USN-5884-1

Source
https://ubuntu.com/security/notices/USN-5884-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/USN-5884-1.json
Related
Published
2023-02-23T16:09:52.810737Z
Modified
2023-02-23T16:09:52.810737Z
Summary
linux-aws vulnerabilities
Details

Kirill Tkhai discovered that the XFS file system implementation in the Linux kernel did not calculate size correctly when pre-allocating space in some situations. A local attacker could use this to expose sensitive information. (CVE-2021-4155)

Lee Jones discovered that a use-after-free vulnerability existed in the Bluetooth implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-20566)

Duoming Zhou discovered that a race condition existed in the SLIP driver in the Linux kernel, leading to a null pointer dereference vulnerability. An attacker could use this to cause a denial of service (system crash). (CVE-2022-41858)

Tamás Koczka discovered that the Bluetooth L2CAP implementation in the Linux kernel did not properly initialize memory in some situations. A physically proximate attacker could possibly use this to expose sensitive information (kernel memory). (CVE-2022-42895)

José Oliveira and Rodrigo Branco discovered that the prctl syscall implementation in the Linux kernel did not properly protect against indirect branch prediction attacks in some situations. A local attacker could possibly use this to expose sensitive information. (CVE-2023-0045)

It was discovered that the RNDIS USB driver in the Linux kernel contained an integer overflow vulnerability. A local attacker with physical access could plug in a malicious USB device to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-23559)

References

Affected packages

Ubuntu:Pro:16.04:LTS / linux-aws

Package

Name
linux-aws

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0The exact introduced commit is unknown
Fixed
4.4.0-1154.169

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "linux-headers-4.4.0-1154-aws": "4.4.0-1154.169",
            "linux-tools-aws": "4.4.0.1154.158",
            "linux-cloud-tools-4.4.0-1154-aws": "4.4.0-1154.169",
            "linux-headers-aws": "4.4.0.1154.158",
            "linux-buildinfo-4.4.0-1154-aws": "4.4.0-1154.169",
            "linux-aws-cloud-tools-4.4.0-1154": "4.4.0-1154.169",
            "linux-modules-extra-4.4.0-1154-aws": "4.4.0-1154.169",
            "linux-image-aws": "4.4.0.1154.158",
            "linux-aws": "4.4.0.1154.158",
            "linux-modules-extra-aws": "4.4.0.1154.158",
            "linux-aws-tools-4.4.0-1154": "4.4.0-1154.169",
            "linux-tools-4.4.0-1154-aws": "4.4.0-1154.169",
            "linux-aws-headers-4.4.0-1154": "4.4.0-1154.169",
            "linux-image-4.4.0-1154-aws": "4.4.0-1154.169",
            "linux-modules-4.4.0-1154-aws": "4.4.0-1154.169"
        }
    ]
}