{"id":34341,"date":"2022-12-02T19:04:03","date_gmt":"2022-12-02T16:04:03","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/170078\/USN-5755-1.txt"},"modified":"2022-12-03T08:13:27","modified_gmt":"2022-12-03T04:43:27","slug":"ubuntu-security-notice-usn-5755-1-linux-kernel","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/ubuntu-security-notice-usn-5755-1-linux-kernel\/","title":{"rendered":"Ubuntu Security Notice USN-5755-1 linux kernel"},"content":{"rendered":"<p dir=\"ltr\">==========================================================================<br \/>\nUbuntu Security Notice USN-5755-1<br \/>\nDecember 01, 2022<\/p>\n<p dir=\"ltr\">linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gkeop, linux-hwe-5.15,<br \/>\nlinux-ibm, linux-intel-iotg, linux-kvm, linux-lowlatency,<br \/>\nlinux-lowlatency-hwe-5.15, linux-oracle, linux-oracle-5.15, linux-raspi<br \/>\nvulnerabilities<br \/>\n==========================================================================<\/p>\n<p dir=\"ltr\">A security issue affects these releases of Ubuntu and its derivatives:<\/p>\n<p dir=\"ltr\">&#8211; Ubuntu 22.04 LTS<br \/>\n&#8211; Ubuntu 20.04 LTS<\/p>\n<p dir=\"ltr\">Summary:<\/p>\n<p dir=\"ltr\">Several security issues were fixed in the Linux kernel.<\/p>\n<p dir=\"ltr\">Software Description:<br \/>\n&#8211; linux: Linux kernel<br \/>\n&#8211; linux-aws: Linux kernel for Amazon Web Services (AWS) systems<br \/>\n&#8211; linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems<br \/>\n&#8211; linux-gkeop: Linux kernel for Google Container Engine (GKE) systems<br \/>\n&#8211; linux-ibm: Linux kernel for IBM cloud systems<br \/>\n&#8211; linux-intel-iotg: Linux kernel for Intel IoT platforms<br \/>\n&#8211; linux-kvm: Linux kernel for cloud environments<br \/>\n&#8211; linux-lowlatency: Linux low latency kernel<br \/>\n&#8211; linux-oracle: Linux kernel for Oracle Cloud systems<br \/>\n&#8211; linux-raspi: Linux kernel for Raspberry Pi systems<br \/>\n&#8211; linux-aws-5.15: Linux kernel for Amazon Web Services (AWS) systems<br \/>\n&#8211; linux-hwe-5.15: Linux hardware enablement (HWE) kernel<br \/>\n&#8211; linux-lowlatency-hwe-5.15: Linux low latency kernel<br \/>\n&#8211; linux-oracle-5.15: Linux kernel for Oracle Cloud systems<\/p>\n<p dir=\"ltr\">Details:<\/p>\n<p dir=\"ltr\">It was discovered that the NFSD implementation in the Linux kernel did not<br \/>\nproperly handle some RPC messages, leading to a buffer overflow. A remote<br \/>\nattacker could use this to cause a denial of service (system crash) or<br \/>\npossibly execute arbitrary code. (CVE-2022-43945)<\/p>\n<p dir=\"ltr\">Jann Horn discovered that the Linux kernel did not properly track memory<br \/>\nallocations for anonymous VMA mappings in some situations, leading to<br \/>\npotential data structure reuse. A local attacker could use this to cause a<br \/>\ndenial of service (system crash) or possibly execute arbitrary code.<br \/>\n(CVE-2022-42703)<\/p>\n<p dir=\"ltr\">It was discovered that a memory leak existed in the IPv6 implementation of<br \/>\nthe Linux kernel. A local attacker could use this to cause a denial of<br \/>\nservice (memory exhaustion). (CVE-2022-3524)<\/p>\n<p dir=\"ltr\">It was discovered that a race condition existed in the Bluetooth subsystem<br \/>\nin the Linux kernel, leading to a use-after-free vulnerability. A local<br \/>\nattacker could use this to cause a denial of service (system crash) or<br \/>\npossibly execute arbitrary code. (CVE-2022-3564)<\/p>\n<p dir=\"ltr\">It was discovered that the ISDN implementation of the Linux kernel<br \/>\ncontained a use-after-free vulnerability. A privileged user could use this<br \/>\nto cause