USN-4912-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-4912-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4912-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-4912-1
Related
  • CVE-2020-0423
  • CVE-2020-0465
  • CVE-2020-0466
  • CVE-2020-14351
  • CVE-2020-14390
  • CVE-2020-25285
  • CVE-2020-25645
  • CVE-2020-25669
  • CVE-2020-27830
  • CVE-2020-36158
  • CVE-2021-20194
  • CVE-2021-29154
  • CVE-2021-3178
  • CVE-2021-3411
Published
2021-04-13T21:35:44.987489Z
Modified
2021-04-13T21:35:44.987489Z
Summary
linux-oem-5.6 vulnerabilities
Details

Piotr Krysiuk discovered that the BPF JIT compiler for x86 in the Linux kernel did not properly validate computation of branch displacements in some situations. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-29154)

It was discovered that a race condition existed in the binder IPC implementation in the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-0423)

It was discovered that the HID multitouch implementation within the Linux kernel did not properly validate input events in some situations. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-0465)

It was discovered that the eventpoll (aka epoll) implementation in the Linux kernel contained a logic error that could lead to a use after free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-0466)

It was discovered that a race condition existed in the perf subsystem of the Linux kernel, leading to a use-after-free vulnerability. An attacker with access to the perf subsystem could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-14351)

It was discovered that the frame buffer implementation in the Linux kernel did not properly handle some edge cases in software scrollback. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-14390)

It was discovered that a race condition existed in the hugetlb sysctl implementation in the Linux kernel. A privileged attacker could use this to cause a denial of service (system crash). (CVE-2020-25285)

It was discovered that the GENEVE tunnel implementation in the Linux kernel when combined with IPSec did not properly select IP routes in some situations. An attacker could use this to expose sensitive information (unencrypted network traffic). (CVE-2020-25645)

Bodong Zhao discovered a use-after-free in the Sun keyboard driver implementation in the Linux kernel. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2020-25669)

Shisong Qin and Bodong Zhao discovered that Speakup screen reader driver in the Linux kernel did not correctly handle setting line discipline in some situations. A local attacker could use this to cause a denial of service (system crash). (CVE-2020-27830)

It was discovered that the Marvell WiFi-Ex device driver in the Linux kernel did not properly validate ad-hoc SSIDs. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-36158)

Loris Reiff discovered that the BPF implementation in the Linux kernel did not properly validate attributes in the getsockopt BPF hook. A local attacker could possibly use this to cause a denial of service (system crash). (CVE-2021-20194)

Adam Zabrocki discovered that the kprobes subsystem in the Linux kernel did not properly detect linker padding in some situations. A privileged attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information. (CVE-2021-3411)

吴异 discovered that the NFS implementation in the Linux kernel did not properly prevent access outside of an NFS export that is a subdirectory of a file system. An attacker could possibly use this to bypass NFS access restrictions. (CVE-2021-3178)

References

Affected packages

Ubuntu:20.04:LTS / linux-oem-5.6

Package

Name
linux-oem-5.6
Purl
pkg:deb/ubuntu/linux-oem-5.6@5.6.0-1053.57?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.6.0-1053.57

Affected versions

5.*

5.6.0-1007.7
5.6.0-1008.8
5.6.0-1010.10
5.6.0-1011.11
5.6.0-1013.13
5.6.0-1017.17
5.6.0-1018.18
5.6.0-1020.20
5.6.0-1021.21
5.6.0-1023.23
5.6.0-1026.26
5.6.0-1027.27
5.6.0-1028.28
5.6.0-1031.32
5.6.0-1032.33
5.6.0-1033.35
5.6.0-1034.36
5.6.0-1035.37
5.6.0-1036.39
5.6.0-1039.43
5.6.0-1042.46
5.6.0-1047.51
5.6.0-1048.52
5.6.0-1050.54
5.6.0-1052.56

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-oem-5.6-headers-5.6.0-1053": "5.6.0-1053.57",
            "linux-tools-5.6.0-1053-oem": "5.6.0-1053.57",
            "linux-buildinfo-5.6.0-1053-oem": "5.6.0-1053.57",
            "linux-headers-5.6.0-1053-oem": "5.6.0-1053.57",
            "linux-image-unsigned-5.6.0-1053-oem": "5.6.0-1053.57",
            "linux-oem-5.6-tools-host": "5.6.0-1053.57",
            "linux-modules-5.6.0-1053-oem": "5.6.0-1053.57",
            "linux-image-unsigned-5.6.0-1053-oem-dbgsym": "5.6.0-1053.57",
            "linux-oem-5.6-tools-5.6.0-1053": "5.6.0-1053.57"
        }
    ]
}