USN-5830-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-5830-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5830-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-5830-1
Related
Published
2023-01-27T18:49:52.616490Z
Modified
2023-01-27T18:49:52.616490Z
Summary
linux-azure, linux-azure-5.4, linux-raspi2 vulnerabilities
Details

It was discovered that the NFSD implementation in the Linux kernel did not properly handle some RPC messages, leading to a buffer overflow. A remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-43945)

Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation in the Linux kernel contained multiple use-after-free vulnerabilities. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-42896)

It was discovered that the Xen netback driver in the Linux kernel did not properly handle packets structured in certain ways. An attacker in a guest VM could possibly use this to cause a denial of service (host NIC availability). (CVE-2022-3643)

It was discovered that an integer overflow vulnerability existed in the Bluetooth subsystem in the Linux kernel. A physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2022-45934)

References

Affected packages

Ubuntu:18.04:LTS / linux-azure-5.4

Package

Name
linux-azure-5.4
Purl
pkg:deb/ubuntu/linux-azure-5.4@5.4.0-1101.107~18.04.1?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.0-1101.107~18.04.1

Affected versions

5.*

5.4.0-1020.20~18.04.1
5.4.0-1022.22~18.04.1
5.4.0-1023.23~18.04.1
5.4.0-1025.25~18.04.1
5.4.0-1026.26~18.04.1
5.4.0-1031.32~18.04.1
5.4.0-1032.33~18.04.1
5.4.0-1034.35~18.04.1
5.4.0-1035.36~18.04.1
5.4.0-1036.38~18.04.1
5.4.0-1039.41~18.04.1
5.4.0-1040.42~18.04.1
5.4.0-1041.43~18.04.1
5.4.0-1043.45~18.04.1
5.4.0-1044.46~18.04.1
5.4.0-1046.48~18.04.1
5.4.0-1047.49~18.04.1
5.4.0-1048.50~18.04.1
5.4.0-1049.51~18.04.1
5.4.0-1051.53~18.04.1
5.4.0-1055.57~18.04.1
5.4.0-1056.58~18.04.1
5.4.0-1058.60~18.04.1
5.4.0-1059.62~18.04.1
5.4.0-1061.64~18.04.1
5.4.0-1062.65~18.04.1
5.4.0-1063.66~18.04.1
5.4.0-1064.67~18.04.1
5.4.0-1065.68~18.04.1
5.4.0-1067.70~18.04.1
5.4.0-1068.71~18.04.1
5.4.0-1069.72~18.04.1
5.4.0-1070.73~18.04.1
5.4.0-1072.75~18.04.1
5.4.0-1073.76~18.04.1
5.4.0-1074.77~18.04.1
5.4.0-1077.80~18.04.1
5.4.0-1078.81~18.04.1
5.4.0-1080.83~18.04.2
5.4.0-1083.87~18.04.1
5.4.0-1085.90~18.04.1
5.4.0-1086.91~18.04.1
5.4.0-1089.94~18.04.1
5.4.0-1090.95~18.04.1
5.4.0-1091.96~18.04.1
5.4.0-1094.100~18.04.1
5.4.0-1095.101~18.04.1
5.4.0-1098.104~18.04.2
5.4.0-1100.106~18.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-buildinfo-5.4.0-1101-azure": "5.4.0-1101.107~18.04.1",
            "linux-modules-extra-5.4.0-1101-azure": "5.4.0-1101.107~18.04.1",
            "linux-image-unsigned-5.4.0-1101-azure": "5.4.0-1101.107~18.04.1",
            "linux-image-unsigned-5.4.0-1101-azure-dbgsym": "5.4.0-1101.107~18.04.1",
            "linux-modules-5.4.0-1101-azure": "5.4.0-1101.107~18.04.1",
            "linux-azure-5.4-headers-5.4.0-1101": "5.4.0-1101.107~18.04.1",
            "linux-cloud-tools-5.4.0-1101-azure": "5.4.0-1101.107~18.04.1",
            "linux-azure-5.4-tools-5.4.0-1101": "5.4.0-1101.107~18.04.1",
            "linux-headers-5.4.0-1101-azure": "5.4.0-1101.107~18.04.1",
            "linux-tools-5.4.0-1101-azure": "5.4.0-1101.107~18.04.1",
            "linux-azure-5.4-cloud-tools-5.4.0-1101": "5.4.0-1101.107~18.04.1"
        }
    ]
}

Ubuntu:18.04:LTS / linux-raspi2

Package

Name
linux-raspi2
Purl
pkg:deb/ubuntu/linux-raspi2@4.15.0-1126.134?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.15.0-1126.134

