USN-6503-1

Source
https://ubuntu.com/security/notices/USN-6503-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6503-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-6503-1
Related
Published
2023-11-21T19:58:21.499902Z
Modified
2023-11-21T19:58:21.499902Z
Summary
linux, linux-aws, linux-laptop, linux-lowlatency, linux-oem-6.5, linux-oracle, linux-raspi, linux-starfive vulnerabilities
Details

Yu Hao discovered that the UBI driver in the Linux kernel did not properly check for MTD with zero erasesize during device attachment. A local privileged attacker could use this to cause a denial of service (system crash). (CVE-2023-31085)

Bien Pham discovered that the netfiler subsystem in the Linux kernel contained a race condition, leading to a use-after-free vulnerability. A local user could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-4244)

Maxim Levitsky discovered that the KVM nested virtualization (SVM) implementation for AMD processors in the Linux kernel did not properly handle x2AVIC MSRs. An attacker in a guest VM could use this to cause a denial of service (host kernel crash). (CVE-2023-5090)

It was discovered that the SMB network file sharing protocol implementation in the Linux kernel did not properly handle certain error conditions, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-5345)

Murray McAllister discovered that the VMware Virtual GPU DRM driver in the Linux kernel did not properly handle memory objects when storing surfaces, leading to a use-after-free vulnerability. A local attacker in a guest VM could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-5633)

References

Affected packages

Ubuntu:22.04:LTS / linux-oem-6.5

Package

Name
linux-oem-6.5
Purl
pkg:deb/ubuntu/linux-oem-6.5?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.5.0-1008.8

Affected versions

6.*

6.5.0-1003.3
6.5.0-1004.4
6.5.0-1006.6
6.5.0-1007.7

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "6.5.0-1008.8",
            "binary_name": "linux-buildinfo-6.5.0-1008-oem"
        },
        {
            "binary_version": "6.5.0-1008.8",
            "binary_name": "linux-headers-6.5.0-1008-oem"
        },
        {
            "binary_version": "6.5.0-1008.8",
            "binary_name": "linux-image-unsigned-6.5.0-1008-oem"
        },
        {
            "binary_version": "6.5.0-1008.8",
            "binary_name": "linux-image-unsigned-6.5.0-1008-oem-dbgsym"
        },
        {
            "binary_version": "6.5.0-1008.8",
            "binary_name": "linux-modules-6.5.0-1008-oem"
        },
        {
            "binary_version": "6.5.0-1008.8",
            "binary_name": "linux-modules-ipu6-6.5.0-1008-oem"
        },
        {
            "binary_version": "6.5.0-1008.8",
            "binary_name": "linux-modules-ivsc-6.5.0-1008-oem"
        },
        {
            "binary_version": "6.5.0-1008.8",
            "binary_name": "linux-modules-iwlwifi-6.5.0-1008-oem"
        },
        {
            "binary_version": "6.5.0-1008.8",
            "binary_name": "linux-oem-6.5-headers-6.5.0-1008"
        },
        {
            "binary_version": "6.5.0-1008.8",
            "binary_name": "linux-oem-6.5-lib-rust-6.5.0-1008-oem"
        },
        {
            "binary_version": "6.5.0-1008.8",
            "binary_name": "linux-oem-6.5-tools-6.5.0-1008"
        },
        {
            "binary_version": "6.5.0-1008.8",
            "binary_name": "linux-oem-6.5-tools-host"
        },
        {
            "binary_version": "6.5.0-1008.8",
            "binary_name": "linux-tools-6.5.0-1008-oem"
        }
    ]
}

Ubuntu:23.10 / linux

Package

Name
linux
Purl
pkg:deb/ubuntu/linux?arch=src?distro=mantic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.5.0-13.13

