Description: | Summary: The remote host is missing an update for the 'linux-aws, linux-aws-6.8, linux-oracle, linux-oracle-6.8' package(s) announced via the USN-7089-3 advisory.
Vulnerability Insight: Chenyuan Yang discovered that the USB Gadget subsystem in the Linux kernel did not properly check for the device to be enabled before writing. A local attacker could possibly use this to cause a denial of service. (CVE-2024-25741)
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture, - MIPS architecture, - PA-RISC architecture, - PowerPC architecture, - RISC-V architecture, - S390 architecture, - x86 architecture, - Cryptographic API, - Serial ATA and Parallel ATA drivers, - Null block device driver, - Bluetooth drivers, - Cdrom driver, - Clock framework and drivers, - Hardware crypto device drivers, - CXL (Compute Express Link) drivers, - Cirrus firmware drivers, - GPIO subsystem, - GPU drivers, - I2C subsystem, - IIO subsystem, - InfiniBand drivers, - ISDN/mISDN subsystem, - LED subsystem, - Multiple devices driver, - Media drivers, - Fastrpc Driver, - Network drivers, - Microsoft Azure Network Adapter (MANA) driver, - Near Field Communication (NFC) drivers, - NVME drivers, - NVMEM (Non Volatile Memory) drivers, - PCI subsystem, - Pin controllers subsystem, - x86 platform drivers, - S/390 drivers, - SCSI drivers, - Thermal drivers, - TTY drivers, - UFS subsystem, - USB DSL drivers, - USB core drivers, - DesignWare USB3 driver, - USB Gadget drivers, - USB Serial drivers, - VFIO drivers, - VHOST drivers, - File systems infrastructure, - BTRFS file system, - GFS2 file system, - JFFS2 file system, - JFS file system, - Network file systems library, - Network file system client, - NILFS2 file system, - NTFS3 file system, - SMB network file system, - Memory management, - Netfilter, - Tracing infrastructure, - io_uring subsystem, - BPF subsystem, - Core kernel, - Bluetooth subsystem, - CAN network layer, - Ceph Core library, - Networking core, - IPv4 networking, - IPv6 networking, - IUCV driver, - MAC80211 subsystem, - Network traffic control, - Sun RPC protocol, - Wireless networking, - AMD SoC Alsa drivers, - SoC Audio for Freescale CPUs drivers, - MediaTek ASoC drivers, - SoC audio core drivers, - SOF drivers, - Sound sequencer drivers, (CVE-2024-42239, CVE-2024-42079, CVE-2024-41080, CVE-2024-42064, CVE-2024-42127, CVE-2024-41049, CVE-2024-41086, CVE-2024-42142, CVE-2024-42244, CVE-2024-41060, CVE-2024-42131, CVE-2024-42085, CVE-2024-42246, CVE-2024-41062, CVE-2024-42115, CVE-2024-42234, CVE-2024-42080, CVE-2024-41095, CVE-2024-41063, CVE-2024-42227, CVE-2024-41089, CVE-2024-42133, CVE-2024-43858, CVE-2024-42135, CVE-2024-42113, CVE-2024-42120, CVE-2024-42149, CVE-2024-42132, CVE-2024-41038, CVE-2024-41069, CVE-2024-41090, CVE-2024-41059, CVE-2024-41028, CVE-2024-42126, CVE-2024-42121, CVE-2024-42155, CVE-2024-42110, CVE-2024-41021, CVE-2024-41044, ... [Please see the references for more information on the vulnerabilities]
Affected Software/OS: 'linux-aws, linux-aws-6.8, linux-oracle, linux-oracle-6.8' package(s) on Ubuntu 22.04, Ubuntu 24.04.
Solution: Please install the updated package(s).
CVSS Score: 6.8
CVSS Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C
|