a denial of service (system crash) or possibly execute arbitrary<br \/>\ncode. (CVE-2022-3565)<\/p>\n<p dir=\"ltr\">It was discovered that the TCP implementation in the Linux kernel contained<br \/>\na data race condition. An attacker could possibly use this to cause<br \/>\nundesired behaviors. (CVE-2022-3566)<\/p>\n<p dir=\"ltr\">It was discovered that the IPv6 implementation in the Linux kernel<br \/>\ncontained a data race condition. An attacker could possibly use this to<br \/>\ncause undesired behaviors. (CVE-2022-3567)<\/p>\n<p dir=\"ltr\">It was discovered that the Realtek RTL8152 USB Ethernet adapter driver in<br \/>\nthe Linux kernel did not properly handle certain error conditions. A local<br \/>\nattacker with physical access could plug in a specially crafted USB device<br \/>\nto cause a denial of service (memory exhaustion). (CVE-2022-3594)<\/p>\n<p dir=\"ltr\">It was discovered that a null pointer dereference existed in the NILFS2<br \/>\nfile system implementation in the Linux kernel. A local attacker could use<br \/>\nthis to cause a denial of service (system crash). (CVE-2022-3621)<\/p>\n<p dir=\"ltr\">Update instructions:<\/p>\n<p dir=\"ltr\">The problem can be corrected by updating your system to the following<br \/>\npackage versions:<\/p>\n<p dir=\"ltr\">Ubuntu 22.04 LTS:<br \/>\nlinux-image-5.15.0-1011-gkeop 5.15.0-1011.15<br \/>\nlinux-image-5.15.0-1021-ibm 5.15.0-1021.24<br \/>\nlinux-image-5.15.0-1021-intel-iotg 5.15.0-1021.26<br \/>\nlinux-image-5.15.0-1021-raspi 5.15.0-1021.23<br \/>\nlinux-image-5.15.0-1021-raspi-nolpae 5.15.0-1021.23<br \/>\nlinux-image-5.15.0-1024-kvm 5.15.0-1024.29<br \/>\nlinux-image-5.15.0-1025-gcp 5.15.0-1025.32<br \/>\nlinux-image-5.15.0-1025-oracle 5.15.0-1025.31<br \/>\nlinux-image-5.15.0-1026-aws 5.15.0-1026.30<br \/>\nlinux-image-5.15.0-56-generic 5.15.0-56.62<br \/>\nlinux-image-5.15.0-56-generic-64k 5.15.0-56.62<br \/>\nlinux-image-5.15.0-56-generic-lpae 5.15.0-56.62<br \/>\nlinux-image-5.15.0-56-lowlatency 5.15.0-56.62<br \/>\nlinux-image-5.15.0-56-lowlatency-64k 5.15.0-56.62<br \/>\nlinux-image-aws 5.15.0.1026.24<br \/>\nlinux-image-aws-lts-22.04 5.15.0.1026.24<br \/>\nlinux-image-gcp 5.15.0.1025.20<br \/>\nlinux-image-generic 5.15.0.56.54<br \/>\nlinux-image-generic-64k 5.15.0.56.54<br \/>\nlinux-image-generic-64k-hwe-22.04 5.15.0.56.54<br \/>\nlinux-image-generic-hwe-22.04 5.15.0.56.54<br \/>\nlinux-image-generic-lpae 5.15.0.56.54<br \/>\nlinux-image-generic-lpae-hwe-22.04 5.15.0.56.54<br \/>\nlinux-image-gkeop 5.15.0.1011.10<br \/>\nlinux-image-gkeop-5.15 5.15.0.1011.10<br \/>\nlinux-image-ibm 5.15.0.1021.17<br \/>\nlinux-image-intel-iotg 5.15.0.1021.20<br \/>\nlinux-image-kvm 5.15.0.1024.22<br \/>\nlinux-image-lowlatency 5.15.0.56.49<br \/>\nlinux-image-lowlatency-64k 5.15.0.56.49<br \/>\nlinux-image-lowlatency-64k-hwe-22.04 5.15.0.56.49<br \/>\nlinux-image-lowlatency-hwe-22.04 5.15.0.56.49<br \/>\nlinux-image-oracle 5.15.0.1025.20<br \/>\nlinux-image-raspi 5.15.0.1021.18<br \/>\nlinux-image-raspi-nolpae 5.15.0.1021.18<br \/>\nlinux-image-virtual 5.15.0.56.54<br \/>\nlinux-image-virtual-hwe-22.04 5.15.0.56.54<\/p>\n<p dir=\"ltr\">Ubuntu 20.04 LTS:<br \/>\nlinux-image-5.15.0-1025-oracle 5.15.0-1025.31~20.04.2<br \/>\nlinux-image-5.15.0-1026-aws 5.15.0-1026.30~20.04.2<br \/>\nlinux-image-5.15.0-56-generic 5.15.0-56.62~20.04.1<br \/>\nlinux-image-5.15.0-56-generic-64k 5.15.0-56.62~20.04.1<br \/>\nlinux-image-5.15.0-56-generic-lpae 5.15.0-56.62~20.04.1<br \/>\nlinux-image-5.15.0-56-lowlatency 5.15.0-56.62~20.04.1<br \/>\nlinux-image-5.15.0-56-lowlatency-64k 5.15.0-56.62~20.04.1<br \/>\nlinux-image-aws 5.15.0.1026.30~20.04.16<br \/>\nlinux-image-generic-64k-hwe-20.04 5.15.0.56.62~20.04.22<br \/>\nlinux-image-generic-hwe-20.04 5.15.0.56.62~20.04.22<br \/>\nlinux-image-generic-lpae-hwe-20.04 5.15.0.56.62~20.04.22<br \/>\nlinux-image-lowlatency-64k-hwe-20.04 5.15.0.56.62~20.04.20<br \/>\nlinux-image-lowlatency-hwe-20.04 5.15.0.56.62~20.04.20<br \/>\nlinux-image-oracle 5.15.0.1025.31~20.04.1<br \/>\nlinux-image-virtual-hwe-20.04 5.15.0.56.62~20.04.22<\/p>\n<p dir=\"ltr\">After a standard system update you need to reboot your computer to make<br \/>\nall the necessary changes.