Affected versions

6.*

6.2.0-20.20
6.2.0-21.21
6.3.0-7.7
6.5.0-5.5
6.5.0-7.7
6.5.0-9.9
6.5.0-10.10

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-buildinfo-6.5.0-13-generic"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-buildinfo-6.5.0-13-generic-64k"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-cloud-tools-6.5.0-13"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-cloud-tools-6.5.0-13-generic"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-cloud-tools-common"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-doc"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-headers-6.5.0-13"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-headers-6.5.0-13-generic"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-headers-6.5.0-13-generic-64k"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-image-6.5.0-13-generic"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-image-6.5.0-13-generic-dbgsym"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-image-unsigned-6.5.0-13-generic"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-image-unsigned-6.5.0-13-generic-64k"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-image-unsigned-6.5.0-13-generic-64k-dbgsym"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-image-unsigned-6.5.0-13-generic-dbgsym"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-lib-rust-6.5.0-13-generic"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-libc-dev"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-modules-6.5.0-13-generic"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-modules-6.5.0-13-generic-64k"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-modules-extra-6.5.0-13-generic"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-modules-ipu6-6.5.0-13-generic"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-modules-ivsc-6.5.0-13-generic"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-modules-iwlwifi-6.5.0-13-generic"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-source-6.5.0"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-tools-6.5.0-13"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-tools-6.5.0-13-generic"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-tools-6.5.0-13-generic-64k"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-tools-common"
        },
        {
            "binary_version": "6.5.0-13.13",
            "binary_name": "linux-tools-host"
        }
    ]
}

Ubuntu:23.10 / linux-aws

Package

Name
linux-aws
Purl
pkg:deb/ubuntu/linux-aws?arch=src?distro=mantic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.5.0-1010.10

Affected versions

6.*

6.2.0-1003.3
6.2.0-1004.4
6.5.0-1005.5
6.5.0-1007.7
6.5.0-1008.8
6.5.0-1009.9

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "6.5.0-1010.10",
            "binary_name": "linux-aws-cloud-tools-6.5.0-1010"
        },
        {
            "binary_version": "6.5.0-1010.10",
            "binary_name": "linux-aws-headers-6.5.0-1010"
        },
        {
            "binary_version": "6.5.0-1010.10",
            "binary_name": "linux-aws-tools-6.5.0-1010"
        },
        {
            "binary_version": "6.5.0-1010.10",
            "binary_name": "linux-buildinfo-6.5.0-1010-aws"
        },
        {
            "binary_version": "6.5.0-1010.10",
            "binary_name": "linux-cloud-tools-6.5.0-1010-aws"
        },
        {
            "binary_version": "6.5.0-1010.10",
            "binary_name": "linux-headers-6.5.0-1010-aws"
        },
        {
            "binary_version": "6.5.0-1010.10",
            "binary_name": "linux-image-unsigned-6.5.0-1010-aws"
        },
        {
            "binary_version": "6.5.0-1010.10",
            "binary_name": "linux-image-unsigned-6.5.0-1010-aws-dbgsym"
        },
        {
            "binary_version": "6.5.0-1010.10",
            "binary_name": "linux-modules-6.5.0-1010-aws"
        },
        {
            "binary_version": "6.5.0-1010.10",
            "binary_name": "linux-modules-extra-6.5.0-1010-aws"
        },
        {
            "binary_version": "6.5.0-1010.10",
            "binary_name": "linux-tools-6.5.0-1010-aws"
        }
    ]
}

Ubuntu:23.10 / linux-laptop

Package

Name
linux-laptop
Purl
pkg:deb/ubuntu/linux-laptop?arch=src?distro=mantic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.5.0-1006.9

