Security Bulletin
This security bulletin contains information about 23 vulnerabilities.
EUVDB-ID: #VU85682
Risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-46838
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows an unprivileged guest to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of network packets at the backend. An unprivileged guest can send zero-length packets to the OS kernel and perform a denial of service (DoS) attack.
MitigationUpdate the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU88378
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52340
CWE-ID:
CWE-400 - Resource exhaustion
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error when processing very large ICMPv6 packets. A remote attacker can send a flood of IPv6 ICMP6 PTB messages, cause the high lock contention and increased CPU usage, leading to a denial of service.
Successful vulnerability exploitation requires a attacker to be on the local network or have a high bandwidth connection.
Update the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU87166
Risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52429
CWE-ID:
CWE-754 - Improper Check for Unusual or Exceptional Conditions
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper error handling within the dm_table_create() function in drivers/md/dm-table.c. A local user can pass specially crafted data to the kernel and perform a denial of service (DoS) attack.
MitigationUpdate the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU87595
Risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-23851
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the copy_params() function in drivers/md/dm-ioctl.c. A remote attacker can trigger an out-of-bounds read and perform a denial of service (DoS) attack.
Update the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU86553
Risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-0607
CWE-ID:
CWE-399 - Resource Management Errors
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper management of internal resources within the nft_byteorder_eval() function in the Netfilter subsystem. A local user can perform a denial of service (DoS) attack.
MitigationUpdate the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU88895
Risk: Low
CVSSv3.1: 6.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52464
CWE-ID:
CWE-787 - Out-of-bounds write
Exploit availability: No
Description The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a boundary error within the thunderx_ocx_com_threaded_isr() function in drivers/edac/thunderx_edac.c. A local user can trigger an out-of-bounds write and execute arbitrary code on the target system.
MitigationUpdate the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU87741
Risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52448
CWE-ID:
CWE-476 - NULL Pointer Dereference
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in gfs2_rgrp_dump() function. A local user can perform a denial of service (DoS) attack.
MitigationUpdate the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU89242
Risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52457
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a use-after-free error within the omap8250_remove() function in drivers/tty/serial/8250/8250_omap.c. A local user can perform a denial of service (DoS) attack.
Update the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU89245
Risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52443
CWE-ID:
CWE-476 - NULL Pointer Dereference
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the unpack_profile() function in security/apparmor/policy_unpack.c. A local user can perform a denial of service (DoS) attack.
MitigationUpdate the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU87573
Risk: Low
CVSSv3.1: 6.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52439
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the uio_open() function in drivers/uio/uio.c. A local user can trigger a use-after-free error and execute arbitrary code with elevated privileges.
Update the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU91314
Risk: Low
CVSSv3.1: 7.7 [AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52612
CWE-ID:
CWE-119 - Memory corruption
Exploit availability: No
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to memory corruption within the scomp_acomp_comp_decomp() function in crypto/scompress.c. A local user can escalate privileges on the system.
MitigationUpdate the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU89267
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-26633
CWE-ID:
CWE-20 - Improper input validation
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to an error in NEXTHDR_FRAGMENT handling within the ip6_tnl_parse_tlv_enc_lim() function in net/ipv6/ip6_tunnel.c. A remote attacker can send specially crafted packets to the system and perform a denial of service (DoS) attack.
MitigationUpdate the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU87682
Risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2024-26597
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition in drivers/net/ethernet/qualcomm/rmnet/rmnet_config.c when parsing the netlink attributes. A local user can trigger an out-of-bounds read error and perform a denial of service (DoS) attack.
Update the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU87742
Risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52449
CWE-ID:
CWE-476 - NULL Pointer Dereference
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error in mtd. A local user can perform a denial of service (DoS) attack.
MitigationUpdate the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU90918
Risk: Low
CVSSv3.1: 6.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52444
CWE-ID:
CWE-617 - Reachable Assertion
Exploit availability: No
DescriptionThe vulnerability allows a local user to execute arbitrary code.
The vulnerability exists due to reachable assertion within the f2fs_rename() function in fs/f2fs/namei.c. A local user can execute arbitrary code.
MitigationUpdate the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU91484
Risk: Low
CVSSv3.1: 7.7 [AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52609
Exploit availability: No
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition within the binder_update_page_range() function in drivers/android/binder_alloc.c. A local user can escalate privileges on the system.
MitigationUpdate the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU89235
Risk: Low
CVSSv3.1: 7.7 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52469
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the kv_parse_power_table() function in drivers/gpu/drm/amd/amdgpu/kv_dpm.c. A local user can trigger a use-after-free error and execute arbitrary code with elevated privileges.
