USN-4285-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-4285-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-4285-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-4285-1
Related
Published
2020-02-18T19:35:31.330774Z
Modified
2020-02-18T19:35:31.330774Z
Summary
linux-aws-5.0, linux-azure, linux-gcp, linux-gke-5.0, linux-oracle-5.0 vulnerabilities
Details

It was discovered that the Linux kernel did not properly clear data structures on context switches for certain Intel graphics processors. A local attacker could use this to expose sensitive information. (CVE-2019-14615)

It was discovered that the HSA Linux kernel driver for AMD GPU devices did not properly check for errors in certain situations, leading to a NULL pointer dereference. A local attacker could possibly use this to cause a denial of service. (CVE-2019-16229)

It was discovered that the Marvell 8xxx Libertas WLAN device driver in the Linux kernel did not properly check for errors in certain situations, leading to a NULL pointer dereference. A local attacker could possibly use this to cause a denial of service. (CVE-2019-16232)

It was discovered that the Renesas Digital Radio Interface (DRIF) driver in the Linux kernel did not properly initialize data. A local attacker could possibly use this to expose sensitive information (kernel memory). (CVE-2019-18786).

It was discovered that the Afatech AF9005 DVB-T USB device driver in the Linux kernel did not properly deallocate memory in certain error conditions. A local attacker could possibly use this to cause a denial of service (kernel memory exhaustion). (CVE-2019-18809)

It was discovered that multiple memory leaks existed in the Marvell WiFi-Ex Driver for the Linux kernel. A local attacker could possibly use this to cause a denial of service (kernel memory exhaustion). (CVE-2019-19057)

It was discovered that the Realtek rtlwifi USB device driver in the Linux kernel did not properly deallocate memory in certain error conditions. A local attacker could possibly use this to cause a denial of service (kernel memory exhaustion). (CVE-2019-19063)

It was discovered that the Kvaser CAN/USB driver in the Linux kernel did not properly initialize memory in certain situations. A local attacker could possibly use this to expose sensitive information (kernel memory). (CVE-2019-19947)

Gao Chuan discovered that the SAS Class driver in the Linux kernel contained a race condition that could lead to a NULL pointer dereference. A local attacker could possibly use this to cause a denial of service (system crash). (CVE-2019-19965)

It was discovered that the Datagram Congestion Control Protocol (DCCP) implementation in the Linux kernel did not properly deallocate memory in certain error conditions. An attacker could possibly use this to cause a denial of service (kernel memory exhaustion). (CVE-2019-20096)

Mitchell Frank discovered that the Wi-Fi implementation in the Linux kernel when used as an access point would send IAPP location updates for stations before client authentication had completed. A physically proximate attacker could use this to cause a denial of service. (CVE-2019-5108)

It was discovered that a race condition can lead to a use-after-free while destroying GEM contexts in the i915 driver for the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-7053)

References

Affected packages

Ubuntu:18.04:LTS / linux-aws-5.0

Package

Name
linux-aws-5.0
Purl
pkg:deb/ubuntu/linux-aws-5.0@5.0.0-1025.28?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.0-1025.28

Affected versions

5.*

5.0.0-1021.24~18.04.1
5.0.0-1022.25~18.04.1
5.0.0-1023.26~18.04.1
5.0.0-1024.27~18.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-tools-5.0.0-1025-aws": "5.0.0-1025.28",
            "linux-image-5.0.0-1025-aws-dbgsym": "5.0.0-1025.28",
            "linux-modules-extra-5.0.0-1025-aws": "5.0.0-1025.28",
            "linux-modules-5.0.0-1025-aws": "5.0.0-1025.28",
            "linux-aws-headers-5.0.0-1025": "5.0.0-1025.28",
            "linux-aws-5.0-tools-5.0.0-1025": "5.0.0-1025.28",
            "linux-buildinfo-5.0.0-1025-aws": "5.0.0-1025.28",
            "linux-image-5.0.0-1025-aws": "5.0.0-1025.28",
            "linux-cloud-tools-5.0.0-1025-aws": "5.0.0-1025.28",
            "linux-headers-5.0.0-1025-aws": "5.0.0-1025.28"
        }
    ]
}

