USN-5518-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-5518-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5518-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-5518-1
Related
Published
2022-07-14T01:05:45Z
Modified
2022-07-14T01:05:45Z
Summary
linux, linux-aws, linux-azure, linux-gcp, linux-gke, linux-ibm, linux-kvm, linux-lowlatency, linux-oracle, linux-raspi vulnerabilities
Details

It was discovered that the eBPF implementation in the Linux kernel did not properly prevent writes to kernel objects in BPFBTFLOAD commands. A privileged local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-0500)

It was discovered that the Marvell NFC device driver implementation in the Linux kernel did not properly perform memory cleanup operations in some situations, leading to a use-after-free vulnerability. A local attacker could possibly use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-1734)

Yongkang Jia discovered that the KVM hypervisor implementation in the Linux kernel did not properly handle guest TLB mapping invalidation requests in some situations. An attacker in a guest VM could use this to cause a denial of service (system crash) in the host OS. (CVE-2022-1789)

Duoming Zhou discovered a race condition in the NFC subsystem in the Linux kernel, leading to a use-after-free vulnerability. A privileged local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-1974)

Duoming Zhou discovered that the NFC subsystem in the Linux kernel did not properly prevent context switches from occurring during certain atomic context operations. A privileged local attacker could use this to cause a denial of service (system crash). (CVE-2022-1975)

Minh Yuan discovered that the floppy driver in the Linux kernel contained a race condition in some situations, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-33981)

References

Affected packages

Ubuntu:22.04:LTS / linux

Package

Name
linux
Purl
pkg:deb/ubuntu/linux@5.15.0-41.44?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.0-41.44

Affected versions

5.*

5.13.0-19.19
5.15.0-17.17
5.15.0-18.18
5.15.0-22.22
5.15.0-23.23
5.15.0-25.25
5.15.0-27.28
5.15.0-30.31
5.15.0-33.34
5.15.0-35.36
5.15.0-37.39
5.15.0-39.42
5.15.0-40.43

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-headers-5.15.0-41-generic-lpae": "5.15.0-41.44",
            "linux-modules-5.15.0-41-generic-64k": "5.15.0-41.44",
            "linux-headers-5.15.0-41-generic-64k": "5.15.0-41.44",
            "linux-cloud-tools-common": "5.15.0-41.44",
            "linux-modules-iwlwifi-5.15.0-41-generic": "5.15.0-41.44",
            "linux-modules-5.15.0-41-generic-lpae": "5.15.0-41.44",
            "linux-libc-dev": "5.15.0-41.44",
            "linux-image-unsigned-5.15.0-41-generic-64k-dbgsym": "5.15.0-41.44",
            "linux-doc": "5.15.0-41.44",
            "linux-tools-5.15.0-41": "5.15.0-41.44",
            "linux-image-5.15.0-41-generic": "5.15.0-41.44",
            "linux-source-5.15.0": "5.15.0-41.44",
            "linux-tools-5.15.0-41-generic-lpae": "5.15.0-41.44",
            "linux-cloud-tools-5.15.0-41": "5.15.0-41.44",
            "linux-headers-5.15.0-41": "5.15.0-41.44",
            "linux-tools-5.15.0-41-generic": "5.15.0-41.44",
            "linux-image-unsigned-5.15.0-41-generic-dbgsym": "5.15.0-41.44",
            "linux-buildinfo-5.15.0-41-generic-64k": "5.15.0-41.44",
            "linux-tools-host": "5.15.0-41.44",
            "linux-tools-5.15.0-41-generic-64k": "5.15.0-41.44",
            "linux-image-unsigned-5.15.0-41-generic": "5.15.0-41.44",
            "linux-image-5.15.0-41-generic-lpae": "5.15.0-41.44",
            "linux-buildinfo-5.15.0-41-generic-lpae": "5.15.0-41.44",
            "linux-modules-5.15.0-41-generic": "5.15.0-41.44",
            "linux-modules-extra-5.15.0-41-generic": "5.15.0-41.44",
            "linux-headers-5.15.0-41-generic": "5.15.0-41.44",
            "linux-image-5.15.0-41-generic-dbgsym": "5.15.0-41.44",
            "linux-image-5.15.0-41-generic-lpae-dbgsym": "5.15.0-41.44",
            "linux-image-unsigned-5.15.0-41-generic-64k": "5.15.0-41.44",
            "linux-tools-common": "5.15.0-41.44",
            "linux-buildinfo-5.15.0-41-generic": "5.15.0-41.44",
            "linux-cloud-tools-5.15.0-41-generic": "5.15.0-41.44"
        }
    ]
}

