USN-6628-2

Source
https://ubuntu.com/security/notices/USN-6628-2
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6628-2.json
JSON Data
https://api.osv.dev/v1/vulns/USN-6628-2
Related
Published
2024-02-15T03:02:33.147813Z
Modified
2024-02-15T03:02:33.147813Z
Summary
linux-intel-iotg-5.15 vulnerabilities
Details

Quentin Minster discovered that a race condition existed in the KSMBD implementation in the Linux kernel when handling sessions operations. A remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-32250, CVE-2023-32252, CVE-2023-32257)

Marek Marczykowski-Górecki discovered that the Xen event channel infrastructure implementation in the Linux kernel contained a race condition. An attacker in a guest VM could possibly use this to cause a denial of service (paravirtualized device unavailability). (CVE-2023-34324)

Zheng Wang discovered a use-after-free in the Renesas Ethernet AVB driver in the Linux kernel during device removal. A privileged attacker could use this to cause a denial of service (system crash). (CVE-2023-35827)

Tom Dohrmann discovered that the Secure Encrypted Virtualization (SEV) implementation for AMD processors in the Linux kernel contained a race condition when accessing MMIO registers. A local attacker in a SEV guest VM could possibly use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-46813)

It was discovered that the Microchip USB Ethernet driver in the Linux kernel contained a race condition during device removal, leading to a use- after-free vulnerability. A physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2023-6039)

Lin Ma discovered that the netfilter subsystem in the Linux kernel did not properly validate network family support while creating a new netfilter table. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2023-6040)

It was discovered that the TLS subsystem in the Linux kernel did not properly perform cryptographic operations in some situations, leading to a null pointer dereference vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-6176)

It was discovered that the CIFS network file system implementation in the Linux kernel did not properly validate the server frame size in certain situation, leading to an out-of-bounds read vulnerability. An attacker could use this to construct a malicious CIFS image that, when operated on, could cause a denial of service (system crash) or possibly expose sensitive information. (CVE-2023-6606)

Xingyuan Mo discovered that the netfilter subsystem in the Linux kernel did not properly handle dynset expressions passed from userspace, leading to a null pointer dereference vulnerability. A local attacker could use this to cause a denial of service (system crash). (CVE-2023-6622)

Xingyuan Mo discovered that the netfilter subsystem in the Linux kernel did not properly handle inactive elements in its PIPAPO data structure, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-6817)

Budimir Markovic, Lucas De Marchi, and Pengfei Xu discovered that the perf subsystem in the Linux kernel did not properly validate all event sizes when attaching new events, leading to an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-6931)

It was discovered that the IGMP protocol implementation in the Linux kernel contained a race condition, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-6932)

Kevin Rich discovered that the netfilter subsystem in the Linux kernel did not properly check deactivated elements in certain situations, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2024-0193)

It was discovered that the TIPC protocol implementation in the Linux kernel did not properly handle locking during tipccryptokey_revoke() operations. A local attacker could use this to cause a denial of service (kernel deadlock). (CVE-2024-0641)

References

Affected packages

Ubuntu:20.04:LTS / linux-intel-iotg-5.15

Package

Name
linux-intel-iotg-5.15
Purl
pkg:deb/ubuntu/linux-intel-iotg-5.15?arch=src?distro=focal

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.0-1048.54~20.04.1

Affected versions

5.*

5.15.0-1003.5~20.04.1
5.15.0-1008.11~20.04.1
5.15.0-1010.14~20.04.1
5.15.0-1015.20~20.04.2
5.15.0-1016.21~20.04.1
5.15.0-1017.22~20.04.1
5.15.0-1018.23~20.04.1
5.15.0-1021.26~20.04.1
5.15.0-1023.28~20.04.1
5.15.0-1025.30~20.04.1
5.15.0-1026.31~20.04.1
5.15.0-1027.32~20.04.1
5.15.0-1030.35~20.04.1
5.15.0-1031.36~20.04.1
5.15.0-1033.38~20.04.1
5.15.0-1034.39~20.04.1
5.15.0-1036.41~20.04.1
5.15.0-1037.42~20.04.1
5.15.0-1038.43~20.04.1
5.15.0-1040.46~20.04.1
5.15.0-1043.49~20.04.1
5.15.0-1045.51~20.04.1
5.15.0-1046.52~20.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "binary_version": "5.15.0-1048.54~20.04.1",
            "binary_name": "linux-buildinfo-5.15.0-1048-intel-iotg"
        },
        {
            "binary_version": "5.15.0-1048.54~20.04.1",
            "binary_name": "linux-cloud-tools-5.15.0-1048-intel-iotg"
        },
        {
            "binary_version": "5.15.0-1048.54~20.04.1",
            "binary_name": "linux-headers-5.15.0-1048-intel-iotg"
        },
        {
            "binary_version": "5.15.0-1048.54~20.04.1",
            "binary_name": "linux-image-unsigned-5.15.0-1048-intel-iotg"
        },
        {
            "binary_version": "5.15.0-1048.54~20.04.1",
            "binary_name": "linux-image-unsigned-5.15.0-1048-intel-iotg-dbgsym"
        },
        {
            "binary_version": "5.15.0-1048.54~20.04.1",
            "binary_name": "linux-intel-iotg-5.15-cloud-tools-5.15.0-1048"
        },
        {
            "binary_version": "5.15.0-1048.54~20.04.1",
            "binary_name": "linux-intel-iotg-5.15-cloud-tools-common"
        },
        {
            "binary_version": "5.15.0-1048.54~20.04.1",
            "binary_name": "linux-intel-iotg-5.15-headers-5.15.0-1048"
        },
        {
            "binary_version": "5.15.0-1048.54~20.04.1",
            "binary_name": "linux-intel-iotg-5.15-tools-5.15.0-1048"
        },
        {
            "binary_version": "5.15.0-1048.54~20.04.1",
            "binary_name": "linux-intel-iotg-5.15-tools-common"
        },
        {
            "binary_version": "5.15.0-1048.54~20.04.1",
            "binary_name": "linux-intel-iotg-5.15-tools-host"
        },
        {
            "binary_version": "5.15.0-1048.54~20.04.1",
            "binary_name": "linux-modules-5.15.0-1048-intel-iotg"
        },
        {
            "binary_version": "5.15.0-1048.54~20.04.1",
            "binary_name": "linux-modules-extra-5.15.0-1048-intel-iotg"
        },
        {
            "binary_version": "5.15.0-1048.54~20.04.1",
            "binary_name": "linux-modules-iwlwifi-5.15.0-1048-intel-iotg"
        },
        {
            "binary_version": "5.15.0-1048.54~20.04.1",
            "binary_name": "linux-tools-5.15.0-1048-intel-iotg"
        }
    ]
}