{"id":40331,"date":"2023-04-12T22:33:56","date_gmt":"2023-04-12T18:33:56","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/171864\/USN-6013-1.txt"},"modified":"2023-04-16T15:07:52","modified_gmt":"2023-04-16T10:37:52","slug":"ubuntu-security-notice-usn-6013-1-linux-kernel","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/ubuntu-security-notice-usn-6013-1-linux-kernel\/","title":{"rendered":"Ubuntu Security Notice USN-6013-1 Linux kernel"},"content":{"rendered":"<p>==========================================================================<br \/>\nUbuntu Security Notice USN-6013-1<br \/>\nApril 12, 2023<\/p>\n<p>linux-aws vulnerabilities<br \/>\n==========================================================================<\/p>\n<p>A security issue affects these releases of Ubuntu and its derivatives:<\/p>\n<p>&#8211; Ubuntu 14.04 ESM<\/p>\n<p>Summary:<\/p>\n<p>Several security issues were fixed in the Linux kernel.<\/p>\n<p>Software Description:<br \/>\n&#8211; linux-aws: Linux kernel for Amazon Web Services (AWS) systems<\/p>\n<p>Details:<\/p>\n<p>Xuewei Feng, Chuanpu Fu, Qi Li, Kun Sun, and Ke Xu discovered that the TCP<br \/>\nimplementation in the Linux kernel did not properly handle IPID assignment.<br \/>\nA remote attacker could use this to cause a denial of service (connection<br \/>\ntermination) or inject forged data. (CVE-2020-36516)<\/p>\n<p>Ke Sun, Alyssa Milburn, Henrique Kawakami, Emma Benoit, Igor Chervatyuk,<br \/>\nLisa Aichele, and Thais Moreira Hamasaki discovered that the Spectre<br \/>\nVariant 2 mitigations for AMD processors on Linux were insufficient in some<br \/>\nsituations. A local attacker could possibly use this to expose sensitive<br \/>\ninformation. (CVE-2021-26401)<\/p>\n<p>J\u00fcrgen Gro\u00df discovered that the Xen subsystem within the Linux kernel did<br \/>\nnot adequately limit the number of events driver domains (unprivileged PV<br \/>\nbackends) could send to other guest VMs. An attacker in a driver domain<br \/>\ncould use this to cause a denial of service in other guest VMs.<br \/>\n(CVE-2021-28712, CVE-2021-28713)<\/p>\n<p>Wolfgang Frisch discovered that the ext4 file system implementation in the<br \/>\nLinux kernel contained an integer overflow when handling metadata inode<br \/>\nextents. An attacker could use this to construct a malicious ext4 file<br \/>\nsystem image that, when mounted, could cause a denial of service (system<br \/>\ncrash). (CVE-2021-3428)<\/p>\n<p>It was discovered that the IEEE 802.15.4 wireless network subsystem in the<br \/>\nLinux kernel did not properly handle certain error conditions, leading to a<br \/>\nnull pointer dereference vulnerability. A local attacker could possibly use<br \/>\nthis to cause a denial of service (system crash). (CVE-2021-3659)<\/p>\n<p>It was discovered that the System V IPC implementation in the Linux kernel<br \/>\ndid not properly handle large shared memory counts. A local attacker could<br \/>\nuse this to cause a denial of service (memory exhaustion). (CVE-2021-3669)<\/p>\n<p>Alois Wohlschlager discovered that the overlay file system in the Linux<br \/>\nkernel did not restrict private clones in some situations. An attacker<br \/>\ncould use this to expose sensitive information. (CVE-2021-3732)<\/p>\n<p>It was discovered that the SCTP protocol implementation in the Linux kernel<br \/>\ndid not properly verify VTAGs in some situations. A remote attacker could<br \/>\npossibly use this to cause a denial of service (connection disassociation).<br \/>\n(CVE-2021-3772)<\/p>\n<p>It was discovered that the btrfs file system implementation in the Linux<br \/>\nkernel did not properly handle locking in certain error conditions. A local<br \/>\nattacker could use this to cause a denial of service (kernel deadlock).<br \/>\n(CVE-2021-4149)<\/p>\n<p>Jann Horn discovered that the socket subsystem in the Linux kernel<br \/>\ncontained a race condition when handling listen() and connect() operations,<br \/>\nleading to a read-after-free vulnerability. A local attacker could use this<br \/>\nto cause a denial of service (system crash) or possibly expose sensitive<br \/>\ninformation. (CVE-2021-4203)<\/p>\n<p>It was discovered that the file system quotas implementation in the Linux<br \/>\nkernel did not properly validate the quota block number. An attacker could<br \/>\nuse this to construct a malicious file system image that, when mounted and<br \/>\noperated on, could cause a denial of service (system crash).