USN-6536-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-6536-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6536-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-6536-1
Related
Published
2023-12-06T13:34:16Z
Modified
2023-12-06T13:34:16Z
Summary
linux, linux-aws, linux-laptop, linux-lowlatency, linux-oem-6.5, linux-oracle, linux-raspi, linux-starfive vulnerabilities
Details

Lucas Leong discovered that the netfilter subsystem in the Linux kernel did not properly validate some attributes passed from userspace. A local attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information (kernel memory). (CVE-2023-39189)

Kyle Zeng discovered that the IPv4 implementation in the Linux kernel did not properly handle socket buffers (skb) when performing IP routing in certain circumstances, leading to a null pointer dereference vulnerability. A privileged attacker could use this to cause a denial of service (system crash). (CVE-2023-42754)

Yikebaer Aizezi discovered that the ext4 file system implementation in the Linux kernel contained a use-after-free vulnerability when handling inode extent metadata. An attacker could use this to construct a malicious ext4 file system image that, when mounted, could cause a denial of service (system crash). (CVE-2023-45898)

Jason Wang discovered that the virtio ring implementation in the Linux kernel did not properly handle iov buffers in some situations. A local attacker in a guest VM could use this to cause a denial of service (host system crash). (CVE-2023-5158)

Alon Zahavi discovered that the NVMe-oF/TCP subsystem in the Linux kernel did not properly handle queue initialization failures in certain situations, leading to a use-after-free vulnerability. A remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-5178)

Budimir Markovic discovered that the perf subsystem in the Linux kernel did not properly handle event groups, leading to an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-5717)

References

Affected packages

Ubuntu:22.04:LTS / linux-oem-6.5

Package

Name
linux-oem-6.5
Purl
pkg:deb/ubuntu/linux-oem-6.5@6.5.0-1009.10?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.5.0-1009.10

Affected versions

6.*

6.5.0-1003.3
6.5.0-1004.4
6.5.0-1006.6
6.5.0-1007.7
6.5.0-1008.8

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-oem-6.5-lib-rust-6.5.0-1009-oem": "6.5.0-1009.10",
            "linux-image-unsigned-6.5.0-1009-oem": "6.5.0-1009.10",
            "linux-modules-iwlwifi-6.5.0-1009-oem": "6.5.0-1009.10",
            "linux-oem-6.5-tools-6.5.0-1009": "6.5.0-1009.10",
            "linux-oem-6.5-tools-host": "6.5.0-1009.10",
            "linux-tools-6.5.0-1009-oem": "6.5.0-1009.10",
            "linux-image-unsigned-6.5.0-1009-oem-dbgsym": "6.5.0-1009.10",
            "linux-modules-ipu6-6.5.0-1009-oem": "6.5.0-1009.10",
            "linux-modules-6.5.0-1009-oem": "6.5.0-1009.10",
            "linux-buildinfo-6.5.0-1009-oem": "6.5.0-1009.10",
            "linux-headers-6.5.0-1009-oem": "6.5.0-1009.10",
            "linux-modules-ivsc-6.5.0-1009-oem": "6.5.0-1009.10",
            "linux-oem-6.5-headers-6.5.0-1009": "6.5.0-1009.10"
        }
    ]
}

Ubuntu:23.10 / linux

Package

Name
linux
Purl
pkg:deb/ubuntu/linux@6.5.0-14.14?arch=src?distro=mantic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.5.0-14.14

Affected versions

6.*

6.2.0-20.20
6.2.0-21.21
6.3.0-7.7
6.5.0-5.5
6.5.0-7.7
6.5.0-9.9
6.5.0-10.10
6.5.0-13.13

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-image-unsigned-6.5.0-14-generic-64k-dbgsym": "6.5.0-14.14",
            "linux-cloud-tools-common": "6.5.0-14.14",
            "linux-lib-rust-6.5.0-14-generic": "6.5.0-14.14",
            "linux-headers-6.5.0-14-generic-64k": "6.5.0-14.14",
            "linux-libc-dev": "6.5.0-14.14",
            "linux-headers-6.5.0-14-generic": "6.5.0-14.14",
            "linux-cloud-tools-6.5.0-14": "6.5.0-14.14",
            "linux-modules-iwlwifi-6.5.0-14-generic": "6.5.0-14.14",
            "linux-doc": "6.5.0-14.14",
            "linux-source-6.5.0": "6.5.0-14.14",
            "linux-tools-6.5.0-14": "6.5.0-14.14",
            "linux-modules-6.5.0-14-generic-64k": "6.5.0-14.14",
            "linux-image-unsigned-6.5.0-14-generic": "6.5.0-14.14",
            "linux-modules-6.5.0-14-generic": "6.5.0-14.14",
            "linux-image-unsigned-6.5.0-14-generic-64k": "6.5.0-14.14",
            "linux-modules-ipu6-6.5.0-14-generic": "6.5.0-14.14",
            "linux-tools-6.5.0-14-generic-64k": "6.5.0-14.14",
            "linux-tools-6.5.0-14-generic": "6.5.0-14.14",
            "linux-modules-ivsc-6.5.0-14-generic": "6.5.0-14.14",
            "linux-image-6.5.0-14-generic": "6.5.0-14.14",
            "linux-tools-host": "6.5.0-14.14",
            "linux-modules-extra-6.5.0-14-generic": "6.5.0-14.14",
            "linux-buildinfo-6.5.0-14-generic-64k": "6.5.0-14.14",
            "linux-image-unsigned-6.5.0-14-generic-dbgsym": "6.5.0-14.14",
            "linux-image-6.5.0-14-generic-dbgsym": "6.5.0-14.14",
            "linux-cloud-tools-6.5.0-14-generic": "6.5.0-14.14",
            "linux-buildinfo-6.5.0-14-generic": "6.5.0-14.14",
            "linux-headers-6.5.0-14": "6.5.0-14.14",
            "linux-tools-common": "6.5.0-14.14"
        }
    ]
}

