Description: | Summary: The remote host is missing an update for the 'linux-ibm-5.15, linux-oracle-5.15' package(s) announced via the USN-7007-2 advisory.
Vulnerability Insight: Chenyuan Yang discovered that the CEC driver driver in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2024-23848)
Chenyuan Yang discovered that the USB Gadget subsystem in the Linux kernel did not properly check for the device to be enabled before writing. A local attacker could possibly use this to cause a denial of service. (CVE-2024-25741)
It was discovered that the JFS file system contained an out-of-bounds read vulnerability when printing xattr debug information. A local attacker could use this to cause a denial of service (system crash). (CVE-2024-40902)
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM64 architecture, - M68K architecture, - MIPS architecture, - PowerPC architecture, - RISC-V architecture, - x86 architecture, - Block layer subsystem, - Cryptographic API, - Accessibility subsystem, - ACPI drivers, - Serial ATA and Parallel ATA drivers, - Drivers core, - Bluetooth drivers, - Character device driver, - CPU frequency scaling framework, - Hardware crypto device drivers, - Buffer Sharing and Synchronization framework, - DMA engine subsystem, - FPGA Framework, - GPIO subsystem, - GPU drivers, - Greybus drivers, - HID subsystem, - HW tracing, - I2C subsystem, - IIO subsystem, - InfiniBand drivers, - Input Device (Mouse) drivers, - Macintosh device drivers, - Multiple devices driver, - Media drivers, - VMware VMCI Driver, - Network drivers, - Near Field Communication (NFC) drivers, - NVME drivers, - Pin controllers subsystem, - PTP clock framework, - S/390 drivers, - SCSI drivers, - SoundWire subsystem, - Greybus lights staging drivers, - Media staging drivers, - Thermal drivers, - TTY drivers, - USB subsystem, - DesignWare USB3 driver, - Framebuffer layer, - ACRN Hypervisor Service Module driver, - eCrypt file system, - File systems infrastructure, - Ext4 file system, - F2FS file system, - JFFS2 file system, - JFS file system, - NILFS2 file system, - NTFS3 file system, - SMB network file system, - IOMMU subsystem, - Memory management, - Netfilter, - BPF subsystem, - Kernel debugger infrastructure, - DMA mapping infrastructure, - IRQ subsystem, - Tracing infrastructure, - 9P file system network protocol, - B.A.T.M.A.N. meshing protocol, - CAN network layer, - Ceph Core library, - Networking core, - IPv4 networking, - IPv6 networking, - IUCV driver, - MAC80211 subsystem, - Multipath TCP, - NET/ROM layer, - NFC subsystem, - Open vSwitch, - Network traffic control, - TIPC protocol, - TLS protocol, - Unix domain sockets, - Wireless networking, - XFRM subsystem, - ALSA framework, - SoC Audio for Freescale CPUs ... [Please see the references for more information on the vulnerabilities]
Affected Software/OS: 'linux-ibm-5.15, linux-oracle-5.15' package(s) on Ubuntu 20.04.
Solution: Please install the updated package(s).
CVSS Score: 6.8
CVSS Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C
|