Affected versions

4.*

4.13.0-1005.5
4.13.0-1006.6
4.13.0-1008.8
4.15.0-1006.7
4.15.0-1009.10
4.15.0-1010.11
4.15.0-1011.12
4.15.0-1012.13
4.15.0-1013.14
4.15.0-1017.18
4.15.0-1018.19
4.15.0-1020.22
4.15.0-1021.23
4.15.0-1022.24
4.15.0-1024.26
4.15.0-1026.28
4.15.0-1027.29
4.15.0-1028.30
4.15.0-1029.31
4.15.0-1030.32
4.15.0-1031.33
4.15.0-1032.34
4.15.0-1033.35
4.15.0-1034.36
4.15.0-1036.38
4.15.0-1037.39
4.15.0-1038.40
4.15.0-1040.43
4.15.0-1041.44
4.15.0-1043.46
4.15.0-1044.47
4.15.0-1045.49
4.15.0-1047.51
4.15.0-1048.52
4.15.0-1049.53
4.15.0-1050.54
4.15.0-1052.56
4.15.0-1053.57
4.15.0-1054.58
4.15.0-1055.59
4.15.0-1057.61
4.15.0-1060.64
4.15.0-1061.65
4.15.0-1062.66
4.15.0-1063.67
4.15.0-1065.69
4.15.0-1067.71
4.15.0-1068.72
4.15.0-1070.74
4.15.0-1071.75
4.15.0-1073.78
4.15.0-1074.79
4.15.0-1076.81
4.15.0-1077.82
4.15.0-1078.83
4.15.0-1079.84
4.15.0-1080.85
4.15.0-1081.86
4.15.0-1082.87
4.15.0-1083.88
4.15.0-1084.89
4.15.0-1085.90
4.15.0-1086.91
4.15.0-1089.94
4.15.0-1092.98
4.15.0-1093.99
4.15.0-1094.100
4.15.0-1095.101
4.15.0-1096.102
4.15.0-1097.103
4.15.0-1098.104
4.15.0-1099.106
4.15.0-1101.108
4.15.0-1102.109
4.15.0-1103.110
4.15.0-1105.112
4.15.0-1106.113
4.15.0-1107.114
4.15.0-1108.115
4.15.0-1109.116
4.15.0-1111.118
4.15.0-1114.122
4.15.0-1115.123
4.15.0-1117.125
4.15.0-1118.126
4.15.0-1119.127
4.15.0-1120.128
4.15.0-1121.129
4.15.0-1124.132
4.15.0-1125.133

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-image-4.15.0-1126-raspi2-dbgsym": "4.15.0-1126.134",
            "linux-buildinfo-4.15.0-1126-raspi2": "4.15.0-1126.134",
            "linux-modules-4.15.0-1126-raspi2": "4.15.0-1126.134",
            "linux-headers-4.15.0-1126-raspi2": "4.15.0-1126.134",
            "linux-raspi2-tools-4.15.0-1126": "4.15.0-1126.134",
            "linux-image-4.15.0-1126-raspi2": "4.15.0-1126.134",
            "linux-raspi2-headers-4.15.0-1126": "4.15.0-1126.134",
            "linux-tools-4.15.0-1126-raspi2": "4.15.0-1126.134"
        }
    ]
}

Ubuntu:20.04:LTS / linux-azure

Package

Name
linux-azure
Purl
pkg:deb/ubuntu/linux-azure@5.4.0-1101.107?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.4.0-1101.107

Affected versions

5.*

5.3.0-1003.3
5.3.0-1008.9
5.3.0-1009.10
5.4.0-1006.6
5.4.0-1008.8
5.4.0-1009.9
5.4.0-1010.10
5.4.0-1012.12
5.4.0-1016.16
5.4.0-1019.19
5.4.0-1020.20
5.4.0-1022.22
5.4.0-1023.23
5.4.0-1025.25
5.4.0-1026.26
5.4.0-1031.32
5.4.0-1032.33
5.4.0-1034.35
5.4.0-1035.36
5.4.0-1036.38
5.4.0-1039.41
5.4.0-1040.42
5.4.0-1041.43
5.4.0-1043.45
5.4.0-1044.46
5.4.0-1046.48
5.4.0-1047.49
5.4.0-1048.50
5.4.0-1049.51
5.4.0-1051.53
5.4.0-1055.57
5.4.0-1056.58
5.4.0-1058.60
5.4.0-1059.62
5.4.0-1061.64
5.4.0-1062.65
5.4.0-1063.66
5.4.0-1064.67
5.4.0-1065.68
5.4.0-1067.70
5.4.0-1068.71
5.4.0-1069.72
5.4.0-1070.73
5.4.0-1072.75
5.4.0-1073.76
5.4.0-1074.77
5.4.0-1077.80
5.4.0-1078.81
5.4.0-1080.83
5.4.0-1083.87
5.4.0-1085.90
5.4.0-1086.91
5.4.0-1089.94
5.4.0-1090.95
5.4.0-1091.96
5.4.0-1094.100
5.4.0-1095.101
5.4.0-1098.104
5.4.0-1100.106

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-buildinfo-5.4.0-1101-azure": "5.4.0-1101.107",
            "linux-modules-extra-5.4.0-1101-azure": "5.4.0-1101.107",
            "linux-image-unsigned-5.4.0-1101-azure": "5.4.0-1101.107",
            "linux-image-unsigned-5.4.0-1101-azure-dbgsym": "5.4.0-1101.107",
            "linux-modules-5.4.0-1101-azure": "5.4.0-1101.107",
            "linux-azure-tools-5.4.0-1101": "5.4.0-1101.107",
            "linux-cloud-tools-5.4.0-1101-azure": "5.4.0-1101.107",
            "linux-headers-5.4.0-1101-azure": "5.4.0-1101.107",
            "linux-azure-headers-5.4.0-1101": "5.4.0-1101.107",
            "linux-tools-5.4.0-1101-azure": "5.4.0-1101.107",
            "linux-azure-cloud-tools-5.4.0-1101": "5.4.0-1101.107"
        }
    ]
}