Affected versions

6.*

6.5.0-1003.6
6.5.0-1004.7
6.5.0-1005.8

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "6.5.0-1006.9",
            "binary_name": "linux-buildinfo-6.5.0-1006-laptop"
        },
        {
            "binary_version": "6.5.0-1006.9",
            "binary_name": "linux-headers-6.5.0-1006-laptop"
        },
        {
            "binary_version": "6.5.0-1006.9",
            "binary_name": "linux-image-6.5.0-1006-laptop"
        },
        {
            "binary_version": "6.5.0-1006.9",
            "binary_name": "linux-image-6.5.0-1006-laptop-dbgsym"
        },
        {
            "binary_version": "6.5.0-1006.9",
            "binary_name": "linux-laptop-headers-6.5.0-1006"
        },
        {
            "binary_version": "6.5.0-1006.9",
            "binary_name": "linux-laptop-tools-6.5.0-1006"
        },
        {
            "binary_version": "6.5.0-1006.9",
            "binary_name": "linux-laptop-tools-common"
        },
        {
            "binary_version": "6.5.0-1006.9",
            "binary_name": "linux-laptop-tools-host"
        },
        {
            "binary_version": "6.5.0-1006.9",
            "binary_name": "linux-modules-6.5.0-1006-laptop"
        },
        {
            "binary_version": "6.5.0-1006.9",
            "binary_name": "linux-tools-6.5.0-1006-laptop"
        }
    ]
}

Ubuntu:23.10 / linux-lowlatency

Package

Name
linux-lowlatency
Purl
pkg:deb/ubuntu/linux-lowlatency?arch=src?distro=mantic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.5.0-13.13.1

Affected versions

6.*

6.2.0-1003.3
6.3.0-7.7.1
6.5.0-5.5.1
6.5.0-8.8.1
6.5.0-9.9.1
6.5.0-10.10.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-buildinfo-6.5.0-13-lowlatency"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-buildinfo-6.5.0-13-lowlatency-64k"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-cloud-tools-6.5.0-13-lowlatency"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-headers-6.5.0-13-lowlatency"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-headers-6.5.0-13-lowlatency-64k"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-image-unsigned-6.5.0-13-lowlatency"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-image-unsigned-6.5.0-13-lowlatency-64k"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-image-unsigned-6.5.0-13-lowlatency-64k-dbgsym"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-image-unsigned-6.5.0-13-lowlatency-dbgsym"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-lowlatency-cloud-tools-6.5.0-13"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-lowlatency-cloud-tools-common"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-lowlatency-headers-6.5.0-13"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-lowlatency-lib-rust-6.5.0-13-lowlatency"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-lowlatency-tools-6.5.0-13"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-lowlatency-tools-common"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-lowlatency-tools-host"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-modules-6.5.0-13-lowlatency"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-modules-6.5.0-13-lowlatency-64k"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-modules-iwlwifi-6.5.0-13-lowlatency"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-tools-6.5.0-13-lowlatency"
        },
        {
            "binary_version": "6.5.0-13.13.1",
            "binary_name": "linux-tools-6.5.0-13-lowlatency-64k"
        }
    ]
}

Ubuntu:23.10 / linux-oracle

Package

Name
linux-oracle
Purl
pkg:deb/ubuntu/linux-oracle?arch=src?distro=mantic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.5.0-1012.12

Affected versions

6.*

6.2.0-1003.3
6.2.0-1004.4
6.5.0-1005.5
6.5.0-1009.9
6.5.0-1010.10
6.5.0-1011.11

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "6.5.0-1012.12",
            "binary_name": "linux-buildinfo-6.5.0-1012-oracle"
        },
        {
            "binary_version": "6.5.0-1012.12",
            "binary_name": "linux-headers-6.5.0-1012-oracle"
        },
        {
            "binary_version": "6.5.0-1012.12",
            "binary_name": "linux-image-unsigned-6.5.0-1012-oracle"
        },
        {
            "binary_version": "6.5.0-1012.12",
            "binary_name": "linux-image-unsigned-6.5.0-1012-oracle-dbgsym"
        },
        {
            "binary_version": "6.5.0-1012.12",
            "binary_name": "linux-modules-6.5.0-1012-oracle"
        },
        {
            "binary_version": "6.5.0-1012.12",
            "binary_name": "linux-modules-extra-6.5.0-1012-oracle"
        },
        {
            "binary_version": "6.5.0-1012.12",
            "binary_name": "linux-modules-iwlwifi-6.5.0-1012-oracle"
        },
        {
            "binary_version": "6.5.0-1012.12",
            "binary_name": "linux-oracle-headers-6.5.0-1012"
        },
        {
            "binary_version": "6.5.0-1012.12",
            "binary_name": "linux-oracle-tools-6.5.0-1012"
        },
        {
            "binary_version": "6.5.0-1012.12",
            "binary_name": "linux-tools-6.5.0-1012-oracle"
        }
    ]
}

