Description: | Summary: The remote host is missing an update for the 'linux-oem-6.11' package(s) announced via the USN-7310-1 advisory.
Vulnerability Insight: Attila Szasz discovered that the HFS+ file system implementation in the Linux Kernel contained a heap overflow vulnerability. An attacker could use a specially crafted file system image that, when mounted, could cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2025-0927)
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture, - ARM64 architecture, - PowerPC architecture, - RISC-V architecture, - S390 architecture, - SuperH RISC architecture, - User-Mode Linux (UML), - x86 architecture, - Block layer subsystem, - Cryptographic API, - Compute Acceleration Framework, - ACPI drivers, - Drivers core, - ATA over ethernet (AOE) driver, - RAM backed block device driver, - Network block device driver, - Ublk userspace block driver, - Compressed RAM block device driver, - Bluetooth drivers, - TPM device driver, - Clock framework and drivers, - Data acquisition framework and drivers, - CPU frequency scaling framework, - Hardware crypto device drivers, - CXL (Compute Express Link) drivers, - DAX dirext access to differentiated memory framework, - Buffer Sharing and Synchronization framework, - EDAC drivers, - FireWire subsystem, - ARM SCMI message protocol, - ARM SCPI message protocol, - EFI core, - Qualcomm firmware drivers, - GPIO subsystem, - GPU drivers, - HID subsystem, - I2C subsystem, - I3C subsystem, - IIO ADC drivers, - IIO subsystem, - InfiniBand drivers, - Input Device core drivers, - IOMMU subsystem, - IRQ chip drivers, - Mailbox framework, - Multiple devices driver, - Media drivers, - Multifunction device drivers, - MMC subsystem, - MTD block device drivers, - Ethernet bonding driver, - Network drivers, - Mellanox network drivers, - STMicroelectronics network drivers, - NTB driver, - Virtio pmem driver, - NVME drivers, - Parport drivers, - PCI subsystem, - Alibaba DDR Sub-System Driveway PMU driver, - PHY drivers, - Pin controllers subsystem, - x86 platform drivers, - i.MX PM domains, - Powercap sysfs driver, - Voltage and Current Regulator drivers, - Remote Processor subsystem, - StarFive reset controller drivers, - Real Time Clock drivers, - SCSI subsystem, - SuperH / SH-Mobile drivers, - QCOM SoC drivers, - Xilinx SoC drivers, - SPI subsystem, - Direct Digital Synthesis drivers, - Media staging drivers, - TCM subsystem, - Thermal drivers, - Thunderbolt and USB4 drivers, - TTY drivers, - UFS subsystem, - USB Device Class drivers, - DesignWare USB3 driver, - USB Gadget drivers, - USB Host Controller drivers, - USB Dual Role (OTG-ready) Controller drivers, - USB Serial drivers, - USB Type-C support driver, - USB Type-C Port Controller Manager driver, - TI TPS6598x USB Power Delivery controller driver, - ... [Please see the references for more information on the vulnerabilities]
Affected Software/OS: 'linux-oem-6.11' package(s) on Ubuntu 24.04.
Solution: Please install the updated package(s).
CVSS Score: 9.4
CVSS Vector: AV:N/AC:L/Au:N/C:C/I:N/A:C
|