USN-5500-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-5500-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5500-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-5500-1
Related
Published
2022-07-01T18:44:02.198302Z
Modified
2022-07-01T18:44:02.198302Z
Summary
linux, linux-aws vulnerabilities
Details

Eric Biederman discovered that the cgroup process migration implementation in the Linux kernel did not perform permission checks correctly in some situations. A local attacker could possibly use this to gain administrative privileges. (CVE-2021-4197)

Lin Ma discovered that the NFC Controller Interface (NCI) implementation in the Linux kernel contained a race condition, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-4202)

It was discovered that the PF_KEYv2 implementation in the Linux kernel did not properly initialize kernel memory in some situations. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2022-1353)

It was discovered that the virtual graphics memory manager implementation in the Linux kernel was subject to a race condition, potentially leading to an information leak. (CVE-2022-1419)

Minh Yuan discovered that the floppy disk driver in the Linux kernel contained a race condition, leading to a use-after-free vulnerability. A local attacker could possibly use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-1652)

It was discovered that the Atheros ath9k wireless device driver in the Linux kernel did not properly handle some error conditions, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-1679)

It was discovered that the Marvell NFC device driver implementation in the Linux kernel did not properly perform memory cleanup operations in some situations, leading to a use-after-free vulnerability. A local attacker could possibly use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-1734)

赵子轩 discovered that the 802.2 LLC type 2 driver in the Linux kernel did not properly perform reference counting in some error conditions. A local attacker could use this to cause a denial of service. (CVE-2022-28356)

References

Affected packages

Ubuntu:Pro:16.04:LTS / linux

Package

Name
linux
Purl
pkg:deb/ubuntu/linux@4.4.0-229.263?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.0-229.263

Affected versions

4.*

4.2.0-16.19
4.2.0-17.21
4.2.0-19.23
4.3.0-1.10
4.3.0-2.11
4.3.0-5.16
4.3.0-6.17
4.3.0-7.18
4.4.0-2.16
4.4.0-4.19
4.4.0-6.21
4.4.0-7.22
4.4.0-8.23
4.4.0-9.24
4.4.0-10.25
4.4.0-11.26
4.4.0-12.28
4.4.0-13.29
4.4.0-14.30
4.4.0-15.31
4.4.0-16.32
4.4.0-17.33
4.4.0-18.34
4.4.0-21.37
4.4.0-22.39
4.4.0-22.40
4.4.0-24.43
4.4.0-28.47
4.4.0-31.50
4.4.0-34.53
4.4.0-36.55
4.4.0-38.57
4.4.0-42.62
4.4.0-43.63
4.4.0-45.66
4.4.0-47.68
4.4.0-51.72
4.4.0-53.74
4.4.0-57.78
4.4.0-59.80
4.4.0-62.83
4.4.0-63.84
4.4.0-64.85
4.4.0-65.86
4.4.0-66.87
4.4.0-67.88
4.4.0-70.91
4.4.0-71.92
4.4.0-72.93
4.4.0-75.96
4.4.0-77.98
4.4.0-78.99
4.4.0-79.100
4.4.0-81.104
4.4.0-83.106
4.4.0-87.110
4.4.0-89.112
4.4.0-91.114
4.4.0-92.115
4.4.0-93.116
4.4.0-96.119
4.4.0-97.120
4.4.0-98.121
4.4.0-101.124
4.4.0-103.126
4.4.0-104.127
4.4.0-108.131
4.4.0-109.132
4.4.0-112.135
4.4.0-116.140
4.4.0-119.143
4.4.0-121.145
4.4.0-122.146
4.4.0-124.148
4.4.0-127.153
4.4.0-128.154
4.4.0-130.156
4.4.0-131.157
4.4.0-133.159
4.4.0-134.160
4.4.0-135.161
4.4.0-137.163
4.4.0-138.164
4.4.0-139.165
4.4.0-140.166
4.4.0-141.167
4.4.0-142.168
4.4.0-143.169
4.4.0-145.171
4.4.0-146.172
4.4.0-148.174
4.4.0-150.176
4.4.0-151.178
4.4.0-154.181
4.4.0-157.185
4.4.0-159.187
4.4.0-161.189
4.4.0-164.192
4.4.0-165.193
4.4.0-166.195
4.4.0-168.197
4.4.0-169.198
4.4.0-170.199
4.4.0-171.200
4.4.0-173.203
4.4.0-174.204
4.4.0-176.206
4.4.0-177.207
4.4.0-178.208
4.4.0-179.209
4.4.0-184.214
4.4.0-185.215
4.4.0-186.216
4.4.0-187.217
4.4.0-189.219
4.4.0-190.220
4.4.0-193.224
4.4.0-194.226
4.4.0-197.229
4.4.0-198.230
4.4.0-200.232
4.4.0-201.233
4.4.0-203.235
4.4.0-204.236
4.4.0-206.238
4.4.0-208.240
4.4.0-209.241
4.4.0-210.242
4.4.0-211.243
4.4.0-212.244
4.4.0-213.245
4.4.0-214.246
4.4.0-216.249
4.4.0-217.250
4.4.0-218.251
4.4.0-219.252
4.4.0-221.254
4.4.0-222.255
4.4.0-223.256
4.4.0-224.257
4.4.0-227.261

