Ubuntu update for linux



Risk Low
Patch available YES
Number of vulnerabilities 2
CVE-ID CVE-2022-0001
CVE-2022-0002
CWE-ID CWE-200
Exploitation vector Local
Public exploit N/A
Vulnerable software
Ubuntu
Operating systems & Components / Operating system

linux-image-lowlatency (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-kvm (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-oracle (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-gke (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-gcp (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-azure (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-aws (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-generic (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-virtual (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-virtual-lts-xenial (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-lowlatency-lts-xenial (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-generic-lts-xenial (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-oem (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-virtual-hwe-16.04 (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-lowlatency-hwe-16.04 (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-generic-hwe-16.04 (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-snapdragon (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-raspi2 (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-oracle-lts-18.04 (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-generic-lpae (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-gcp-lts-18.04 (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-dell300x (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-azure-lts-18.04 (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-aws-lts-18.04 (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-4.15.0-171-lowlatency (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-4.15.0-171-generic-lpae (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-4.15.0-171-generic (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-4.15.0-1133-azure (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-4.15.0-1123-aws (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-4.15.0-1122-snapdragon (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-4.15.0-1118-gcp (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-4.15.0-1109-kvm (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-4.15.0-1105-raspi2 (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-4.15.0-1089-oracle (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-4.15.0-1037-dell300x (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-aws-hwe (Ubuntu package)
Operating systems & Components / Operating system package or component

linux-image-4.4.0-1101-aws (Ubuntu package)
Operating systems & Components / Operating system package or component

Vendor Canonical Ltd.

Security Bulletin

This security bulletin contains information about 2 vulnerabilities.

1) Information disclosure

EUVDB-ID: #VU61198

Risk: Low

CVSSv4.0: 1.9 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-0001

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to non-transparent sharing of branch predictor selectors between contexts. A local user can gain unauthorized access to sensitive information on the system.

Mitigation

Update the affected package linux to the latest version.

