The iouring subsystem in the Linux kernel allowed the MAXRWCOUNT limit to be bypassed in the PROVIDEBUFFERS operation, which led to negative values being usedin memrw when reading /proc/<PID>/mem. This could be used to create a heap overflow leading to arbitrary code execution in the kernel. It was addressed via commit d1f82808877b ("iouring: truncate lengths larger than MAXRWCOUNT on provide buffers") (v5.13-rc1) and backported to the stable kernels in v5.12.4, v5.11.21, and v5.10.37. It was introduced in ddf0322db79c ("iouring: add IORINGOPPROVIDEBUFFERS") (v5.7-rc1).
{ "availability": "No subscription required", "binaries": [ { "binary_name": "block-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "block-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "block-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "crypto-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "crypto-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "crypto-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "dasd-extra-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "dasd-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "fat-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "fat-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "fat-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "fb-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "firewire-core-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "floppy-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "fs-core-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "fs-core-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "fs-core-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "fs-secondary-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "fs-secondary-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "fs-secondary-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "input-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "input-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "input-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "ipmi-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "ipmi-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "ipmi-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "kernel-image-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "kernel-image-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "kernel-image-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-buildinfo-5.8.0-53-generic", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-buildinfo-5.8.0-53-generic-64k", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-buildinfo-5.8.0-53-generic-lpae", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-buildinfo-5.8.0-53-lowlatency", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-cloud-tools-5.8.0-53-generic", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-cloud-tools-5.8.0-53-lowlatency", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-headers-5.8.0-53-generic", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-headers-5.8.0-53-generic-64k", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-headers-5.8.0-53-generic-lpae", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-headers-5.8.0-53-lowlatency", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-hwe-5.8-cloud-tools-5.8.0-53", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-hwe-5.8-cloud-tools-common", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-hwe-5.8-headers-5.8.0-53", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-hwe-5.8-source-5.8.0", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-hwe-5.8-tools-5.8.0-53", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-hwe-5.8-tools-common", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-hwe-5.8-tools-host", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-hwe-5.8-udebs-generic", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-hwe-5.8-udebs-generic-64k", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-hwe-5.8-udebs-generic-lpae", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-image-5.8.0-53-generic", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-image-5.8.0-53-generic-dbgsym", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-image-5.8.0-53-generic-lpae", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-image-5.8.0-53-generic-lpae-dbgsym", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-image-unsigned-5.8.0-53-generic", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-image-unsigned-5.8.0-53-generic-64k", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-image-unsigned-5.8.0-53-generic-64k-dbgsym", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-image-unsigned-5.8.0-53-generic-dbgsym", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-image-unsigned-5.8.0-53-lowlatency", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-image-unsigned-5.8.0-53-lowlatency-dbgsym", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-modules-5.8.0-53-generic", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-modules-5.8.0-53-generic-64k", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-modules-5.8.0-53-generic-lpae", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-modules-5.8.0-53-lowlatency", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-modules-extra-5.8.0-53-generic", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-tools-5.8.0-53-generic", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-tools-5.8.0-53-generic-64k", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-tools-5.8.0-53-generic-lpae", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "linux-tools-5.8.0-53-lowlatency", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "md-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "md-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "md-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "message-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "message-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "mouse-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "mouse-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "mouse-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "multipath-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "multipath-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "multipath-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "nfs-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "nfs-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "nfs-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "nic-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "nic-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "nic-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "nic-pcmcia-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "nic-shared-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "nic-shared-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "nic-shared-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "nic-usb-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "nic-usb-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "nic-usb-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "parport-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "parport-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "parport-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "pata-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "pcmcia-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "pcmcia-storage-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "plip-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "plip-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "plip-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "ppp-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "ppp-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "ppp-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "sata-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "sata-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "sata-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "scsi-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "scsi-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "scsi-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "serial-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "storage-core-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "storage-core-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "storage-core-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "usb-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "usb-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "usb-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "virtio-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "virtio-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "vlan-modules-5.8.0-53-generic-64k-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "vlan-modules-5.8.0-53-generic-di", "binary_version": "5.8.0-53.60~20.04.1" }, { "binary_name": "vlan-modules-5.8.0-53-generic-lpae-di", "binary_version": "5.8.0-53.60~20.04.1" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "linux-buildinfo-5.10.0-1026-oem", "binary_version": "5.10.0-1026.27" }, { "binary_name": "linux-headers-5.10.0-1026-oem", "binary_version": "5.10.0-1026.27" }, { "binary_name": "linux-image-unsigned-5.10.0-1026-oem", "binary_version": "5.10.0-1026.27" }, { "binary_name": "linux-image-unsigned-5.10.0-1026-oem-dbgsym", "binary_version": "5.10.0-1026.27" }, { "binary_name": "linux-modules-5.10.0-1026-oem", "binary_version": "5.10.0-1026.27" }, { "binary_name": "linux-oem-5.10-headers-5.10.0-1026", "binary_version": "5.10.0-1026.27" }, { "binary_name": "linux-oem-5.10-tools-5.10.0-1026", "binary_version": "5.10.0-1026.27" }, { "binary_name": "linux-oem-5.10-tools-host", "binary_version": "5.10.0-1026.27" }, { "binary_name": "linux-tools-5.10.0-1026-oem", "binary_version": "5.10.0-1026.27" } ] }
{ "availability": "No subscription required", "binaries": [ { "binary_name": "block-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "crypto-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "fat-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "firewire-core-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "fs-core-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "fs-secondary-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "input-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "ipmi-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "kernel-image-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "linux-buildinfo-5.8.0-25-generic", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "linux-headers-5.8.0-25-generic", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "linux-image-5.8.0-25-generic", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "linux-image-5.8.0-25-generic-dbgsym", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "linux-modules-5.8.0-25-generic", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "linux-modules-extra-5.8.0-25-generic", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "linux-riscv-5.8-headers-5.8.0-25", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "linux-riscv-5.8-tools-5.8.0-25", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "linux-tools-5.8.0-25-generic", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "linux-udebs-generic", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "md-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "message-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "mouse-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "multipath-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "nfs-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "nic-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "nic-shared-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "nic-usb-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "parport-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "pata-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "plip-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "ppp-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "sata-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "scsi-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "storage-core-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "usb-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "virtio-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" }, { "binary_name": "vlan-modules-5.8.0-25-generic-di", "binary_version": "5.8.0-25.27~20.04.1" } ] }