Description: | Summary: The remote host is missing an update for the 'linux-oem-6.5' package(s) announced via the USN-6765-1 advisory.
Vulnerability Insight: Alon Zahavi discovered that the NVMe-oF/TCP subsystem in the Linux kernel did not properly validate H2C PDU data, leading to a null pointer dereference vulnerability. A remote attacker could use this to cause a denial of service (system crash). (CVE-2023-6356, CVE-2023-6535, CVE-2023-6536)
Sander Wiebing, Alvise de Faveri Tron, Herbert Bos, and Cristiano Giuffrida discovered that the Linux kernel mitigations for the initial Branch History Injection vulnerability (CVE-2022-0001) were insufficient for Intel processors. A local attacker could potentially use this to expose sensitive information. (CVE-2024-2201)
Chenyuan Yang discovered that the RDS Protocol implementation in the Linux kernel contained an out-of-bounds read vulnerability. An attacker could use this to possibly cause a denial of service (system crash). (CVE-2024-23849)
It was discovered that a race condition existed in the Bluetooth subsystem in the Linux kernel, leading to a null pointer dereference vulnerability. A privileged local attacker could use this to possibly cause a denial of service (system crash). (CVE-2024-24860)
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture, - PowerPC architecture, - S390 architecture, - Core kernel, - x86 architecture, - Block layer subsystem, - Cryptographic API, - Android drivers, - Drivers core, - Power management core, - Bus devices, - Hardware random number generator core, - Device frequency, - DMA engine subsystem, - EDAC drivers, - ARM SCMI message protocol, - GPU drivers, - IIO ADC drivers, - InfiniBand drivers, - IOMMU subsystem, - Media drivers, - Multifunction device drivers, - MTD block device drivers, - Network drivers, - NVME drivers, - PCI driver for MicroSemi Switchtec, - x86 platform drivers, - Power supply drivers, - SCSI drivers, - QCOM SoC drivers, - SPMI drivers, - Thermal drivers, - TTY drivers, - VFIO drivers, - BTRFS file system, - Ceph distributed file system, - EFI Variable file system, - EROFS file system, - Ext4 file system, - F2FS file system, - GFS2 file system, - JFS file system, - Network file systems library, - Network file system server daemon, - Pstore file system, - ReiserFS file system, - SMB network file system, - BPF subsystem, - Memory management, - TLS protocol, - Networking core, - IPv4 networking, - IPv6 networking, - Logical Link layer, - Netfilter, - Network traffic control, - SMC sockets, - Sun RPC protocol, - AppArmor security module, (CVE-2023-52635, CVE-2024-26632, CVE-2023-52468, CVE-2023-52472, CVE-2023-52589, CVE-2024-26671, CVE-2024-26640, CVE-2024-26631, CVE-2023-52489, CVE-2023-52616, CVE-2023-52445, CVE-2023-52463, CVE-2024-26610, CVE-2023-52497, CVE-2023-52453, CVE-2023-52470, CVE-2024-26649, ... [Please see the references for more information on the vulnerabilities]
Affected Software/OS: 'linux-oem-6.5' package(s) on Ubuntu 22.04.
Solution: Please install the updated package(s).
CVSS Score: 6.8
CVSS Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C
|