Jana Hofmann, Emanuele Vannacci, Cedric Fournet, Boris Kopf, and Oleksii Oleksenko discovered that some AMD processors could leak stale data from division operations in certain situations. A local attacker could possibly use this to expose sensitive information. (CVE-2023-20588)
Lonial Con discovered that the netfilter subsystem in the Linux kernel contained a memory leak when handling certain element flush operations. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2023-4569)
{
"binaries": [
{
"binary_name": "linux-buildinfo-6.1.0-1022-oem",
"binary_version": "6.1.0-1022.22"
},
{
"binary_name": "linux-headers-6.1.0-1022-oem",
"binary_version": "6.1.0-1022.22"
},
{
"binary_name": "linux-image-unsigned-6.1.0-1022-oem",
"binary_version": "6.1.0-1022.22"
},
{
"binary_name": "linux-modules-6.1.0-1022-oem",
"binary_version": "6.1.0-1022.22"
},
{
"binary_name": "linux-modules-ipu6-6.1.0-1022-oem",
"binary_version": "6.1.0-1022.22"
},
{
"binary_name": "linux-modules-ivsc-6.1.0-1022-oem",
"binary_version": "6.1.0-1022.22"
},
{
"binary_name": "linux-modules-iwlwifi-6.1.0-1022-oem",
"binary_version": "6.1.0-1022.22"
},
{
"binary_name": "linux-oem-6.1-headers-6.1.0-1022",
"binary_version": "6.1.0-1022.22"
},
{
"binary_name": "linux-oem-6.1-tools-6.1.0-1022",
"binary_version": "6.1.0-1022.22"
},
{
"binary_name": "linux-oem-6.1-tools-host",
"binary_version": "6.1.0-1022.22"
},
{
"binary_name": "linux-tools-6.1.0-1022-oem",
"binary_version": "6.1.0-1022.22"
}
],
"availability": "No subscription required"
}
{
"cves": [
{
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "high",
"type": "Ubuntu"
}
],
"id": "CVE-2023-4569"
},
{
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "high",
"type": "Ubuntu"
}
],
"id": "CVE-2023-20588"
}
],
"ecosystem": "Ubuntu:22.04:LTS"
}