USN-5599-1

See a problem?
Source
https://ubuntu.com/security/notices/USN-5599-1
Import Source
https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5599-1.json
JSON Data
https://api.osv.dev/v1/vulns/USN-5599-1
Related
Published
2022-09-05T22:22:29.498967Z
Modified
2022-09-05T22:22:29.498967Z
Summary
linux-oracle vulnerabilities
Details

Asaf Modelevsky discovered that the Intel(R) 10GbE PCI Express (ixgbe) Ethernet driver for the Linux kernel performed insufficient control flow management. A local attacker could possibly use this to cause a denial of service. (CVE-2021-33061)

Moshe Kol, Amit Klein and Yossi Gilad discovered that the IP implementation in the Linux kernel did not provide sufficient randomization when calculating port offsets. An attacker could possibly use this to expose sensitive information. (CVE-2022-1012)

Norbert Slusarek discovered that a race condition existed in the perf subsystem in the Linux kernel, resulting in a use-after-free vulnerability. A privileged local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-1729)

Qiuhao Li, Gaoning Pan, and Yongkang Jia discovered that the KVM hypervisor implementation in the Linux kernel did not properly handle an illegal instruction in a guest, resulting in a null pointer dereference. An attacker in a guest VM could use this to cause a denial of service (system crash) in the host OS. (CVE-2022-1852)

It was discovered that the UDF file system implementation in the Linux kernel contained an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-1943)

Gerald Lee discovered that the NTFS file system implementation in the Linux kernel did not properly handle certain error conditions, leading to a use- after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information. (CVE-2022-1973)

It was discovered that the device-mapper verity (dm-verity) driver in the Linux kernel did not properly verify targets being loaded into the device- mapper table. A privileged attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-2503)

Zheyu Ma discovered that the Intel iSMT SMBus host controller driver in the Linux kernel contained an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-2873)

Selim Enes Karaduman discovered that a race condition existed in the pipe buffers implementation of the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly escalate privileges. (CVE-2022-2959)

References

Affected packages

Ubuntu:22.04:LTS / linux-oracle

Package

Name
linux-oracle
Purl
pkg:deb/ubuntu/linux-oracle@5.15.0-1017.22?arch=src?distro=jammy

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.0-1017.22

Affected versions

5.*

5.13.0-1008.10
5.15.0-1001.3
5.15.0-1002.4
5.15.0-1003.5
5.15.0-1006.8
5.15.0-1007.9
5.15.0-1009.12
5.15.0-1011.15
5.15.0-1013.17
5.15.0-1016.20

Ecosystem specific

{
    "availability": "No subscription required",
    "binaries": [
        {
            "linux-oracle-tools-5.15.0-1017": "5.15.0-1017.22",
            "linux-oracle-headers-5.15.0-1017": "5.15.0-1017.22",
            "linux-image-unsigned-5.15.0-1017-oracle-dbgsym": "5.15.0-1017.22",
            "linux-headers-5.15.0-1017-oracle": "5.15.0-1017.22",
            "linux-modules-extra-5.15.0-1017-oracle": "5.15.0-1017.22",
            "linux-buildinfo-5.15.0-1017-oracle": "5.15.0-1017.22",
            "linux-modules-5.15.0-1017-oracle": "5.15.0-1017.22",
            "linux-tools-5.15.0-1017-oracle": "5.15.0-1017.22",
            "linux-image-unsigned-5.15.0-1017-oracle": "5.15.0-1017.22"
        }
    ]
}