Update the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU87745
Risk: Low
CVSSv3.1: 7.7 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52445
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error in pvrusb2. A local user can execute arbitrary code with elevated privileges.
Update the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU88891
Risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52451
CWE-ID:
CWE-125 - Out-of-bounds read
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition within the dlpar_memory_remove_by_index() function in arch/powerpc/platforms/pseries/hotplug-memory.c. A local user can trigger an out-of-bounds read and perform a denial of service (DoS) attack.
Update the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU92074
Risk: Low
CVSSv3.1: 4.8 [AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52470
CWE-ID:
CWE-476 - NULL Pointer Dereference
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to NULL pointer dereference within the radeon_crtc_init() function in drivers/gpu/drm/radeon/radeon_display.c. A local user can perform a denial of service (DoS) attack.
MitigationUpdate the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU89244
Risk: Low
CVSSv3.1: 4.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52454
CWE-ID:
CWE-476 - NULL Pointer Dereference
Exploit availability: No
DescriptionThe vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error within the nvmet_tcp_build_pdu_iovec() function in drivers/nvme/target/tcp.c. A local user can perform a denial of service (DoS) attack.
MitigationUpdate the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU87592
Risk: Low
CVSSv3.1: 2.2 [CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52436
CWE-ID:
CWE-200 - Information exposure
Exploit availability: No
DescriptionThe vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to the __f2fs_setxattr() function in fs/f2fs/xattr.c, does not empty by default the unused space in the xattr list. A local user can gain access to potentially sensitive information.
Update the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU87593
Risk: Low
CVSSv3.1: 6.8 [CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-52438
CWE-ID:
CWE-416 - Use After Free
Exploit availability: No
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a use-after-free error within the binder_alloc_free_page() function in drivers/android/binder_alloc.c. A local user can trigger a race condition and escalate privileges on the system.
Update the affected package linux to the latest version.
Vulnerable software versionsUbuntu: 18.04 - 20.04
linux-image-5.4.0-175-lowlatency (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-175-generic (Ubuntu package): before Ubuntu Pro
linux-image-virtual (Ubuntu package): before 5.4.0.176.174
linux-image-raspi2 (Ubuntu package): before 5.4.0.1106.136
linux-image-raspi (Ubuntu package): before 5.4.0.1106.136
linux-image-oracle-lts-20.04 (Ubuntu package): before 5.4.0.1121.114
linux-image-oem-osp1 (Ubuntu package): before Ubuntu Pro
linux-image-oem (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-lowlatency (Ubuntu package): before 5.4.0.176.174
linux-image-kvm (Ubuntu package): before 5.4.0.1110.106
linux-image-ibm-lts-20.04 (Ubuntu package): before 5.4.0.1069.98
linux-image-gkeop-5.4 (Ubuntu package): before 5.4.0.1089.87
linux-image-gkeop (Ubuntu package): before 5.4.0.1089.87
linux-image-generic-lpae (Ubuntu package): before 5.4.0.176.174
linux-image-generic (Ubuntu package): before 5.4.0.176.174
linux-image-gcp-lts-20.04 (Ubuntu package): before 5.4.0.1126.128
linux-image-bluefield (Ubuntu package): before 5.4.0.1082.78
linux-image-azure-lts-20.04 (Ubuntu package): before 5.4.0.1127.121
linux-image-aws-lts-20.04 (Ubuntu package): before 5.4.0.1122.119
linux-image-5.4.0-176-lowlatency (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic-lpae (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-176-generic (Ubuntu package): before 5.4.0-176.196
linux-image-5.4.0-1127-azure (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1126-gcp (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1122-aws (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1121-oracle (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1110-kvm (Ubuntu package): before 5.4.0-1110.117
linux-image-5.4.0-1106-raspi (Ubuntu package): before Ubuntu Pro
linux-image-5.4.0-1089-gkeop (Ubuntu package): before 5.4.0-1089.93
linux-image-5.4.0-1082-bluefield (Ubuntu package): before 5.4.0-1082.89
linux-image-5.4.0-1069-ibm (Ubuntu package): before Ubuntu Pro
linux-image-lowlatency-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-virtual-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-snapdragon-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-generic-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-raspi-hwe-18.04 (Ubuntu package): before Ubuntu Pro
linux-image-ibm (Ubuntu package): before Ubuntu Pro
linux-image-aws (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-gcp (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-azure (Ubuntu package): before Ubuntu Pro (Infra-only)
linux-image-oracle (Ubuntu package): before Ubuntu Pro (Infra-only)
CPE2.3 External linkshttp://ubuntu.com/security/notices/USN-6726-1
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.