<br \/>\n(CVE-2021-45868)<\/p>\n<p>Zhihua Yao discovered that the MOXART SD\/MMC driver in the Linux kernel did<br \/>\nnot properly handle device removal, leading to a use-after-free<br \/>\nvulnerability. A physically proximate attacker could possibly use this to<br \/>\ncause a denial of service (system crash). (CVE-2022-0487)<\/p>\n<p>It was discovered that the block layer subsystem in the Linux kernel did<br \/>\nnot properly initialize memory in some situations. A privileged local<br \/>\nattacker could use this to expose sensitive information (kernel memory).<br \/>\n(CVE-2022-0494)<\/p>\n<p>It was discovered that the UDF file system implementation in the Linux<br \/>\nkernel could attempt to dereference a null pointer in some situations. An<br \/>\nattacker could use this to construct a malicious UDF image that, when<br \/>\nmounted and operated on, could cause a denial of service (system crash).<br \/>\n(CVE-2022-0617)<\/p>\n<p>David Bouman discovered that the netfilter subsystem in the Linux kernel<br \/>\ndid not initialize memory in some situations. A local attacker could use<br \/>\nthis to expose sensitive information (kernel memory). (CVE-2022-1016)<\/p>\n<p>It was discovered that the implementation of the 6pack and mkiss protocols<br \/>\nin the Linux kernel did not handle detach events properly in some<br \/>\nsituations, leading to a use-after-free vulnerability. A local attacker<br \/>\ncould possibly use this to cause a denial of service (system crash).<br \/>\n(CVE-2022-1195)<\/p>\n<p>Duoming Zhou discovered race conditions in the AX.25 amateur radio protocol<br \/>\nimplementation in the Linux kernel, leading to use-after-free<br \/>\nvulnerabilities. A local attacker could possibly use this to cause a denial<br \/>\nof service (system crash). (CVE-2022-1205)<\/p>\n<p>It was discovered that the tty subsystem in the Linux kernel contained a<br \/>\nrace condition in certain situations, leading to an out-of-bounds read<br \/>\nvulnerability. A local attacker could possibly use this to cause a denial<br \/>\nof service (system crash) or expose sensitive information. (CVE-2022-1462)<\/p>\n<p>It was discovered that the implementation of X.25 network protocols in the<br \/>\nLinux kernel did not terminate link layer sessions properly. A local<br \/>\nattacker could possibly use this to cause a denial of service (system<br \/>\ncrash). (CVE-2022-1516)<\/p>\n<p>Duoming Zhou discovered a race condition in the NFC subsystem in the Linux<br \/>\nkernel, leading to a use-after-free vulnerability. A privileged local<br \/>\nattacker could use this to cause a denial of service (system crash) or<br \/>\npossibly execute arbitrary code. (CVE-2022-1974)<\/p>\n<p>Duoming Zhou discovered that the NFC subsystem in the Linux kernel did not<br \/>\nproperly prevent context switches from occurring during certain atomic<br \/>\ncontext operations. A privileged local attacker could use this to cause a<br \/>\ndenial of service (system crash). (CVE-2022-1975)<\/p>\n<p>It was discovered that the HID subsystem in the Linux kernel did not<br \/>\nproperly validate inputs in certain conditions. A local attacker with<br \/>\nphysical access could plug in a specially crafted USB device to expose<br \/>\nsensitive information. (CVE-2022-20132)<\/p>\n<p>It was discovered that the device-mapper verity (dm-verity) driver in the<br \/>\nLinux kernel did not properly verify targets being loaded into the device-<br \/>\nmapper table. A privileged attacker could use this to cause a denial of<br \/>\nservice (system crash) or possibly execute arbitrary code. (CVE-2022-20572,<br \/>\nCVE-2022-2503)<\/p>\n<p>Duoming Zhou discovered that race conditions existed in the timer handling<br \/>\nimplementation of the Linux kernel&#8217;s Rose X.25 protocol layer, resulting in<br \/>\nuse-after-free vulnerabilities. A local attacker could use this to cause a<br \/>\ndenial of service (system crash). (CVE-2022-2318)<\/p>\n<p>Zheyu Ma discovered that the Silicon Motion SM712 framebuffer driver in the<br \/>\nLinux kernel did not properly handle very small reads. A local attacker<br \/>\ncould use this to cause a denial of service (system crash). (CVE-2022-2380)<\/p>\n<p>David Leadbeater discovered that the netfilter IRC protocol tracking<br \/>\nimplementation in the Linux Kernel incorrectly handled certain message<br \/>\npayloads in some situations. A remote attacker could possibly use this to<br \/>\ncause a denial of service or bypass firewall filtering. (CVE-2022-2663)<\/p>\n<p>Lucas Leong discovered that the LightNVM subsystem in the Linux kernel did<br \/>\nnot properly handle data lengths in certain situations. A privileged<br \/>\nattacker