黄思聪 discovered that the NFC Controller Interface (NCI) implementation in the Linux kernel did not properly handle certain memory allocation failure conditions, leading to a null pointer dereference vulnerability. A local attacker could use this to cause a denial of service (system crash). (CVE-2023-46343)
It was discovered that a race condition existed in the Bluetooth subsystem of the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-51779)
It was discovered that a race condition existed in the Rose X.25 protocol implementation in the Linux kernel, leading to a use-after- free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-51782)
Alon Zahavi discovered that the NVMe-oF/TCP subsystem of the Linux kernel did not properly handle connect command payloads in certain situations, leading to an out-of-bounds read vulnerability. A remote attacker could use this to expose sensitive information (kernel memory). (CVE-2023-6121)
Jann Horn discovered that the io_uring subsystem in the Linux kernel contained an out-of-bounds access vulnerability. A local attacker could use this to cause a denial of service (system crash). (CVE-2023-6560)
Dan Carpenter discovered that the netfilter subsystem in the Linux kernel did not store data in properly sized memory locations. A local user could use this to cause a denial of service (system crash). (CVE-2024-0607)
Supraja Sridhara, Benedict Schlüter, Mark Kuhne, Andrin Bertschi, and Shweta Shinde discovered that the Confidential Computing framework in the Linux kernel for x86 platforms did not properly handle 32-bit emulation on TDX and SEV. An attacker with access to the VMM could use this to cause a denial of service (guest crash) or possibly execute arbitrary code. (CVE-2024-25744)
{
"binaries": [
{
"binary_version": "6.5.0-1016.16~22.04.1",
"binary_name": "linux-azure-6.5-cloud-tools-6.5.0-1016"
},
{
"binary_version": "6.5.0-1016.16~22.04.1",
"binary_name": "linux-azure-6.5-headers-6.5.0-1016"
},
{
"binary_version": "6.5.0-1016.16~22.04.1",
"binary_name": "linux-azure-6.5-tools-6.5.0-1016"
},
{
"binary_version": "6.5.0-1016.16~22.04.1",
"binary_name": "linux-buildinfo-6.5.0-1016-azure"
},
{
"binary_version": "6.5.0-1016.16~22.04.1",
"binary_name": "linux-cloud-tools-6.5.0-1016-azure"
},
{
"binary_version": "6.5.0-1016.16~22.04.1",
"binary_name": "linux-headers-6.5.0-1016-azure"
},
{
"binary_version": "6.5.0-1016.16~22.04.1",
"binary_name": "linux-image-unsigned-6.5.0-1016-azure"
},
{
"binary_version": "6.5.0-1016.16~22.04.1",
"binary_name": "linux-modules-6.5.0-1016-azure"
},
{
"binary_version": "6.5.0-1016.16~22.04.1",
"binary_name": "linux-modules-extra-6.5.0-1016-azure"
},
{
"binary_version": "6.5.0-1016.16~22.04.1",
"binary_name": "linux-modules-ipu6-6.5.0-1016-azure"
},
{
"binary_version": "6.5.0-1016.16~22.04.1",
"binary_name": "linux-modules-ivsc-6.5.0-1016-azure"
},
{
"binary_version": "6.5.0-1016.16~22.04.1",
"binary_name": "linux-modules-iwlwifi-6.5.0-1016-azure"
},
{
"binary_version": "6.5.0-1016.16~22.04.1",
"binary_name": "linux-tools-6.5.0-1016-azure"
}
],
"availability": "No subscription required"
}
{
"cves": [
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-6121"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-6560"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-46343"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-51779"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-51782"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2024-0607"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2024-25744"
}
],
"ecosystem": "Ubuntu:22.04:LTS"
}
{
"binaries": [
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-buildinfo-6.5.0-25-generic"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-buildinfo-6.5.0-25-generic-64k"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-cloud-tools-6.5.0-25-generic"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-headers-6.5.0-25-generic"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-headers-6.5.0-25-generic-64k"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-hwe-6.5-cloud-tools-6.5.0-25"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-hwe-6.5-cloud-tools-common"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-hwe-6.5-headers-6.5.0-25"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-hwe-6.5-tools-6.5.0-25"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-hwe-6.5-tools-common"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-hwe-6.5-tools-host"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-image-6.5.0-25-generic"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-image-unsigned-6.5.0-25-generic"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-image-unsigned-6.5.0-25-generic-64k"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-modules-6.5.0-25-generic"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-modules-6.5.0-25-generic-64k"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-modules-extra-6.5.0-25-generic"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-modules-ipu6-6.5.0-25-generic"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-modules-ivsc-6.5.0-25-generic"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-modules-iwlwifi-6.5.0-25-generic"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-source-6.5.0"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-tools-6.5.0-25-generic"
},
{
"binary_version": "6.5.0-25.25~22.04.1",
"binary_name": "linux-tools-6.5.0-25-generic-64k"
}
],
"availability": "No subscription required"
}
{
"cves": [
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-6121"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-6560"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-46343"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-51779"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2023-51782"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2024-0607"
},
{
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
},
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H"
},
{
"type": "Ubuntu",
"score": "medium"
}
],
"id": "CVE-2024-25744"
}
],
"ecosystem": "Ubuntu:22.04:LTS"
}