{"id":45642,"date":"2023-07-26T21:10:21","date_gmt":"2023-07-26T17:10:21","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/173757\/LSN-0096-1.txt"},"modified":"2023-07-28T00:12:52","modified_gmt":"2023-07-27T19:42:52","slug":"kernel-live-patch-security-notice-lsn-0096-1-linux-kernel","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/kernel-live-patch-security-notice-lsn-0096-1-linux-kernel\/","title":{"rendered":"Kernel Live Patch Security Notice LSN-0096-1 Linux kernel"},"content":{"rendered":"<p>Linux kernel vulnerabilities<\/p>\n<p>A security issue affects these releases of Ubuntu and its derivatives:<\/p>\n<p>&#8211; Ubuntu 20.04 LTS<br \/>\n&#8211; Ubuntu 18.04 LTS<br \/>\n&#8211; Ubuntu 16.04 ESM<br \/>\n&#8211; Ubuntu 22.04 LTS<br \/>\n&#8211; Ubuntu 14.04 ESM<\/p>\n<p>Summary<\/p>\n<p>Several security issues were fixed in the kernel.<\/p>\n<p>Software Description<\/p>\n<p>&#8211; linux &#8211; Linux kernel<br \/>\n&#8211; linux-aws &#8211; Linux kernel for Amazon Web Services (AWS) systems<br \/>\n&#8211; linux-azure &#8211; Linux kernel for Microsoft Azure Cloud systems<br \/>\n&#8211; linux-gcp &#8211; Linux kernel for Google Cloud Platform (GCP) systems<br \/>\n&#8211; linux-gke &#8211; Linux kernel for Google Container Engine (GKE) systems<br \/>\n&#8211; linux-gkeop &#8211; Linux kernel for Google Container Engine (GKE) systems<br \/>\n&#8211; linux-ibm &#8211; Linux kernel for IBM cloud systems<\/p>\n<p>Details<\/p>\n<p>It was discovered that the Broadcom FullMAC USB WiFi driver in the Linux<br \/>\nkernel did not properly perform data buffer size validation in some<br \/>\nsituations. A physically proximate attacker could use this to craft a<br \/>\nmalicious USB device that when inserted, could cause a denial of service<br \/>\n(system crash) or possibly expose sensitive information. (CVE-2023-1380)<\/p>\n<p>Reima Ishii discovered that the nested KVM implementation for Intel x86<br \/>\nprocessors in the Linux kernel did not properly validate control<br \/>\nregisters in certain situations. An attacker in a guest VM could use<br \/>\nthis to cause a denial of service (guest crash). (CVE-2023-30456)<\/p>\n<p>Mingi Cho discovered that the netfilter subsystem in the Linux kernel<br \/>\ndid not properly validate the status of a nft chain while performing a<br \/>\nlookup by id, leading to a use-after-free vulnerability. An attacker<br \/>\ncould use this to cause a denial of service (system crash) or possibly<br \/>\nexecute arbitrary code. (CVE-2023-31248)<\/p>\n<p>Gwangun Jung discovered that the Quick Fair Queueing scheduler<br \/>\nimplementation in the Linux kernel contained an out-of-bounds write<br \/>\nvulnerability. A local attacker could use this to cause a denial of<br \/>\nservice (system crash) or possibly execute arbitrary code.<br \/>\n(CVE-2023-31436)<\/p>\n<p>Tanguy Dubroca discovered that the netfilter subsystem in the Linux<br \/>\nkernel did not properly handle certain pointer data type, leading to an<br \/>\nout-of- bounds write vulnerability. A privileged attacker could use this<br \/>\nto cause a denial of service (system crash) or possibly execute<br \/>\narbitrary code. (CVE-2023-35001)<\/p>\n<p>Update instructions<\/p>\n<p>The problem can be corrected by updating your kernel livepatch to the<br \/>\nfollowing versions:<\/p>\n<p>Ubuntu 20.04 LTS<br \/>\naws &#8211; 96.2<br \/>\nazure &#8211; 96.2<br \/>\ngcp &#8211; 96.2<br \/>\ngcp &#8211; 96.3<br \/>\ngeneric &#8211; 96.2<br \/>\ngeneric &#8211; 96.3<br \/>\ngke &#8211; 96.2<br \/>\ngke &#8211; 96.3<br \/>\ngkeop &#8211; 96.2<br \/>\nibm &#8211; 96.2<br \/>\nlowlatency &#8211; 96.2<br \/>\nlowlatency &#8211; 96.3<\/p>\n<p>Ubuntu 18.04 LTS<br \/>\nazure &#8211; 96.2<br \/>\ngcp &#8211; 96.2<br \/>\ngeneric &#8211; 96.2<br \/>\ngke &#8211; 96.2<br \/>\ngkeop &#8211; 96.2<br \/>\nibm &#8211; 96.2<br \/>\nlowlatency &#8211; 96.2<\/p>\n<p>Ubuntu 16.04 ESM<br \/>\naws &#8211; 96.2<br \/>\nazure &#8211; 96.2<br \/>\ngcp &#8211; 96.2<br \/>\ngeneric &#8211; 96.2<br \/>\nlowlatency &#8211; 96.2<\/p>\n<p>Ubuntu 22.04 LTS<br \/>\nazure &#8211; 96.2<br \/>\nazure &#8211; 96.3<br \/>\ngcp &#8211; 96.2<br \/>\ngcp &#8211; 96.3<br \/>\ngeneric &#8211; 96.2<br \/>\ngeneric &#8211; 96.3<br \/>\ngke &#8211; 96.2<br \/>\ngke &#8211; 96.3<br \/>\nibm &#8211; 96.2<br \/>\nibm &#8211; 96.3<\/p>\n<p>Ubuntu 14.04 ESM<br \/>\ngeneric &#8211; 96.2<br \/>\nlowlatency &#8211; 96.2<\/p>\n<p>Support Information<\/p>\n<p>Livepatches for supported LTS kernels will receive upgrades for a period<br \/>\nof up to 13 months after the build date of the kernel.<\/p>\n<p>Livepatches for supported HWE kernels which are not based on an LTS<br \/>\nkernel version will receive upgrades for a period of up to 9 months<br \/>\nafter the build date of the kernel, or until the end of support for that<br \/>\nkernel\u2019s non-LTS distro release version, whichever is sooner.<\/p>\n<p>References<\/p>\n<p>&#8211; CVE-2023-1380<br \/>\n&#8211; CVE-2023-30456<br \/>\n&#8211; CVE-2023-31248<br \/>\n&#8211; CVE-2023-31436<br \/>\n&#8211; CVE-2023-35001<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Linux kernel vulnerabilities A security issue affects these releases of Ubuntu and its derivatives: &#8211; Ubuntu 20.04 LTS &#8211; Ubuntu 18.04 LTS &#8211; Ubuntu 16.04 ESM &#8211; Ubuntu 22.04 LTS &#8211; Ubuntu 14.04 ESM Summary Several security issues were fixed in the kernel. Software Description &#8211; linux &#8211; Linux kernel &#8211; linux-aws &#8211; Linux kernel &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-45642","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45642","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=45642"}],"version-history":[{"count":1,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45642\/revisions"}],"predecessor-version":[{"id":45697,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/45642\/revisions\/45697"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=45642"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=45642"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=45642"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}