could use this to cause a denial of service (system crash) or<br \/>\npossibly execute arbitrary code. (CVE-2022-2991)<\/p>\n<p>It was discovered that the Intel 740 frame buffer driver in the Linux<br \/>\nkernel contained a divide by zero vulnerability. A local attacker could use<br \/>\nthis to cause a denial of service (system crash). (CVE-2022-3061)<\/p>\n<p>Jiasheng Jiang discovered that the wm8350 charger driver in the Linux<br \/>\nkernel did not properly deallocate memory, leading to a null pointer<br \/>\ndereference vulnerability. A local attacker could use this to cause a<br \/>\ndenial of service (system crash). (CVE-2022-3111)<\/p>\n<p>It was discovered that the sound subsystem in the Linux kernel contained a<br \/>\nrace condition in some situations. A local attacker could use this to cause<br \/>\na denial of service (system crash). (CVE-2022-3303)<\/p>\n<p>It was discovered that the Broadcom FullMAC USB WiFi driver in the Linux<br \/>\nkernel did not properly perform bounds checking in some situations. A<br \/>\nphysically proximate attacker could use this to craft a malicious USB<br \/>\ndevice that when inserted, could cause a denial of service (system crash)<br \/>\nor possibly execute arbitrary code. (CVE-2022-3628)<\/p>\n<p>Ziming Zhang discovered that the VMware Virtual GPU DRM driver in the Linux<br \/>\nkernel contained an out-of-bounds write vulnerability. A local attacker<br \/>\ncould use this to cause a denial of service (system crash).<br \/>\n(CVE-2022-36280)<\/p>\n<p>It was discovered that the NILFS2 file system implementation in the Linux<br \/>\nkernel did not properly deallocate memory in certain error conditions. An<br \/>\nattacker could use this to cause a denial of service (memory exhaustion).<br \/>\n(CVE-2022-3646)<\/p>\n<p>It was discovered that the Netlink Transformation (XFRM) subsystem in the<br \/>\nLinux kernel contained a reference counting error. A local attacker could<br \/>\nuse this to cause a denial of service (system crash). (CVE-2022-36879)<\/p>\n<p>It was discovered that the infrared transceiver USB driver did not properly<br \/>\nhandle USB control messages. A local attacker with physical access could<br \/>\nplug in a specially crafted USB device to cause a denial of service (memory<br \/>\nexhaustion). (CVE-2022-3903)<\/p>\n<p>Jann Horn discovered a race condition existed in the Linux kernel when<br \/>\nunmapping VMAs in certain situations, resulting in possible use-after-free<br \/>\nvulnerabilities. A local attacker could possibly use this to cause a denial<br \/>\nof service (system crash) or execute arbitrary code. (CVE-2022-39188)<\/p>\n<p>Hyunwoo Kim discovered that the DVB Core driver in the Linux kernel did not<br \/>\nproperly perform reference counting in some situations, leading to a use-<br \/>\nafter-free vulnerability. A local attacker could use this to cause a denial<br \/>\nof service (system crash) or possibly execute arbitrary code.<br \/>\n(CVE-2022-41218)<\/p>\n<p>It was discovered that a race condition existed in the SMSC UFX USB driver<br \/>\nimplementation in the Linux kernel, leading to a use-after-free<br \/>\nvulnerability. A physically proximate attacker could use this to cause a<br \/>\ndenial of service (system crash) or possibly execute arbitrary code.<br \/>\n(CVE-2022-41849)<\/p>\n<p>It was discovered that a race condition existed in the Roccat HID driver in<br \/>\nthe Linux kernel, leading to a use-after-free vulnerability. A local<br \/>\nattacker could use this to cause a denial of service (system crash) or<br \/>\npossibly execute arbitrary code. (CVE-2022-41850)<\/p>\n<p>It was discovered that the USB core subsystem in the Linux kernel did not<br \/>\nproperly handle nested reset events. A local attacker with physical access<br \/>\ncould plug in a specially crafted USB device to cause a denial of service<br \/>\n(kernel deadlock). (CVE-2022-4662)<\/p>\n<p>It was discovered that the network queuing discipline implementation in the<br \/>\nLinux kernel contained a null pointer dereference in some situations. A<br \/>\nlocal attacker could use this to cause a denial of service (system crash).<br \/>\n(CVE-2022-47929)<\/p>\n<p>Kyle Zeng discovered that the IPv6 implementation in the Linux kernel<br \/>\ncontained a NULL pointer dereference vulnerability in certain situations. A<br \/>\nlocal attacker could use this to cause a denial of service (system crash).