Ubuntu:23.10 / linux-aws

Package

Name
linux-aws
Purl
pkg:deb/ubuntu/linux-aws@6.5.0-1011.11?arch=src?distro=mantic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.5.0-1011.11

Affected versions

6.*

6.2.0-1003.3
6.2.0-1004.4
6.5.0-1005.5
6.5.0-1007.7
6.5.0-1008.8
6.5.0-1009.9
6.5.0-1010.10

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-aws-cloud-tools-6.5.0-1011": "6.5.0-1011.11",
            "linux-aws-tools-6.5.0-1011": "6.5.0-1011.11",
            "linux-tools-6.5.0-1011-aws": "6.5.0-1011.11",
            "linux-headers-6.5.0-1011-aws": "6.5.0-1011.11",
            "linux-modules-6.5.0-1011-aws": "6.5.0-1011.11",
            "linux-aws-headers-6.5.0-1011": "6.5.0-1011.11",
            "linux-buildinfo-6.5.0-1011-aws": "6.5.0-1011.11",
            "linux-image-unsigned-6.5.0-1011-aws": "6.5.0-1011.11",
            "linux-image-unsigned-6.5.0-1011-aws-dbgsym": "6.5.0-1011.11",
            "linux-cloud-tools-6.5.0-1011-aws": "6.5.0-1011.11",
            "linux-modules-extra-6.5.0-1011-aws": "6.5.0-1011.11"
        }
    ]
}

Ubuntu:23.10 / linux-laptop

Package

Name
linux-laptop
Purl
pkg:deb/ubuntu/linux-laptop@6.5.0-1007.10?arch=src?distro=mantic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.5.0-1007.10

Affected versions

6.*

6.5.0-1003.6
6.5.0-1004.7
6.5.0-1005.8
6.5.0-1006.9

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-laptop-headers-6.5.0-1007": "6.5.0-1007.10",
            "linux-image-6.5.0-1007-laptop": "6.5.0-1007.10",
            "linux-laptop-tools-6.5.0-1007": "6.5.0-1007.10",
            "linux-headers-6.5.0-1007-laptop": "6.5.0-1007.10",
            "linux-buildinfo-6.5.0-1007-laptop": "6.5.0-1007.10",
            "linux-modules-6.5.0-1007-laptop": "6.5.0-1007.10",
            "linux-image-6.5.0-1007-laptop-dbgsym": "6.5.0-1007.10",
            "linux-tools-6.5.0-1007-laptop": "6.5.0-1007.10"
        }
    ]
}

Ubuntu:23.10 / linux-lowlatency

Package

Name
linux-lowlatency
Purl
pkg:deb/ubuntu/linux-lowlatency@6.5.0-14.14.1?arch=src?distro=mantic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.5.0-14.14.1