Ubuntu:22.04:LTS / linux-aws

Package

Name
linux-aws
Purl
pkg:deb/ubuntu/linux-aws@5.15.0-1015.19?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.0-1015.19

Affected versions

5.*

5.13.0-1005.6
5.15.0-1002.4
5.15.0-1003.5
5.15.0-1004.6
5.15.0-1005.7
5.15.0-1008.10
5.15.0-1009.11
5.15.0-1011.14
5.15.0-1013.17
5.15.0-1014.18

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-cloud-tools-5.15.0-1015-aws": "5.15.0-1015.19",
            "linux-buildinfo-5.15.0-1015-aws": "5.15.0-1015.19",
            "linux-image-unsigned-5.15.0-1015-aws-dbgsym": "5.15.0-1015.19",
            "linux-modules-5.15.0-1015-aws": "5.15.0-1015.19",
            "linux-aws-cloud-tools-5.15.0-1015": "5.15.0-1015.19",
            "linux-aws-headers-5.15.0-1015": "5.15.0-1015.19",
            "linux-headers-5.15.0-1015-aws": "5.15.0-1015.19",
            "linux-tools-5.15.0-1015-aws": "5.15.0-1015.19",
            "linux-modules-extra-5.15.0-1015-aws": "5.15.0-1015.19",
            "linux-aws-tools-5.15.0-1015": "5.15.0-1015.19",
            "linux-image-unsigned-5.15.0-1015-aws": "5.15.0-1015.19"
        }
    ]
}

Ubuntu:22.04:LTS / linux-azure

Package

Name
linux-azure
Purl
pkg:deb/ubuntu/linux-azure@5.15.0-1014.17?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.0-1014.17

Affected versions

5.*

5.13.0-1006.7
5.15.0-1001.2
5.15.0-1002.3
5.15.0-1003.4
5.15.0-1005.6
5.15.0-1007.8
5.15.0-1008.9
5.15.0-1010.12
5.15.0-1012.15
5.15.0-1013.16

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-azure-cloud-tools-5.15.0-1014": "5.15.0-1014.17",
            "linux-headers-5.15.0-1014-azure": "5.15.0-1014.17",
            "linux-azure-headers-5.15.0-1014": "5.15.0-1014.17",
            "linux-modules-5.15.0-1014-azure": "5.15.0-1014.17",
            "linux-image-unsigned-5.15.0-1014-azure-dbgsym": "5.15.0-1014.17",
            "linux-azure-tools-5.15.0-1014": "5.15.0-1014.17",
            "linux-image-unsigned-5.15.0-1014-azure": "5.15.0-1014.17",
            "linux-buildinfo-5.15.0-1014-azure": "5.15.0-1014.17",
            "linux-cloud-tools-5.15.0-1014-azure": "5.15.0-1014.17",
            "linux-modules-extra-5.15.0-1014-azure": "5.15.0-1014.17",
            "linux-tools-5.15.0-1014-azure": "5.15.0-1014.17"
        }
    ]
}

Ubuntu:22.04:LTS / linux-gcp

Package

Name
linux-gcp
Purl
pkg:deb/ubuntu/linux-gcp@5.15.0-1013.18?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.0-1013.18

Affected versions

5.*

5.13.0-1005.6
5.15.0-1001.3
5.15.0-1002.5
5.15.0-1003.6
5.15.0-1004.7
5.15.0-1005.8
5.15.0-1006.9
5.15.0-1008.12
5.15.0-1010.15

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-image-unsigned-5.15.0-1013-gcp-dbgsym": "5.15.0-1013.18",
            "linux-image-unsigned-5.15.0-1013-gcp": "5.15.0-1013.18",
            "linux-modules-extra-5.15.0-1013-gcp": "5.15.0-1013.18",
            "linux-tools-5.15.0-1013-gcp": "5.15.0-1013.18",
            "linux-gcp-tools-5.15.0-1013": "5.15.0-1013.18",
            "linux-headers-5.15.0-1013-gcp": "5.15.0-1013.18",
            "linux-modules-iwlwifi-5.15.0-1013-gcp": "5.15.0-1013.18",
            "linux-buildinfo-5.15.0-1013-gcp": "5.15.0-1013.18",
            "linux-modules-5.15.0-1013-gcp": "5.15.0-1013.18",
            "linux-gcp-headers-5.15.0-1013": "5.15.0-1013.18"
        }
    ]
}

Ubuntu:22.04:LTS / linux-gke

Package

Name
linux-gke
Purl
pkg:deb/ubuntu/linux-gke@5.15.0-1011.14?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.0-1011.14

Affected versions

5.*

5.15.0-1002.2
5.15.0-1003.3
5.15.0-1004.5
5.15.0-1005.6
5.15.0-1006.7
5.15.0-1008.10
5.15.0-1010.13

