-5.3.0-1040-gke-dbgsym"
        },
        {
            "binary_version": "5.3.0-1040.43",
            "binary_name": "linux-modules-5.3.0-1040-gke"
        },
        {
            "binary_version": "5.3.0-1040.43",
            "binary_name": "linux-modules-extra-5.3.0-1040-gke"
        },
        {
            "binary_version": "5.3.0-1040.43",
            "binary_name": "linux-tools-5.3.0-1040-gke"
        }
    ]
}

Ubuntu:18.04:LTS / linux-hwe

Package

Name
linux-hwe
Purl
pkg:deb/ubuntu/linux-hwe?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.3.0-70.66

Affected versions

4.*

4.18.0-13.14~18.04.1
4.18.0-14.15~18.04.1
4.18.0-15.16~18.04.1
4.18.0-16.17~18.04.1
4.18.0-17.18~18.04.1
4.18.0-18.19~18.04.1
4.18.0-20.21~18.04.1
4.18.0-21.22~18.04.1
4.18.0-22.23~18.04.1
4.18.0-24.25~18.04.1
4.18.0-25.26~18.04.1

5.*

5.0.0-23.24~18.04.1
5.0.0-25.26~18.04.1
5.0.0-27.28~18.04.1
5.0.0-29.31~18.04.1
5.0.0-31.33~18.04.1
5.0.0-32.34~18.04.2
5.0.0-35.38~18.04.1
5.0.0-36.39~18.04.1
5.0.0-37.40~18.04.1
5.3.0-26.28~18.04.1
5.3.0-28.30~18.04.1
5.3.0-40.32~18.04.1
5.3.0-42.34~18.04.1
5.3.0-45.37~18.04.1
5.3.0-46.38~18.04.1
5.3.0-51.44~18.04.2
5.3.0-53.47~18.04.1
5.3.0-59.53~18.04.1
5.3.0-61.55~18.04.1
5.3.0-62.56~18.04.1
5.3.0-64.58~18.04.1
5.3.0-65.59
5.3.0-66.60
5.3.0-67.61
5.3.0-68.63
5.3.0-69.65

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "block-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "crypto-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "fat-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "fb-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "firewire-core-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "floppy-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "fs-core-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "fs-secondary-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "input-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "ipmi-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "kernel-image-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-buildinfo-5.3.0-70-generic"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-buildinfo-5.3.0-70-lowlatency"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-cloud-tools-5.3.0-70-generic"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-cloud-tools-5.3.0-70-lowlatency"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-headers-5.3.0-70-generic"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-headers-5.3.0-70-lowlatency"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-hwe-cloud-tools-5.3.0-70"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-hwe-headers-5.3.0-70"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-hwe-tools-5.3.0-70"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-hwe-udebs-generic"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-image-5.3.0-70-generic"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-image-5.3.0-70-generic-dbgsym"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-image-5.3.0-70-lowlatency"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-image-5.3.0-70-lowlatency-dbgsym"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-image-unsigned-5.3.0-70-generic"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-image-unsigned-5.3.0-70-generic-dbgsym"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-image-unsigned-5.3.0-70-lowlatency"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-image-unsigned-5.3.0-70-lowlatency-dbgsym"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-modules-5.3.0-70-generic"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-modules-5.3.0-70-lowlatency"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-modules-extra-5.3.0-70-generic"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-source-5.3.0"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-tools-5.3.0-70-generic"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "linux-tools-5.3.0-70-lowlatency"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "md-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "message-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "mouse-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "multipath-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "nfs-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "nic-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "nic-pcmcia-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "nic-shared-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "nic-usb-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "parport-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "pata-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "pcmcia-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "pcmcia-storage-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "plip-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "ppp-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "sata-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "scsi-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "serial-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "storage-core-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "usb-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "virtio-modules-5.3.0-70-generic-di"
        },
        {
            "binary_version": "5.3.0-70.66",
            "binary_name": "vlan-modules-5.3.0-70-generic-di"
        }
    ]
}

Ubuntu:18.04:LTS / linux-raspi2-5.3

Package

Name
linux-raspi2-5.3
Purl
pkg:deb/ubuntu/linux-raspi2-5.3?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.3.0-1037.39

Affected versions

5.*

5.3.0-1017.19~18.04.1
5.3.0-1018.20~18.04.1
5.3.0-1019.21~18.04.1
5.3.0-1021.23~18.04.1
5.3.0-1022.24~18.04.1
5.3.0-1023.25~18.04.1
5.3.0-1026.28~18.04.1
5.3.0-1027.29~18.04.1
5.3.0-1028.30~18.04.2
5.3.0-1030.32~18.04.2
5.3.0-1032.34
5.3.0-1033.35
5.3.0-1035.37
5.3.0-1036.38

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "5.3.0-1037.39",
            "binary_name": "linux-buildinfo-5.3.0-1037-raspi2"
        },
        {
            "binary_version": "5.3.0-1037.39",
            "binary_name": "linux-headers-5.3.0-1037-raspi2"
        },
        {
            "binary_version": "5.3.0-1037.39",
            "binary_name": "linux-image-5.3.0-1037-raspi2"
        },
        {
            "binary_version": "5.3.0-1037.39",
            "binary_name": "linux-image-5.3.0-1037-raspi2-dbgsym"
        },
        {
            "binary_version": "5.3.0-1037.39",
            "binary_name": "linux-modules-5.3.0-1037-raspi2"
        },
        {
            "binary_version": "5.3.0-1037.39",
            "binary_name": "linux-raspi2-5.3-headers-5.3.0-1037"
        },
        {
            "binary_version": "5.3.0-1037.39",
            "binary_name": "linux-raspi2-5.3-tools-5.3.0-1037"
        },
        {
            "binary_version": "5.3.0-1037.39",
            "binary_name": "linux-tools-5.3.0-1037-raspi2"
        }
    ]
}