USN-5794-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-5794-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/USN-5794-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-5794-1
Related
  • CVE-2022-3643
  • CVE-2022-42896
  • CVE-2022-43945
  • CVE-2022-45934
Published
2023-01-06T22:55:54.449737Z
Modified
2023-01-06T22:55:54.449737Z
Summary
linux-aws vulnerabilities
Details

It was discovered that the NFSD implementation in the Linux kernel did not properly handle some RPC messages, leading to a buffer overflow. A remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-43945)

Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation in the Linux kernel contained multiple use-after-free vulnerabilities. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-42896)

It was discovered that the Xen netback driver in the Linux kernel did not properly handle packets structured in certain ways. An attacker in a guest VM could possibly use this to cause a denial of service (host NIC availability). (CVE-2022-3643)

It was discovered that an integer overflow vulnerability existed in the Bluetooth subsystem in the Linux kernel. A physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2022-45934)

References

Affected packages

Ubuntu:Pro:16.04:LTS / linux-aws

Package

Name
linux-aws

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.0-1153.168

Ecosystem specific

{
    "availability": "Available with Ubuntu Pro: https://ubuntu.com/pro",
    "binaries": [
        {
            "linux-tools-aws": "4.4.0.1153.157",
            "linux-headers-aws": "4.4.0.1153.157",
            "linux-modules-4.4.0-1153-aws": "4.4.0-1153.168",
            "linux-buildinfo-4.4.0-1153-aws": "4.4.0-1153.168",
            "linux-cloud-tools-4.4.0-1153-aws": "4.4.0-1153.168",
            "linux-aws": "4.4.0.1153.157",
            "linux-aws-tools-4.4.0-1153": "4.4.0-1153.168",
            "linux-image-aws": "4.4.0.1153.157",
            "linux-tools-4.4.0-1153-aws": "4.4.0-1153.168",
            "linux-modules-extra-aws": "4.4.0.1153.157",
            "linux-modules-extra-4.4.0-1153-aws": "4.4.0-1153.168",
            "linux-aws-headers-4.4.0-1153": "4.4.0-1153.168",
            "linux-headers-4.4.0-1153-aws": "4.4.0-1153.168",
            "linux-aws-cloud-tools-4.4.0-1153": "4.4.0-1153.168",
            "linux-image-4.4.0-1153-aws": "4.4.0-1153.168"
        }
    ]
}