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-image-unsigned-5.15.0-1011-gke": "5.15.0-1011.14",
            "linux-gke-tools-5.15.0-1011": "5.15.0-1011.14",
            "linux-modules-5.15.0-1011-gke": "5.15.0-1011.14",
            "linux-modules-iwlwifi-5.15.0-1011-gke": "5.15.0-1011.14",
            "linux-image-unsigned-5.15.0-1011-gke-dbgsym": "5.15.0-1011.14",
            "linux-headers-5.15.0-1011-gke": "5.15.0-1011.14",
            "linux-modules-extra-5.15.0-1011-gke": "5.15.0-1011.14",
            "linux-buildinfo-5.15.0-1011-gke": "5.15.0-1011.14",
            "linux-tools-5.15.0-1011-gke": "5.15.0-1011.14",
            "linux-gke-headers-5.15.0-1011": "5.15.0-1011.14"
        }
    ]
}

Ubuntu:22.04:LTS / linux-ibm

Package

Name
linux-ibm
Purl
pkg:deb/ubuntu/linux-ibm@5.15.0-1010.12?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.0-1010.12

Affected versions

5.*

5.15.0-1002.2
5.15.0-1003.3
5.15.0-1004.4
5.15.0-1005.5
5.15.0-1007.8
5.15.0-1009.11

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-tools-5.15.0-1010-ibm": "5.15.0-1010.12",
            "linux-ibm-tools-common": "5.15.0-1010.12",
            "linux-buildinfo-5.15.0-1010-ibm": "5.15.0-1010.12",
            "linux-ibm-source-5.15.0": "5.15.0-1010.12",
            "linux-image-unsigned-5.15.0-1010-ibm-dbgsym": "5.15.0-1010.12",
            "linux-image-unsigned-5.15.0-1010-ibm": "5.15.0-1010.12",
            "linux-modules-5.15.0-1010-ibm": "5.15.0-1010.12",
            "linux-ibm-headers-5.15.0-1010": "5.15.0-1010.12",
            "linux-modules-iwlwifi-5.15.0-1010-ibm": "5.15.0-1010.12",
            "linux-headers-5.15.0-1010-ibm": "5.15.0-1010.12",
            "linux-ibm-tools-5.15.0-1010": "5.15.0-1010.12",
            "linux-modules-extra-5.15.0-1010-ibm": "5.15.0-1010.12",
            "linux-ibm-cloud-tools-common": "5.15.0-1010.12"
        }
    ]
}

Ubuntu:22.04:LTS / linux-kvm

Package

Name
linux-kvm
Purl
pkg:deb/ubuntu/linux-kvm@5.15.0-1013.16?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.0-1013.16

Affected versions

5.*

5.13.0-1004.4
5.13.0-1006.6+22.04.1
5.13.0-1007.7+22.04.1
5.13.0-1010.11+22.04.1
5.15.0-1002.2
5.15.0-1004.4
5.15.0-1005.5
5.15.0-1007.7
5.15.0-1008.8
5.15.0-1010.11
5.15.0-1012.14

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-kvm-tools-5.15.0-1013": "5.15.0-1013.16",
            "linux-modules-5.15.0-1013-kvm": "5.15.0-1013.16",
            "linux-tools-5.15.0-1013-kvm": "5.15.0-1013.16",
            "linux-buildinfo-5.15.0-1013-kvm": "5.15.0-1013.16",
            "linux-image-unsigned-5.15.0-1013-kvm": "5.15.0-1013.16",
            "linux-image-unsigned-5.15.0-1013-kvm-dbgsym": "5.15.0-1013.16",
            "linux-headers-5.15.0-1013-kvm": "5.15.0-1013.16",
            "linux-kvm-headers-5.15.0-1013": "5.15.0-1013.16"
        }
    ]
}

Ubuntu:22.04:LTS / linux-lowlatency

Package

Name
linux-lowlatency
Purl
pkg:deb/ubuntu/linux-lowlatency@5.15.0-41.44?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.0-41.44

Affected versions

5.*

5.15.0-22.22
5.15.0-23.23
5.15.0-24.24
5.15.0-27.28
5.15.0-30.31
5.15.0-33.34
5.15.0-35.36
5.15.0-37.39
5.15.0-39.42
5.15.0-40.43