Ubuntu:18.04:LTS / linux-azure

Package

Name
linux-azure
Purl
pkg:deb/ubuntu/linux-azure@5.0.0-1032.34?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.0-1032.34

Affected versions

4.*

4.15.0-1002.2
4.15.0-1003.3
4.15.0-1004.4
4.15.0-1008.8
4.15.0-1009.9
4.15.0-1012.12
4.15.0-1013.13
4.15.0-1014.14
4.15.0-1018.18
4.15.0-1019.19
4.15.0-1021.21
4.15.0-1022.23
4.15.0-1023.24
4.15.0-1025.26
4.15.0-1028.29
4.15.0-1030.31
4.15.0-1031.32
4.15.0-1032.33
4.15.0-1035.36
4.15.0-1036.38
4.15.0-1037.39
4.18.0-1011.11~18.04.1
4.18.0-1013.13~18.04.1
4.18.0-1014.14~18.04.1
4.18.0-1018.18~18.04.1
4.18.0-1019.19~18.04.1
4.18.0-1020.20~18.04.1
4.18.0-1023.24~18.04.1
4.18.0-1024.25~18.04.1
4.18.0-1025.27~18.04.1

5.*

5.0.0-1014.14~18.04.1
5.0.0-1016.17~18.04.1
5.0.0-1018.19~18.04.1
5.0.0-1020.21~18.04.1
5.0.0-1022.23~18.04.1
5.0.0-1023.24~18.04.1
5.0.0-1025.27~18.04.1
5.0.0-1027.29~18.04.1
5.0.0-1028.30~18.04.1
5.0.0-1029.31~18.04.1
5.0.0-1031.33

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-azure-cloud-tools-5.0.0-1032": "5.0.0-1032.34",
            "linux-azure-headers-5.0.0-1032": "5.0.0-1032.34",
            "linux-cloud-tools-5.0.0-1032-azure": "5.0.0-1032.34",
            "linux-image-unsigned-5.0.0-1032-azure-dbgsym": "5.0.0-1032.34",
            "linux-azure-tools-5.0.0-1032": "5.0.0-1032.34",
            "linux-headers-5.0.0-1032-azure": "5.0.0-1032.34",
            "linux-modules-5.0.0-1032-azure": "5.0.0-1032.34",
            "linux-tools-5.0.0-1032-azure": "5.0.0-1032.34",
            "linux-buildinfo-5.0.0-1032-azure": "5.0.0-1032.34",
            "linux-modules-extra-5.0.0-1032-azure": "5.0.0-1032.34",
            "linux-image-unsigned-5.0.0-1032-azure": "5.0.0-1032.34"
        }
    ]
}

Ubuntu:18.04:LTS / linux-gcp

Package

Name
linux-gcp
Purl
pkg:deb/ubuntu/linux-gcp@5.0.0-1031.32?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.0-1031.32

Affected versions

4.*

4.15.0-1001.1
4.15.0-1003.3
4.15.0-1005.5
4.15.0-1006.6
4.15.0-1008.8
4.15.0-1009.9
4.15.0-1010.10
4.15.0-1014.14
4.15.0-1015.15
4.15.0-1017.18
4.15.0-1018.19
4.15.0-1019.20
4.15.0-1021.22
4.15.0-1023.24
4.15.0-1024.25
4.15.0-1025.26
4.15.0-1026.27
4.15.0-1027.28
4.15.0-1028.29
4.15.0-1029.31
4.15.0-1030.32
4.15.0-1032.34
4.15.0-1033.35
4.15.0-1034.36
4.15.0-1036.38
4.15.0-1037.39
4.15.0-1040.42
4.15.0-1042.45
4.15.0-1044.70

