USN-5002-1

Source
https://ubuntu.com/security/notices/USN-5002-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5002-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-5002-1
Related
Published
2021-06-23T04:12:41.292374Z
Modified
2021-06-23T04:12:41.292374Z
Summary
linux-hwe, linux-gke-5.3, linux-raspi2-5.3 vulnerability
Details

Norbert Slusarek discovered a race condition in the CAN BCM networking protocol of the Linux kernel leading to multiple use-after-free vulnerabilities. A local attacker could use this issue to execute arbitrary code.

References

Affected packages

Ubuntu:18.04:LTS / linux-gke-5.3

Package

Name
linux-gke-5.3
Purl
pkg:deb/ubuntu/linux-gke-5.3?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.3.0-1044.47

Affected versions

5.*

5.3.0-1011.12~18.04.1
5.3.0-1012.13~18.04.1
5.3.0-1014.15~18.04.1
5.3.0-1016.17~18.04.1
5.3.0-1017.18~18.04.1
5.3.0-1018.19~18.04.1
5.3.0-1020.22~18.04.1
5.3.0-1026.28~18.04.1
5.3.0-1030.32~18.04.1
5.3.0-1032.34~18.04.1
5.3.0-1033.35
5.3.0-1034.36
5.3.0-1036.38
5.3.0-1038.40
5.3.0-1039.42
5.3.0-1040.43
5.3.0-1041.44
5.3.0-1042.45
5.3.0-1043.46

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "5.3.0-1044.47",
            "binary_name": "linux-buildinfo-5.3.0-1044-gke"
        },
        {
            "binary_version": "5.3.0-1044.47",
            "binary_name": "linux-gke-5.3-headers-5.3.0-1044"
        },
        {
            "binary_version": "5.3.0-1044.47",
            "binary_name": "linux-gke-5.3-tools-5.3.0-1044"
        },
        {
            "binary_version": "5.3.0-1044.47",
            "binary_name": "linux-headers-5.3.0-1044-gke"
        },
        {
            "binary_version": "5.3.0-1044.47",
            "binary_name": "linux-image-unsigned-5.3.0-1044-gke"
        },
        {
            "binary_version": "5.3.0-1044.47",
            "binary_name": "linux-image-unsigned-5.3.0-1044-gke-dbgsym"
        },
        {
            "binary_version": "5.3.0-1044.47",
            "binary_name": "linux-modules-5.3.0-1044-gke"
        },
        {
            "binary_version": "5.3.0-1044.47",
            "binary_name": "linux-modules-extra-5.3.0-1044-gke"
        },
        {
            "binary_version": "5.3.0-1044.47",
            "binary_name": "linux-tools-5.3.0-1044-gke"
        }
    ]
}

Ubuntu:18.04:LTS / linux-hwe

Package

Name
linux-hwe
Purl
pkg:deb/ubuntu/linux-hwe?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.3.0-75.71

Affected versions

4.*

4.18.0-13.14~18.04.1
4.18.0-14.15~18.04.1
4.18.0-15.16~18.04.1
4.18.0-16.17~18.04.1
4.18.0-17.18~18.04.1
4.18.0-18.19~18.04.1
4.18.0-20.21~18.04.1
4.18.0-21.22~18.04.1
4.18.0-22.23~18.04.1
4.18.0-24.25~18.04.1
4.18.0-25.26~18.04.1

5.*

5.0.0-23.24~18.04.1
5.0.0-25.26~18.04.1
5.0.0-27.28~18.04.1
5.0.0-29.31~18.04.1
5.0.0-31.33~18.04.1
5.0.0-32.34~18.04.2
5.0.0-35.38~18.04.1
5.0.0-36.39~18.04.1
5.0.0-37.40~18.04.1
5.3.0-26.28~18.04.1
5.3.0-28.30~18.04.1
5.3.0-40.32~18.04.1
5.3.0-42.34~18.04.1
5.3.0-45.37~18.04.1
5.3.0-46.38~18.04.1
5.3.0-51.44~18.04.2
5.3.0-53.47~18.04.1
5.3.0-59.53~18.04.1
5.3.0-61.55~18.04.1
5.3.0-62.56~18.04.1
5.3.0-64.58~18.04.1
5.3.0-65.59
5.3.0-66.60
5.3.0-67.61
5.3.0-68.63
5.3.0-69.65
5.3.0-70.66
5.3.0-72.68
5.3.0-73.69
5.3.0-74.70

