Description: | Summary: The remote host is missing an update for the 'linux, linux-aws, linux-kvm, linux-lts-xenial' package(s) announced via the USN-6976-1 advisory.
Vulnerability Insight: Yuxuan Hu discovered that the Bluetooth RFCOMM protocol driver in the Linux Kernel contained a race condition, leading to a NULL pointer dereference. An attacker could possibly use this to cause a denial of service (system crash). (CVE-2024-22099)
It was discovered that a race condition existed in the Bluetooth subsystem in the Linux kernel, leading to a null pointer dereference vulnerability. A privileged local attacker could use this to possibly cause a denial of service (system crash). (CVE-2024-24860)
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - SuperH RISC architecture, - User-Mode Linux (UML), - GPU drivers, - HID subsystem, - MMC subsystem, - Network drivers, - PHY drivers, - SCSI drivers, - USB subsystem, - Xen hypervisor drivers, - GFS2 file system, - Memory management, - Bluetooth subsystem, - IPv4 networking, - IPv6 networking, - NFC subsystem, - HD-audio driver, - ALSA SH drivers, (CVE-2023-52806, CVE-2021-46924, CVE-2021-47521, CVE-2021-47542, CVE-2024-26903, CVE-2024-26654, CVE-2024-27013, CVE-2024-26600, CVE-2021-47518, CVE-2021-47171, CVE-2023-52629, CVE-2023-52644, CVE-2021-46904, CVE-2023-52470, CVE-2024-36901, CVE-2021-46906, CVE-2024-39292, CVE-2022-48659, CVE-2021-47173, CVE-2021-47571, CVE-2024-26929, CVE-2024-39484, CVE-2024-26687, CVE-2024-26679, CVE-2023-52760)
Affected Software/OS: 'linux, linux-aws, linux-kvm, linux-lts-xenial' package(s) on Ubuntu 14.04, Ubuntu 16.04.
Solution: Please install the updated package(s).
CVSS Score: 6.8
CVSS Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C
|