Ubuntu:23.10 / linux-raspi

Package

Name
linux-raspi
Purl
pkg:deb/ubuntu/linux-raspi?arch=src?distro=mantic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.5.0-1007.9

Affected versions

6.*

6.2.0-1004.5
6.5.0-1002.2
6.5.0-1003.4
6.5.0-1004.6
6.5.0-1005.7
6.5.0-1006.8

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "6.5.0-1007.9",
            "binary_name": "linux-buildinfo-6.5.0-1007-raspi"
        },
        {
            "binary_version": "6.5.0-1007.9",
            "binary_name": "linux-headers-6.5.0-1007-raspi"
        },
        {
            "binary_version": "6.5.0-1007.9",
            "binary_name": "linux-image-6.5.0-1007-raspi"
        },
        {
            "binary_version": "6.5.0-1007.9",
            "binary_name": "linux-image-6.5.0-1007-raspi-dbgsym"
        },
        {
            "binary_version": "6.5.0-1007.9",
            "binary_name": "linux-modules-6.5.0-1007-raspi"
        },
        {
            "binary_version": "6.5.0-1007.9",
            "binary_name": "linux-modules-extra-6.5.0-1007-raspi"
        },
        {
            "binary_version": "6.5.0-1007.9",
            "binary_name": "linux-raspi-headers-6.5.0-1007"
        },
        {
            "binary_version": "6.5.0-1007.9",
            "binary_name": "linux-raspi-tools-6.5.0-1007"
        },
        {
            "binary_version": "6.5.0-1007.9",
            "binary_name": "linux-tools-6.5.0-1007-raspi"
        }
    ]
}

Ubuntu:23.10 / linux-starfive

Package

Name
linux-starfive
Purl
pkg:deb/ubuntu/linux-starfive?arch=src?distro=mantic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.5.0-1004.5

Affected versions

5.*

5.19.0-1014.16

6.*

6.5.0-1002.3
6.5.0-1003.4

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "6.5.0-1004.5",
            "binary_name": "linux-buildinfo-6.5.0-1004-starfive"
        },
        {
            "binary_version": "6.5.0-1004.5",
            "binary_name": "linux-headers-6.5.0-1004-starfive"
        },
        {
            "binary_version": "6.5.0-1004.5",
            "binary_name": "linux-image-6.5.0-1004-starfive"
        },
        {
            "binary_version": "6.5.0-1004.5",
            "binary_name": "linux-image-6.5.0-1004-starfive-dbgsym"
        },
        {
            "binary_version": "6.5.0-1004.5",
            "binary_name": "linux-modules-6.5.0-1004-starfive"
        },
        {
            "binary_version": "6.5.0-1004.5",
            "binary_name": "linux-modules-extra-6.5.0-1004-starfive"
        },
        {
            "binary_version": "6.5.0-1004.5",
            "binary_name": "linux-starfive-headers-6.5.0-1004"
        },
        {
            "binary_version": "6.5.0-1004.5",
            "binary_name": "linux-starfive-tools-6.5.0-1004"
        },
        {
            "binary_version": "6.5.0-1004.5",
            "binary_name": "linux-tools-6.5.0-1004-starfive"
        }
    ]
}