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "speakup-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "serial-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "sata-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "linux-source-4.4.0": "4.4.0-229.263",
            "linux-image-4.4.0-229-generic": "4.4.0-229.263",
            "message-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "crypto-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "linux-udebs-generic": "4.4.0-229.263",
            "pcmcia-storage-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "linux-cloud-tools-4.4.0-229-generic": "4.4.0-229.263",
            "linux-modules-4.4.0-229-lowlatency": "4.4.0-229.263",
            "linux-tools-4.4.0-229-generic": "4.4.0-229.263",
            "virtio-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "linux-buildinfo-4.4.0-229-generic": "4.4.0-229.263",
            "linux-tools-4.4.0-229-lowlatency": "4.4.0-229.263",
            "linux-buildinfo-4.4.0-229-lowlatency": "4.4.0-229.263",
            "vlan-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "mouse-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "linux-modules-extra-4.4.0-229-generic": "4.4.0-229.263",
            "block-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "dasd-extra-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "ipmi-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "linux-modules-4.4.0-229-generic": "4.4.0-229.263",
            "md-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "kernel-image-4.4.0-229-generic-di": "4.4.0-229.263",
            "multipath-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "scsi-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "dasd-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "linux-headers-4.4.0-229-lowlatency": "4.4.0-229.263",
            "input-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "linux-headers-4.4.0-229": "4.4.0-229.263",
            "pcmcia-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "linux-cloud-tools-common": "4.4.0-229.263",
            "linux-image-4.4.0-229-generic-dbgsym": "4.4.0-229.263",
            "fat-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "linux-libc-dev": "4.4.0-229.263",
            "nic-pcmcia-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "linux-image-unsigned-4.4.0-229-lowlatency-dbgsym": "4.4.0-229.263",
            "usb-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "linux-doc": "4.4.0-229.263",
            "pata-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "nfs-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "floppy-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "plip-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "linux-image-unsigned-4.4.0-229-generic-dbgsym": "4.4.0-229.263",
            "ppp-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "linux-cloud-tools-4.4.0-229": "4.4.0-229.263",
            "nic-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "fs-secondary-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "linux-tools-4.4.0-229": "4.4.0-229.263",
            "linux-tools-host": "4.4.0-229.263",
            "parport-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "linux-image-unsigned-4.4.0-229-generic": "4.4.0-229.263",
            "linux-image-unsigned-4.4.0-229-lowlatency": "4.4.0-229.263",
            "nic-usb-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "irda-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "fb-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "fs-core-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "firewire-core-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "linux-tools-common": "4.4.0-229.263",
            "linux-headers-4.4.0-229-generic": "4.4.0-229.263",
            "storage-core-modules-4.4.0-229-generic-di": "4.4.0-229.263",
            "linux-cloud-tools-4.4.0-229-lowlatency": "4.4.0-229.263",
            "nic-shared-modules-4.4.0-229-generic-di": "4.4.0-229.263"
        }
    ]
}

