Jana Hofmann, Emanuele Vannacci, Cedric Fournet, Boris Kopf, and Oleksii Oleksenko discovered that some AMD processors could leak stale data from division operations in certain situations. A local attacker could possibly use this to expose sensitive information. (CVE-2023-20588)
Lonial Con discovered that the netfilter subsystem in the Linux kernel contained a memory leak when handling certain element flush operations. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2023-4569)
{ "binaries": [ { "binary_version": "6.1.0-1022.22", "binary_name": "linux-buildinfo-6.1.0-1022-oem" }, { "binary_version": "6.1.0-1022.22", "binary_name": "linux-headers-6.1.0-1022-oem" }, { "binary_version": "6.1.0-1022.22", "binary_name": "linux-image-unsigned-6.1.0-1022-oem" }, { "binary_version": "6.1.0-1022.22", "binary_name": "linux-modules-6.1.0-1022-oem" }, { "binary_version": "6.1.0-1022.22", "binary_name": "linux-modules-ipu6-6.1.0-1022-oem" }, { "binary_version": "6.1.0-1022.22", "binary_name": "linux-modules-ivsc-6.1.0-1022-oem" }, { "binary_version": "6.1.0-1022.22", "binary_name": "linux-modules-iwlwifi-6.1.0-1022-oem" }, { "binary_version": "6.1.0-1022.22", "binary_name": "linux-oem-6.1-headers-6.1.0-1022" }, { "binary_version": "6.1.0-1022.22", "binary_name": "linux-oem-6.1-tools-6.1.0-1022" }, { "binary_version": "6.1.0-1022.22", "binary_name": "linux-oem-6.1-tools-host" }, { "binary_version": "6.1.0-1022.22", "binary_name": "linux-tools-6.1.0-1022-oem" } ], "availability": "No subscription required" }
{ "cves": [ { "id": "CVE-2023-4569", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" }, { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H" }, { "type": "Ubuntu", "score": "high" } ] }, { "id": "CVE-2023-20588", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N" }, { "type": "Ubuntu", "score": "high" } ] } ], "ecosystem": "Ubuntu:22.04:LTS" }