5.*

5.0.0-1020.20~18.04.1
5.0.0-1021.21~18.04.1
5.0.0-1025.26~18.04.1
5.0.0-1026.27~18.04.1
5.0.0-1028.29~18.04.1
5.0.0-1029.30~18.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-modules-extra-5.0.0-1031-gcp": "5.0.0-1031.32",
            "linux-gcp-headers-5.0.0-1031": "5.0.0-1031.32",
            "linux-headers-5.0.0-1031-gcp": "5.0.0-1031.32",
            "linux-tools-5.0.0-1031-gcp": "5.0.0-1031.32",
            "linux-image-unsigned-5.0.0-1031-gcp-dbgsym": "5.0.0-1031.32",
            "linux-buildinfo-5.0.0-1031-gcp": "5.0.0-1031.32",
            "linux-image-unsigned-5.0.0-1031-gcp": "5.0.0-1031.32",
            "linux-modules-5.0.0-1031-gcp": "5.0.0-1031.32",
            "linux-gcp-tools-5.0.0-1031": "5.0.0-1031.32"
        }
    ]
}

Ubuntu:18.04:LTS / linux-gke-5.0

Package

Name
linux-gke-5.0
Purl
pkg:deb/ubuntu/linux-gke-5.0@5.0.0-1030.31?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.0-1030.31

Affected versions

5.*

5.0.0-1011.11~18.04.1
5.0.0-1013.13~18.04.1
5.0.0-1015.15~18.04.1
5.0.0-1017.17~18.04.1
5.0.0-1020.20~18.04.1
5.0.0-1022.22~18.04.3
5.0.0-1023.23~18.04.2
5.0.0-1025.26~18.04.1
5.0.0-1026.27~18.04.2
5.0.0-1027.28~18.04.1
5.0.0-1029.30~18.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-gke-5.0-tools-5.0.0-1030": "5.0.0-1030.31",
            "linux-modules-5.0.0-1030-gke": "5.0.0-1030.31",
            "linux-buildinfo-5.0.0-1030-gke": "5.0.0-1030.31",
            "linux-gke-5.0-headers-5.0.0-1030": "5.0.0-1030.31",
            "linux-image-unsigned-5.0.0-1030-gke": "5.0.0-1030.31",
            "linux-tools-5.0.0-1030-gke": "5.0.0-1030.31",
            "linux-headers-5.0.0-1030-gke": "5.0.0-1030.31",
            "linux-image-unsigned-5.0.0-1030-gke-dbgsym": "5.0.0-1030.31",
            "linux-modules-extra-5.0.0-1030-gke": "5.0.0-1030.31"
        }
    ]
}

Ubuntu:18.04:LTS / linux-oracle-5.0

Package

Name
linux-oracle-5.0
Purl
pkg:deb/ubuntu/linux-oracle-5.0@5.0.0-1011.16?arch=src?distro=bionic

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.0.0-1011.16

Affected versions

5.*

5.0.0-1007.12~18.04.1
5.0.0-1008.13~18.04.1
5.0.0-1009.14~18.04.1
5.0.0-1010.15~18.04.1

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-tools-5.0.0-1011-oracle": "5.0.0-1011.16",
            "linux-modules-extra-5.0.0-1011-oracle": "5.0.0-1011.16",
            "linux-oracle-5.0-headers-5.0.0-1011": "5.0.0-1011.16",
            "linux-image-unsigned-5.0.0-1011-oracle-dbgsym": "5.0.0-1011.16",
            "linux-modules-5.0.0-1011-oracle": "5.0.0-1011.16",
            "linux-oracle-5.0-tools-5.0.0-1011": "5.0.0-1011.16",
            "linux-buildinfo-5.0.0-1011-oracle": "5.0.0-1011.16",
            "linux-headers-5.0.0-1011-oracle": "5.0.0-1011.16",
            "linux-image-unsigned-5.0.0-1011-oracle": "5.0.0-1011.16"
        }
    ]
}