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-lowlatency-tools-5.15.0-41": "5.15.0-41.44",
            "linux-lowlatency-tools-common": "5.15.0-41.44",
            "linux-headers-5.15.0-41-lowlatency": "5.15.0-41.44",
            "linux-image-unsigned-5.15.0-41-lowlatency-dbgsym": "5.15.0-41.44",
            "linux-lowlatency-headers-5.15.0-41": "5.15.0-41.44",
            "linux-cloud-tools-5.15.0-41-lowlatency": "5.15.0-41.44",
            "linux-lowlatency-tools-host": "5.15.0-41.44",
            "linux-lowlatency-cloud-tools-5.15.0-41": "5.15.0-41.44",
            "linux-lowlatency-cloud-tools-common": "5.15.0-41.44",
            "linux-buildinfo-5.15.0-41-lowlatency": "5.15.0-41.44",
            "linux-headers-5.15.0-41-lowlatency-64k": "5.15.0-41.44",
            "linux-image-unsigned-5.15.0-41-lowlatency-64k": "5.15.0-41.44",
            "linux-tools-5.15.0-41-lowlatency-64k": "5.15.0-41.44",
            "linux-modules-5.15.0-41-lowlatency-64k": "5.15.0-41.44",
            "linux-modules-iwlwifi-5.15.0-41-lowlatency": "5.15.0-41.44",
            "linux-image-unsigned-5.15.0-41-lowlatency-64k-dbgsym": "5.15.0-41.44",
            "linux-modules-5.15.0-41-lowlatency": "5.15.0-41.44",
            "linux-tools-5.15.0-41-lowlatency": "5.15.0-41.44",
            "linux-buildinfo-5.15.0-41-lowlatency-64k": "5.15.0-41.44",
            "linux-image-unsigned-5.15.0-41-lowlatency": "5.15.0-41.44"
        }
    ]
}

Ubuntu:22.04:LTS / linux-oracle

Package

Name
linux-oracle
Purl
pkg:deb/ubuntu/linux-oracle@5.15.0-1013.17?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.0-1013.17

Affected versions

5.*

5.13.0-1008.10
5.15.0-1001.3
5.15.0-1002.4
5.15.0-1003.5
5.15.0-1006.8
5.15.0-1007.9
5.15.0-1009.12
5.15.0-1011.15

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-headers-5.15.0-1013-oracle": "5.15.0-1013.17",
            "linux-image-unsigned-5.15.0-1013-oracle-dbgsym": "5.15.0-1013.17",
            "linux-tools-5.15.0-1013-oracle": "5.15.0-1013.17",
            "linux-image-unsigned-5.15.0-1013-oracle": "5.15.0-1013.17",
            "linux-modules-extra-5.15.0-1013-oracle": "5.15.0-1013.17",
            "linux-oracle-tools-5.15.0-1013": "5.15.0-1013.17",
            "linux-modules-5.15.0-1013-oracle": "5.15.0-1013.17",
            "linux-oracle-headers-5.15.0-1013": "5.15.0-1013.17",
            "linux-buildinfo-5.15.0-1013-oracle": "5.15.0-1013.17"
        }
    ]
}

Ubuntu:22.04:LTS / linux-raspi

Package

Name
linux-raspi
Purl
pkg:deb/ubuntu/linux-raspi@5.15.0-1012.14?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.0-1012.14

Affected versions

5.*

5.13.0-1008.9
5.15.0-1002.2
5.15.0-1003.3
5.15.0-1004.4
5.15.0-1005.5
5.15.0-1006.6
5.15.0-1008.8
5.15.0-1011.13

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-headers-5.15.0-1012-raspi-nolpae": "5.15.0-1012.14",
            "linux-buildinfo-5.15.0-1012-raspi": "5.15.0-1012.14",
            "linux-buildinfo-5.15.0-1012-raspi-nolpae": "5.15.0-1012.14",
            "linux-raspi-headers-5.15.0-1012": "5.15.0-1012.14",
            "linux-image-5.15.0-1012-raspi-dbgsym": "5.15.0-1012.14",
            "linux-modules-5.15.0-1012-raspi": "5.15.0-1012.14",
            "linux-modules-extra-5.15.0-1012-raspi-nolpae": "5.15.0-1012.14",
            "linux-raspi-tools-5.15.0-1012": "5.15.0-1012.14",
            "linux-image-5.15.0-1012-raspi-nolpae": "5.15.0-1012.14",
            "linux-headers-5.15.0-1012-raspi": "5.15.0-1012.14",
            "linux-image-5.15.0-1012-raspi-nolpae-dbgsym": "5.15.0-1012.14",
            "linux-modules-extra-5.15.0-1012-raspi": "5.15.0-1012.14",
            "linux-image-5.15.0-1012-raspi": "5.15.0-1012.14",
            "linux-tools-5.15.0-1012-raspi-nolpae": "5.15.0-1012.14",
            "linux-tools-5.15.0-1012-raspi": "5.15.0-1012.14",
            "linux-modules-5.15.0-1012-raspi-nolpae": "5.15.0-1012.14"
        }
    ]
}