Ubuntu:Pro:16.04:LTS / linux-aws

Package

Name
linux-aws
Purl
pkg:deb/ubuntu/linux-aws@4.4.0-1145.160?arch=src?distro=esm-infra/xenial

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.0-1145.160

Affected versions

4.*

4.4.0-1001.10
4.4.0-1003.12
4.4.0-1004.13
4.4.0-1007.16
4.4.0-1009.18
4.4.0-1011.20
4.4.0-1012.21
4.4.0-1013.22
4.4.0-1016.25
4.4.0-1017.26
4.4.0-1018.27
4.4.0-1020.29
4.4.0-1022.31
4.4.0-1026.35
4.4.0-1028.37
4.4.0-1030.39
4.4.0-1031.40
4.4.0-1032.41
4.4.0-1035.44
4.4.0-1037.46
4.4.0-1038.47
4.4.0-1039.48
4.4.0-1041.50
4.4.0-1043.52
4.4.0-1044.53
4.4.0-1047.56
4.4.0-1048.57
4.4.0-1049.58
4.4.0-1050.59
4.4.0-1052.61
4.4.0-1054.63
4.4.0-1055.64
4.4.0-1057.66
4.4.0-1060.69
4.4.0-1061.70
4.4.0-1062.71
4.4.0-1063.72
4.4.0-1065.75
4.4.0-1066.76
4.4.0-1067.77
4.4.0-1069.79
4.4.0-1070.80
4.4.0-1072.82
4.4.0-1073.83
4.4.0-1074.84
4.4.0-1075.85
4.4.0-1077.87
4.4.0-1079.89
4.4.0-1081.91
4.4.0-1083.93
4.4.0-1084.94
4.4.0-1085.96
4.4.0-1087.98
4.4.0-1088.99
4.4.0-1090.101
4.4.0-1092.103
4.4.0-1094.105
4.4.0-1095.106
4.4.0-1096.107
4.4.0-1098.109
4.4.0-1099.110
4.4.0-1100.111
4.4.0-1101.112
4.4.0-1102.113
4.4.0-1104.115
4.4.0-1105.116
4.4.0-1106.117
4.4.0-1107.118
4.4.0-1109.120
4.4.0-1110.121
4.4.0-1111.123
4.4.0-1112.124
4.4.0-1113.126
4.4.0-1114.127
4.4.0-1117.131
4.4.0-1118.132
4.4.0-1119.133
4.4.0-1121.135
4.4.0-1122.136
4.4.0-1123.137
4.4.0-1124.138
4.4.0-1126.140
4.4.0-1127.141
4.4.0-1128.142
4.4.0-1129.143
4.4.0-1130.144
4.4.0-1131.145
4.4.0-1132.146
4.4.0-1133.147
4.4.0-1134.148
4.4.0-1135.149
4.4.0-1137.151
4.4.0-1138.152
4.4.0-1139.153
4.4.0-1140.154
4.4.0-1143.158

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro",
    "binaries": [
        {
            "linux-aws-headers-4.4.0-1145": "4.4.0-1145.160",
            "linux-aws-cloud-tools-4.4.0-1145": "4.4.0-1145.160",
            "linux-image-4.4.0-1145-aws": "4.4.0-1145.160",
            "linux-modules-extra-4.4.0-1145-aws": "4.4.0-1145.160",
            "linux-tools-4.4.0-1145-aws": "4.4.0-1145.160",
            "linux-headers-4.4.0-1145-aws": "4.4.0-1145.160",
            "linux-modules-4.4.0-1145-aws": "4.4.0-1145.160",
            "linux-buildinfo-4.4.0-1145-aws": "4.4.0-1145.160",
            "linux-image-4.4.0-1145-aws-dbgsym": "4.4.0-1145.160",
            "linux-cloud-tools-4.4.0-1145-aws": "4.4.0-1145.160",
            "linux-aws-tools-4.4.0-1145": "4.4.0-1145.160"
        }
    ]
}