<br \/>\n(CVE-2023-0394)<\/p>\n<p>It was discovered that a memory leak existed in the SCTP protocol<br \/>\nimplementation in the Linux kernel. A local attacker could use this to<br \/>\ncause a denial of service (memory exhaustion). (CVE-2023-1074)<\/p>\n<p>Mingi Cho discovered that the netfilter subsystem in the Linux kernel did<br \/>\nnot properly initialize a data structure, leading to a null pointer<br \/>\ndereference vulnerability. An attacker could use this to cause a denial of<br \/>\nservice (system crash). (CVE-2023-1095)<\/p>\n<p>Kyle Zeng discovered that the ATM VC queuing discipline implementation in<br \/>\nthe Linux kernel contained a type confusion vulnerability in some<br \/>\nsituations. An attacker could use this to cause a denial of service (system<br \/>\ncrash). (CVE-2023-23455)<\/p>\n<p>Lianhui Tang discovered that the MPLS implementation in the Linux kernel<br \/>\ndid not properly handle certain sysctl allocation failure conditions,<br \/>\nleading to a double-free vulnerability. An attacker could use this to cause<br \/>\na denial of service or possibly execute arbitrary code. (CVE-2023-26545)<\/p>\n<p>It was discovered that the NTFS file system implementation in the Linux<br \/>\nkernel did not properly validate attributes in certain situations, leading<br \/>\nto an out-of-bounds read vulnerability. A local attacker could possibly use<br \/>\nthis to expose sensitive information (kernel memory). (CVE-2023-26607)<\/p>\n<p>Duoming Zhou discovered that a race condition existed in the infrared<br \/>\nreceiver\/transceiver driver in the Linux kernel, leading to a use-after-<br \/>\nfree vulnerability. A privileged attacker could use this to cause a denial<br \/>\nof service (system crash) or possibly execute arbitrary code.<br \/>\n(CVE-2023-1118)<\/p>\n<p>Update instructions:<\/p>\n<p>The problem can be corrected by updating your system to the following<br \/>\npackage versions:<\/p>\n<p>Ubuntu 14.04 ESM:<br \/>\nlinux-image-4.4.0-1117-aws 4.4.0-1117.123<br \/>\nlinux-image-aws 4.4.0.1117.114<\/p>\n<p>After a standard system update you need to reboot your computer to make<br \/>\nall the necessary changes.<\/p>\n<p>ATTENTION: Due to an unavoidable ABI change the kernel updates have<br \/>\nbeen given a new version number, which requires you to recompile and<br \/>\nreinstall all third party kernel modules you might have installed.<br \/>\nUnless you manually uninstalled the standard kernel metapackages<br \/>\n(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,<br \/>\nlinux-powerpc), a standard system upgrade will automatically perform<br \/>\nthis as well.<\/p>\n<p>References:<br \/>\nhttps:\/\/ubuntu.com\/security\/notices\/USN-6013-1<br \/>\nCVE-2020-36516, CVE-2021-26401, CVE-2021-28712, CVE-2021-28713,<br \/>\nCVE-2021-3428, CVE-2021-3659, CVE-2021-3669, CVE-2021-3732,<br \/>\nCVE-2021-3772, CVE-2021-4149, CVE-2021-4203, CVE-2021-45868,<br \/>\nCVE-2022-0487, CVE-2022-0494, CVE-2022-0617, CVE-2022-1016,<br \/>\nCVE-2022-1195, CVE-2022-1205, CVE-2022-1462, CVE-2022-1516,<br \/>\nCVE-2022-1974, CVE-2022-1975, CVE-2022-20132, CVE-2022-20572,<br \/>\nCVE-2022-2318, CVE-2022-2380, CVE-2022-2503, CVE-2022-2663,<br \/>\nCVE-2022-2991, CVE-2022-3061, CVE-2022-3111, CVE-2022-3303,<br \/>\nCVE-2022-3628, CVE-2022-36280, CVE-2022-3646, CVE-2022-36879,<br \/>\nCVE-2022-3903, CVE-2022-39188, CVE-2022-41218, CVE-2022-41849,<br \/>\nCVE-2022-41850, CVE-2022-4662, CVE-2022-47929, CVE-2023-0394,<br \/>\nCVE-2023-1074, CVE-2023-1095, CVE-2023-1118, CVE-2023-23455,<br \/>\nCVE-2023-26545, CVE-2023-26607<\/p>\n","protected":false},"excerpt":{"rendered":"<p>========================================================================== Ubuntu Security Notice USN-6013-1 April 12, 2023 linux-aws vulnerabilities ========================================================================== A security issue affects these releases of Ubuntu and its derivatives: &#8211; Ubuntu 14.04 ESM Summary: Several security issues were fixed in the Linux kernel. Software Description: &#8211; linux-aws: Linux kernel for Amazon Web Services (AWS) systems Details: Xuewei Feng, Chuanpu Fu, Qi Li, &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-40331","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/40331","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=40331"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/40331\/revisions"}],"predecessor-version":[{"id":40408,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/40331\/revisions\/40408"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=40331"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=40331"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=40331"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}