![]() |
Home ▼ Bookkeeping
Online ▼ Security
Audits ▼
Managed
DNS ▼
About
Order
FAQ
Acceptable Use Policy
Dynamic DNS Clients
Configure Domains Dyanmic DNS Update Password Network
Monitor ▼
Enterprise Package
Advanced Package
Standard Package
Free Trial
FAQ
Price/Feature Summary
Order/Renew
Examples
Configure/Status Alert Profiles | ||
Test ID: | 1.3.6.1.4.1.25623.1.0.845461 |
Category: | Ubuntu Local Security Checks |
Title: | Ubuntu: Security Advisory (USN-5544-1) |
Summary: | The remote host is missing an update for the 'linux, linux-hwe-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15' package(s) announced via the USN-5544-1 advisory. |
Description: | Summary: The remote host is missing an update for the 'linux, linux-hwe-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15' package(s) announced via the USN-5544-1 advisory. Vulnerability Insight: It was discovered that the Atheros ath9k wireless device driver in the Linux kernel did not properly handle some error conditions, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-1679) Felix Fu discovered that the Sun RPC implementation in the Linux kernel did not properly handle socket states, leading to a use-after-free vulnerability. A remote attacker could possibly use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-28893) Arthur Mongodin discovered that the netfilter subsystem in the Linux kernel did not properly perform data validation. A local attacker could use this to escalate privileges in certain situations. (CVE-2022-34918) Minh Yuan discovered that the floppy disk driver in the Linux kernel contained a race condition, leading to a use-after-free vulnerability. A local attacker could possibly use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-1652) Affected Software/OS: 'linux, linux-hwe-5.15, linux-lowlatency, linux-lowlatency-hwe-5.15' package(s) on Ubuntu 20.04, Ubuntu 22.04. Solution: Please install the updated package(s). CVSS Score: 7.2 CVSS Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C |
Cross-Ref: |
Common Vulnerability Exposure (CVE) ID: CVE-2022-1652 Debian Security Information: DSA-5173 (Google Search) https://www.debian.org/security/2022/dsa-5173 https://bugzilla.redhat.com/show_bug.cgi?id=1832397 https://francozappa.github.io/about-bias/ https://kb.cert.org/vuls/id/647177/ Common Vulnerability Exposure (CVE) ID: CVE-2022-1679 https://lore.kernel.org/lkml/87ilqc7jv9.fsf@kernel.org/t/ https://lists.debian.org/debian-lts-announce/2022/10/msg00000.html https://lists.debian.org/debian-lts-announce/2022/11/msg00001.html Common Vulnerability Exposure (CVE) ID: CVE-2022-28893 Debian Security Information: DSA-5161 (Google Search) https://www.debian.org/security/2022/dsa-5161 https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=1a3b1bba7c7a5eb8a11513cf88427cb9d77bc60a http://www.openwall.com/lists/oss-security/2022/04/11/3 http://www.openwall.com/lists/oss-security/2022/04/11/4 http://www.openwall.com/lists/oss-security/2022/04/11/5 Common Vulnerability Exposure (CVE) ID: CVE-2022-34918 Debian Security Information: DSA-5191 (Google Search) https://www.debian.org/security/2022/dsa-5191 http://packetstormsecurity.com/files/168191/Kernel-Live-Patch-Security-Notice-LSN-0089-1.html http://packetstormsecurity.com/files/168543/Netfilter-nft_set_elem_init-Heap-Overflow-Privilege-Escalation.html https://git.kernel.org/pub/scm/linux/kernel/git/netdev/net.git/commit/?id=7e6bc1f6cabcd30aba0b11219d8e01b952eacbb6 https://lore.kernel.org/netfilter-devel/cd9428b6-7ffb-dd22-d949-d86f4869f452@randorisec.fr/T/#u https://www.openwall.com/lists/oss-security/2022/07/02/3 https://www.randorisec.fr/crack-linux-firewall/ http://www.openwall.com/lists/oss-security/2022/07/05/1 http://www.openwall.com/lists/oss-security/2022/08/06/5 |
Copyright | Copyright (C) 2022 Greenbone AG |
This is only one of 146377 vulnerability tests in our test suite. Find out more about running a complete security audit. To run a free test of this vulnerability against your system, register below. |