Lonial Con discovered that the netfilter subsystem in the Linux kernel did not properly handle element deactivation in certain cases, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2024-1085)
Notselwyn discovered that the netfilter subsystem in the Linux kernel did not properly handle verdict parameters in certain cases, leading to a use- after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2024-1086)
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - PWM drivers; (CVE-2024-26597, CVE-2024-26599)
{ "binaries": [ { "binary_version": "6.5.0-1017.17~22.04.1", "binary_name": "linux-azure-6.5-cloud-tools-6.5.0-1017" }, { "binary_version": "6.5.0-1017.17~22.04.1", "binary_name": "linux-azure-6.5-headers-6.5.0-1017" }, { "binary_version": "6.5.0-1017.17~22.04.1", "binary_name": "linux-azure-6.5-tools-6.5.0-1017" }, { "binary_version": "6.5.0-1017.17~22.04.1", "binary_name": "linux-buildinfo-6.5.0-1017-azure" }, { "binary_version": "6.5.0-1017.17~22.04.1", "binary_name": "linux-cloud-tools-6.5.0-1017-azure" }, { "binary_version": "6.5.0-1017.17~22.04.1", "binary_name": "linux-headers-6.5.0-1017-azure" }, { "binary_version": "6.5.0-1017.17~22.04.1", "binary_name": "linux-image-unsigned-6.5.0-1017-azure" }, { "binary_version": "6.5.0-1017.17~22.04.1", "binary_name": "linux-modules-6.5.0-1017-azure" }, { "binary_version": "6.5.0-1017.17~22.04.1", "binary_name": "linux-modules-extra-6.5.0-1017-azure" }, { "binary_version": "6.5.0-1017.17~22.04.1", "binary_name": "linux-modules-ipu6-6.5.0-1017-azure" }, { "binary_version": "6.5.0-1017.17~22.04.1", "binary_name": "linux-modules-ivsc-6.5.0-1017-azure" }, { "binary_version": "6.5.0-1017.17~22.04.1", "binary_name": "linux-modules-iwlwifi-6.5.0-1017-azure" }, { "binary_version": "6.5.0-1017.17~22.04.1", "binary_name": "linux-tools-6.5.0-1017-azure" } ], "availability": "No subscription required" }
{ "cves_map": { "cves": [ { "severity": [ { "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "type": "CVSS_V3" }, { "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "type": "CVSS_V3" }, { "score": "high", "type": "Ubuntu" } ], "id": "CVE-2024-1085" }, { "severity": [ { "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "type": "CVSS_V3" }, { "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "type": "CVSS_V3" }, { "score": "high", "type": "Ubuntu" } ], "id": "CVE-2024-1086" }, { "severity": [ { "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H", "type": "CVSS_V3" }, { "score": "high", "type": "Ubuntu" } ], "id": "CVE-2024-26597" }, { "severity": [ { "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H", "type": "CVSS_V3" }, { "score": "medium", "type": "Ubuntu" } ], "id": "CVE-2024-26599" } ], "ecosystem": "Ubuntu:22.04:LTS" } }