Vulnerable software versions

Ubuntu: 14.04 - 18.04

linux-image-lowlatency (Ubuntu package): before 4.15.0.171.160

linux-image-kvm (Ubuntu package): before 4.15.0.1109.105

linux-image-oracle (Ubuntu package): before 5.13.0.1018.22~20.04.1

linux-image-gke (Ubuntu package): before 5.13.0.1015.14

linux-image-gcp (Ubuntu package): before 5.13.0.1015.14

linux-image-azure (Ubuntu package): before 5.13.0.1014.14

linux-image-aws (Ubuntu package): before 5.13.0.1014.15~20.04.7

linux-image-generic (Ubuntu package): before 4.15.0.171.160

linux-image-virtual (Ubuntu package): before 4.15.0.171.160

linux-image-virtual-lts-xenial (Ubuntu package): before 4.4.0.219.226

linux-image-lowlatency-lts-xenial (Ubuntu package): before 4.4.0.219.226

linux-image-generic-lts-xenial (Ubuntu package): before 4.4.0.219.226

linux-image-oem (Ubuntu package): before 5.4.0.100.104

linux-image-virtual-hwe-16.04 (Ubuntu package): before 4.15.0.187.173

linux-image-lowlatency-hwe-16.04 (Ubuntu package): before 4.15.0.187.173

linux-image-generic-hwe-16.04 (Ubuntu package): before 4.15.0.187.173

linux-image-snapdragon (Ubuntu package): before 4.15.0.1122.125

linux-image-raspi2 (Ubuntu package): before 4.15.0.1105.103

linux-image-oracle-lts-18.04 (Ubuntu package): before 4.15.0.1089.99

linux-image-generic-lpae (Ubuntu package): before 4.15.0.171.160

linux-image-gcp-lts-18.04 (Ubuntu package): before 4.15.0.1118.137

linux-image-dell300x (Ubuntu package): before 4.15.0.1037.39

linux-image-azure-lts-18.04 (Ubuntu package): before 4.15.0.1133.106

linux-image-aws-lts-18.04 (Ubuntu package): before 4.15.0.1123.126

linux-image-4.15.0-171-lowlatency (Ubuntu package): before 4.15.0-171.180

linux-image-4.15.0-171-generic-lpae (Ubuntu package): before 4.15.0-171.180

linux-image-4.15.0-171-generic (Ubuntu package): before 4.15.0-171.180

linux-image-4.15.0-1133-azure (Ubuntu package): before 4.15.0-1133.146

linux-image-4.15.0-1123-aws (Ubuntu package): before 4.15.0-1123.132

linux-image-4.15.0-1122-snapdragon (Ubuntu package): before 4.15.0-1122.131

linux-image-4.15.0-1118-gcp (Ubuntu package): before 4.15.0-1118.132

linux-image-4.15.0-1109-kvm (Ubuntu package): before 4.15.0-1109.112

linux-image-4.15.0-1105-raspi2 (Ubuntu package): before 4.15.0-1105.112

linux-image-4.15.0-1089-oracle (Ubuntu package): before 4.15.0-1089.98

linux-image-4.15.0-1037-dell300x (Ubuntu package): before 4.15.0-1037.42

linux-image-aws-hwe (Ubuntu package): before 4.15.0.1099.92

linux-image-4.4.0-1101-aws (Ubuntu package): before 4.4.0-1101.112

CPE2.3 External links

https://ubuntu.com/security/notices/USN-5319-1


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Information disclosure

EUVDB-ID: #VU61199

Risk: Low

CVSSv4.0: 1.9 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-0002

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to non-transparent sharing of branch predictor within a context. A local user can gain unauthorized access to sensitive information on the system.

Mitigation

Update the affected package linux to the latest version.

Vulnerable software versions

Ubuntu: 14.04 - 18.04

linux-image-lowlatency (Ubuntu package): before 4.15.0.171.160

linux-image-kvm (Ubuntu package): before 4.15.0.1109.105

linux-image-oracle (Ubuntu package): before 5.13.0.1018.22~20.04.1

linux-image-gke (Ubuntu package): before 5.13.0.1015.14

linux-image-gcp (Ubuntu package): before 5.13.0.1015.14

linux-image-azure (Ubuntu package): before 5.13.0.1014.14

linux-image-aws (Ubuntu package): before 5.13.0.1014.15~20.04.7

linux-image-generic (Ubuntu package): before 4.15.0.171.160

linux-image-virtual (Ubuntu package): before 4.15.0.171.160

linux-image-virtual-lts-xenial (Ubuntu package): before 4.4.0.219.226

linux-image-lowlatency-lts-xenial (Ubuntu package): before 4.4.0.219.226

linux-image-generic-lts-xenial (Ubuntu package): before 4.4.0.219.226

linux-image-oem (Ubuntu package): before 5.4.0.100.104

linux-image-virtual-hwe-16.04 (Ubuntu package): before 4.15.0.187.173

linux-image-lowlatency-hwe-16.04 (Ubuntu package): before 4.15.0.187.173

linux-image-generic-hwe-16.04 (Ubuntu package): before 4.15.0.187.173

linux-image-snapdragon (Ubuntu package): before 4.15.0.1122.125

linux-image-raspi2 (Ubuntu package): before 4.15.0.1105.103

linux-image-oracle-lts-18.04 (Ubuntu package): before 4.15.0.1089.99

linux-image-generic-lpae (Ubuntu package): before 4.15.0.171.160

linux-image-gcp-lts-18.04 (Ubuntu package): before 4.15.0.1118.137

linux-image-dell300x (Ubuntu package): before 4.15.0.1037.39

linux-image-azure-lts-18.04 (Ubuntu package): before 4.15.0.1133.106

linux-image-aws-lts-18.04 (Ubuntu package): before 4.15.0.1123.126

linux-image-4.15.0-171-lowlatency (Ubuntu package): before 4.15.0-171.180

linux-image-4.15.0-171-generic-lpae (Ubuntu package): before 4.15.0-171.180

linux-image-4.15.0-171-generic (Ubuntu package): before 4.15.0-171.180

linux-image-4.15.0-1133-azure (Ubuntu package): before 4.15.0-1133.146

linux-image-4.15.0-1123-aws (Ubuntu package): before 4.15.0-1123.132

linux-image-4.15.0-1122-snapdragon (Ubuntu package): before 4.15.0-1122.131

linux-image-4.15.0-1118-gcp (Ubuntu package): before 4.15.0-1118.132

linux-image-4.15.0-1109-kvm (Ubuntu package): before 4.15.0-1109.112

linux-image-4.15.0-1105-raspi2 (Ubuntu package): before 4.15.0-1105.112

linux-image-4.15.0-1089-oracle (Ubuntu package): before 4.15.0-1089.98

linux-image-4.15.0-1037-dell300x (Ubuntu package): before 4.15.0-1037.42

linux-image-aws-hwe (Ubuntu package): before 4.15.0.1099.92

linux-image-4.4.0-1101-aws (Ubuntu package): before 4.4.0-1101.112

CPE2.3 External links

https://ubuntu.com/security/notices/USN-5319-1


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###