<\/p>\n<p dir=\"ltr\">ATTENTION: Due to an unavoidable ABI change the kernel updates have<br \/>\nbeen given a new version number, which requires you to recompile and<br \/>\nreinstall all third party kernel modules you might have installed.<br \/>\nUnless you manually uninstalled the standard kernel metapackages<br \/>\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,<br \/>\nlinux-powerpc), a standard system upgrade will automatically perform<br \/>\nthis as well.<\/p>\n<p dir=\"ltr\">References:<br \/>\nhttps:\/\/ubuntu.com\/security\/notices\/USN-5755-1<br \/>\nCVE-2022-3524, CVE-2022-3564, CVE-2022-3565, CVE-2022-3566,<br \/>\nCVE-2022-3567, CVE-2022-3594, CVE-2022-3621, CVE-2022-42703,<br \/>\nCVE-2022-43945<\/p>\n<p dir=\"ltr\">Package Information:<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/linux\/5.15.0-56.62<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/linux-aws\/5.15.0-1026.30<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/linux-gcp\/5.15.0-1025.32<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/linux-gkeop\/5.15.0-1011.15<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/linux-ibm\/5.15.0-1021.24<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/linux-intel-iotg\/5.15.0-1021.26<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/linux-kvm\/5.15.0-1024.29<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/linux-lowlatency\/5.15.0-56.62<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/linux-oracle\/5.15.0-1025.31<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/linux-raspi\/5.15.0-1021.23<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/linux-aws-5.15\/5.15.0-1026.30~20.04.2<br \/>\nhttps:\/\/launchpad.net\/ubuntu\/+source\/linux-hwe-5.15\/5.15.0-56.62~20.04.1<\/p>\n<p dir=\"ltr\">https:\/\/launchpad.net\/ubuntu\/+source\/linux-lowlatency-hwe-5.15\/5.15.0-56.62~20.04.1<\/p>\n<p dir=\"ltr\">https:\/\/launchpad.net\/ubuntu\/+source\/linux-oracle-5.15\/5.15.0-1025.31~20.04.2<\/p>\n","protected":false},"excerpt":{"rendered":"<p>========================================================================== Ubuntu Security Notice USN-5755-1 December 01, 2022 linux, linux-aws, linux-aws-5.15, linux-gcp, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-intel-iotg, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-oracle, linux-oracle-5.15, linux-raspi vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: &#8211; Ubuntu 22.04 LTS &#8211; Ubuntu 20.04 LTS Summary: Several security issues were fixed in the Linux kernel. Software Description: &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-34341","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34341","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=34341"}],"version-history":[{"count":2,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34341\/revisions"}],"predecessor-version":[{"id":34373,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/34341\/revisions\/34373"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=34341"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=34341"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=34341"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}