Description: | Summary: The remote host is missing an update for the 'linux-azure-5.15' package(s) announced via the USN-7194-1 advisory.
Vulnerability Insight: Andy Nguyen discovered that the Bluetooth L2CAP implementation in the Linux kernel contained a type-confusion error. A physically proximate remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-12351)
Andy Nguyen discovered that the Bluetooth A2MP implementation in the Linux kernel did not properly initialize memory in some situations. A physically proximate remote attacker could use this to expose sensitive information (kernel memory). (CVE-2020-12352)
Andy Nguyen discovered that the Bluetooth HCI event packet parser in the Linux kernel did not properly handle event advertisements of certain sizes, leading to a heap-based buffer overflow. A physically proximate remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-24490)
It was discovered that the CIFS network file system implementation in the Linux kernel did not properly validate certain SMB messages, leading to an out-of-bounds read vulnerability. An attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information. (CVE-2023-6610)
Supraja Sridhara, Benedict Schluter, Mark Kuhne, Andrin Bertschi, and Shweta Shinde discovered that the Confidential Computing framework in the Linux kernel for x86 platforms did not properly handle 32-bit emulation on TDX and SEV. An attacker with access to the VMM could use this to cause a denial of service (guest crash) or possibly execute arbitrary code. (CVE-2024-25744)
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture, - ARM64 architecture, - MIPS architecture, - PowerPC architecture, - RISC-V architecture, - S390 architecture, - User-Mode Linux (UML), - x86 architecture, - Block layer subsystem, - ACPI drivers, - Android drivers, - Serial ATA and Parallel ATA drivers, - ATM drivers, - Drivers core, - ATA over ethernet (AOE) driver, - Null block device driver, - TPM device driver, - Character device driver, - Clock framework and drivers, - Buffer Sharing and Synchronization framework, - ARM SCMI message protocol, - EFI core, - GPIO subsystem, - GPU drivers, - HID subsystem, - Hardware monitoring drivers, - I2C subsystem, - I3C subsystem, - InfiniBand drivers, - Input Device core drivers, - Input Device (Miscellaneous) drivers, - IOMMU subsystem, - IRQ chip drivers, - ISDN/mISDN subsystem, - LED subsystem, - Mailbox framework, - Multiple devices driver, - Media drivers, - VMware VMCI Driver, - MMC subsystem, - Ethernet bonding driver, - Network drivers, - Mellanox network drivers, - Microsoft Azure Network Adapter (MANA) driver, - STMicroelectronics network drivers, - Near Field Communication (NFC) drivers, - ... [Please see the references for more information on the vulnerabilities]
Affected Software/OS: 'linux-azure-5.15' package(s) on Ubuntu 20.04.
Solution: Please install the updated package(s).
CVSS Score: 5.8
CVSS Vector: AV:A/AC:L/Au:N/C:P/I:P/A:P
|