Affected versions

6.*

6.2.0-1003.3
6.3.0-7.7.1
6.5.0-5.5.1
6.5.0-8.8.1
6.5.0-9.9.1
6.5.0-10.10.1
6.5.0-13.13.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-buildinfo-6.5.0-14-lowlatency": "6.5.0-14.14.1",
            "linux-buildinfo-6.5.0-14-lowlatency-64k": "6.5.0-14.14.1",
            "linux-lowlatency-tools-common": "6.5.0-14.14.1",
            "linux-image-unsigned-6.5.0-14-lowlatency": "6.5.0-14.14.1",
            "linux-image-unsigned-6.5.0-14-lowlatency-64k-dbgsym": "6.5.0-14.14.1",
            "linux-lowlatency-tools-host": "6.5.0-14.14.1",
            "linux-image-unsigned-6.5.0-14-lowlatency-64k": "6.5.0-14.14.1",
            "linux-headers-6.5.0-14-lowlatency": "6.5.0-14.14.1",
            "linux-lowlatency-cloud-tools-common": "6.5.0-14.14.1",
            "linux-tools-6.5.0-14-lowlatency-64k": "6.5.0-14.14.1",
            "linux-lowlatency-lib-rust-6.5.0-14-lowlatency": "6.5.0-14.14.1",
            "linux-modules-6.5.0-14-lowlatency-64k": "6.5.0-14.14.1",
            "linux-cloud-tools-6.5.0-14-lowlatency": "6.5.0-14.14.1",
            "linux-headers-6.5.0-14-lowlatency-64k": "6.5.0-14.14.1",
            "linux-lowlatency-cloud-tools-6.5.0-14": "6.5.0-14.14.1",
            "linux-tools-6.5.0-14-lowlatency": "6.5.0-14.14.1",
            "linux-lowlatency-headers-6.5.0-14": "6.5.0-14.14.1",
            "linux-modules-6.5.0-14-lowlatency": "6.5.0-14.14.1",
            "linux-lowlatency-tools-6.5.0-14": "6.5.0-14.14.1",
            "linux-modules-iwlwifi-6.5.0-14-lowlatency": "6.5.0-14.14.1",
            "linux-image-unsigned-6.5.0-14-lowlatency-dbgsym": "6.5.0-14.14.1"
        }
    ]
}

Ubuntu:23.10 / linux-oracle

Package

Name
linux-oracle
Purl
pkg:deb/ubuntu/linux-oracle@6.5.0-1013.13?arch=src?distro=mantic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.5.0-1013.13

Affected versions

6.*

6.2.0-1003.3
6.2.0-1004.4
6.5.0-1005.5
6.5.0-1009.9
6.5.0-1010.10
6.5.0-1011.11
6.5.0-1012.12

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-modules-6.5.0-1013-oracle": "6.5.0-1013.13",
            "linux-image-unsigned-6.5.0-1013-oracle": "6.5.0-1013.13",
            "linux-buildinfo-6.5.0-1013-oracle": "6.5.0-1013.13",
            "linux-modules-extra-6.5.0-1013-oracle": "6.5.0-1013.13",
            "linux-oracle-tools-6.5.0-1013": "6.5.0-1013.13",
            "linux-tools-6.5.0-1013-oracle": "6.5.0-1013.13",
            "linux-image-unsigned-6.5.0-1013-oracle-dbgsym": "6.5.0-1013.13",
            "linux-headers-6.5.0-1013-oracle": "6.5.0-1013.13",
            "linux-modules-iwlwifi-6.5.0-1013-oracle": "6.5.0-1013.13",
            "linux-oracle-headers-6.5.0-1013": "6.5.0-1013.13"
        }
    ]
}

Ubuntu:23.10 / linux-raspi

Package

Name
linux-raspi
Purl
pkg:deb/ubuntu/linux-raspi@6.5.0-1008.11?arch=src?distro=mantic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.5.0-1008.11

Affected versions

6.*

6.2.0-1004.5
6.5.0-1002.2
6.5.0-1003.4
6.5.0-1004.6
6.5.0-1005.7
6.5.0-1006.8
6.5.0-1007.9

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-image-6.5.0-1008-raspi-dbgsym": "6.5.0-1008.11",
            "linux-headers-6.5.0-1008-raspi": "6.5.0-1008.11",
            "linux-modules-6.5.0-1008-raspi": "6.5.0-1008.11",
            "linux-raspi-tools-6.5.0-1008": "6.5.0-1008.11",
            "linux-image-6.5.0-1008-raspi": "6.5.0-1008.11",
            "linux-raspi-headers-6.5.0-1008": "6.5.0-1008.11",
            "linux-modules-extra-6.5.0-1008-raspi": "6.5.0-1008.11",
            "linux-buildinfo-6.5.0-1008-raspi": "6.5.0-1008.11",
            "linux-tools-6.5.0-1008-raspi": "6.5.0-1008.11"
        }
    ]
}

Ubuntu:23.10 / linux-starfive

Package

Name
linux-starfive
Purl
pkg:deb/ubuntu/linux-starfive@6.5.0-1005.6?arch=src?distro=mantic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.5.0-1005.6

Affected versions

5.*

5.19.0-1014.16

6.*

6.5.0-1002.3
6.5.0-1003.4
6.5.0-1004.5

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-headers-6.5.0-1005-starfive": "6.5.0-1005.6",
            "linux-image-6.5.0-1005-starfive-dbgsym": "6.5.0-1005.6",
            "linux-buildinfo-6.5.0-1005-starfive": "6.5.0-1005.6",
            "linux-starfive-headers-6.5.0-1005": "6.5.0-1005.6",
            "linux-modules-6.5.0-1005-starfive": "6.5.0-1005.6",
            "linux-tools-6.5.0-1005-starfive": "6.5.0-1005.6",
            "linux-modules-extra-6.5.0-1005-starfive": "6.5.0-1005.6",
            "linux-starfive-tools-6.5.0-1005": "6.5.0-1005.6",
            "linux-image-6.5.0-1005-starfive": "6.5.0-1005.6"
        }
    ]
}