Description: | Summary: The remote host is missing an update for the 'linux, linux-hwe-5.4' package(s) announced via the USN-7391-1 advisory.
Vulnerability Insight: Chenyuan Yang discovered that the CEC driver driver in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2024-23848)
Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - PowerPC architecture, - S390 architecture, - SuperH RISC architecture, - User-Mode Linux (UML), - x86 architecture, - Cryptographic API, - Virtio block driver, - Data acquisition framework and drivers, - Hardware crypto device drivers, - DMA engine subsystem, - EDAC drivers, - ARM SCPI message protocol, - GPIO subsystem, - GPU drivers, - HID subsystem, - Microsoft Hyper-V drivers, - I3C subsystem, - IIO ADC drivers, - IIO subsystem, - InfiniBand drivers, - LED subsystem, - Multiple devices driver, - Media drivers, - Multifunction device drivers, - MMC subsystem, - MTD block device drivers, - Network drivers, - Mellanox network drivers, - NVME drivers, - PCI subsystem, - Pin controllers subsystem, - x86 platform drivers, - Real Time Clock drivers, - SCSI subsystem, - SuperH / SH-Mobile drivers, - QCOM SoC drivers, - SPI subsystem, - USB Gadget drivers, - USB Serial drivers, - USB Type-C Port Controller Manager driver, - VFIO drivers, - Framebuffer layer, - Xen hypervisor drivers, - BTRFS file system, - Ext4 file system, - F2FS file system, - GFS2 file system, - File systems infrastructure, - JFFS2 file system, - JFS file system, - Network file system (NFS) client, - Network file system (NFS) server daemon, - NILFS2 file system, - Overlay file system, - Proc file system, - Diskquota system, - SMB network file system, - UBI file system, - Timer subsystem, - VLANs driver, - LAPB network protocol, - Kernel init infrastructure, - BPF subsystem, - Kernel CPU control infrastructure, - Tracing infrastructure, - Memory management, - 9P file system network protocol, - Bluetooth subsystem, - CAN network layer, - Networking core, - DCCP (Datagram Congestion Control Protocol), - IEEE802154.4 network protocol, - IPv4 networking, - IPv6 networking, - IEEE 802.15.4 subsystem, - Netfilter, - Netlink, - NET/ROM layer, - Packet sockets, - Network traffic control, - SCTP protocol, - Sun RPC protocol, - TIPC protocol, - eXpress Data Path, - SELinux security module, - USB sound devices, (CVE-2024-53172, CVE-2024-56572, CVE-2024-56739, CVE-2024-56643, CVE-2024-53131, CVE-2024-57904, CVE-2024-53145, CVE-2024-57908, CVE-2024-53155, CVE-2024-56691, CVE-2024-57901, CVE-2024-56595, CVE-2024-55916, CVE-2024-50051, CVE-2024-49936, CVE-2024-57900, CVE-2024-53239, CVE-2024-53142, CVE-2024-57889, CVE-2024-53217, CVE-2024-56619, CVE-2025-21653, CVE-2024-53140, CVE-2024-53130, CVE-2024-43098, ... [Please see the references for more information on the vulnerabilities]
Affected Software/OS: 'linux, linux-hwe-5.4' package(s) on Ubuntu 18.04, Ubuntu 20.04.
Solution: Please install the updated package(s).
CVSS Score: 6.8
CVSS Vector: AV:L/AC:L/Au:S/C:C/I:C/A:C
|