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "block-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "crypto-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "fat-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "fb-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "firewire-core-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "floppy-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "fs-core-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "fs-secondary-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "input-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "ipmi-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "kernel-image-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-buildinfo-5.3.0-75-generic"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-buildinfo-5.3.0-75-lowlatency"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-cloud-tools-5.3.0-75-generic"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-cloud-tools-5.3.0-75-lowlatency"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-headers-5.3.0-75-generic"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-headers-5.3.0-75-lowlatency"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-hwe-cloud-tools-5.3.0-75"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-hwe-headers-5.3.0-75"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-hwe-tools-5.3.0-75"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-hwe-udebs-generic"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-image-5.3.0-75-generic"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-image-5.3.0-75-generic-dbgsym"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-image-5.3.0-75-lowlatency"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-image-5.3.0-75-lowlatency-dbgsym"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-image-unsigned-5.3.0-75-generic"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-image-unsigned-5.3.0-75-generic-dbgsym"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-image-unsigned-5.3.0-75-lowlatency"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-image-unsigned-5.3.0-75-lowlatency-dbgsym"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-modules-5.3.0-75-generic"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-modules-5.3.0-75-lowlatency"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-modules-extra-5.3.0-75-generic"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-source-5.3.0"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-tools-5.3.0-75-generic"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "linux-tools-5.3.0-75-lowlatency"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "md-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "message-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "mouse-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "multipath-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "nfs-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "nic-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "nic-pcmcia-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "nic-shared-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "nic-usb-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "parport-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "pata-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "pcmcia-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "pcmcia-storage-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "plip-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "ppp-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "sata-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "scsi-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "serial-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "storage-core-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "usb-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "virtio-modules-5.3.0-75-generic-di"
        },
        {
            "binary_version": "5.3.0-75.71",
            "binary_name": "vlan-modules-5.3.0-75-generic-di"
        }
    ]
}

Ubuntu:18.04:LTS / linux-raspi2-5.3

Package

Name
linux-raspi2-5.3
Purl
pkg:deb/ubuntu/linux-raspi2-5.3?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.3.0-1041.43

Affected versions

5.*

5.3.0-1017.19~18.04.1
5.3.0-1018.20~18.04.1
5.3.0-1019.21~18.04.1
5.3.0-1021.23~18.04.1
5.3.0-1022.24~18.04.1
5.3.0-1023.25~18.04.1
5.3.0-1026.28~18.04.1
5.3.0-1027.29~18.04.1
5.3.0-1028.30~18.04.2
5.3.0-1030.32~18.04.2
5.3.0-1032.34
5.3.0-1033.35
5.3.0-1035.37
5.3.0-1036.38
5.3.0-1037.39
5.3.0-1038.40
5.3.0-1039.41
5.3.0-1040.42

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "5.3.0-1041.43",
            "binary_name": "linux-buildinfo-5.3.0-1041-raspi2"
        },
        {
            "binary_version": "5.3.0-1041.43",
            "binary_name": "linux-headers-5.3.0-1041-raspi2"
        },
        {
            "binary_version": "5.3.0-1041.43",
            "binary_name": "linux-image-5.3.0-1041-raspi2"
        },
        {
            "binary_version": "5.3.0-1041.43",
            "binary_name": "linux-image-5.3.0-1041-raspi2-dbgsym"
        },
        {
            "binary_version": "5.3.0-1041.43",
            "binary_name": "linux-modules-5.3.0-1041-raspi2"
        },
        {
            "binary_version": "5.3.0-1041.43",
            "binary_name": "linux-raspi2-5.3-headers-5.3.0-1041"
        },
        {
            "binary_version": "5.3.0-1041.43",
            "binary_name": "linux-raspi2-5.3-tools-5.3.0-1041"
        },
        {
            "binary_version": "5.3.0-1041.43",
            "binary_name": "linux-tools-5.3.0-1041-raspi2"
        }
    ]
}