黄思聪 discovered that the NFC Controller Interface (NCI) implementation in the Linux kernel did not properly handle certain memory allocation failure conditions, leading to a null pointer dereference vulnerability. A local attacker could use this to cause a denial of service (system crash). (CVE-2023-46343)
It was discovered that a race condition existed in the Bluetooth subsystem of the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-51779)
It was discovered that a race condition existed in the Rose X.25 protocol implementation in the Linux kernel, leading to a use-after- free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-51782)
Alon Zahavi discovered that the NVMe-oF/TCP subsystem of the Linux kernel did not properly handle connect command payloads in certain situations, leading to an out-of-bounds read vulnerability. A remote attacker could use this to expose sensitive information (kernel memory). (CVE-2023-6121)
Jann Horn discovered that the io_uring subsystem in the Linux kernel contained an out-of-bounds access vulnerability. A local attacker could use this to cause a denial of service (system crash). (CVE-2023-6560)
Dan Carpenter discovered that the netfilter subsystem in the Linux kernel did not store data in properly sized memory locations. A local user could use this to cause a denial of service (system crash). (CVE-2024-0607)
Supraja Sridhara, Benedict Schlüter, Mark Kuhne, Andrin Bertschi, and Shweta Shinde discovered that the Confidential Computing framework in the Linux kernel for x86 platforms did not properly handle 32-bit emulation on TDX and SEV. An attacker with access to the VMM could use this to cause a denial of service (guest crash) or possibly execute arbitrary code. (CVE-2024-25744)
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "linux-azure-6.5-cloud-tools-6.5.0-1016",
"binary_version": "6.5.0-1016.16~22.04.1"
},
{
"binary_name": "linux-azure-6.5-headers-6.5.0-1016",
"binary_version": "6.5.0-1016.16~22.04.1"
},
{
"binary_name": "linux-azure-6.5-tools-6.5.0-1016",
"binary_version": "6.5.0-1016.16~22.04.1"
},
{
"binary_name": "linux-buildinfo-6.5.0-1016-azure",
"binary_version": "6.5.0-1016.16~22.04.1"
},
{
"binary_name": "linux-cloud-tools-6.5.0-1016-azure",
"binary_version": "6.5.0-1016.16~22.04.1"
},
{
"binary_name": "linux-headers-6.5.0-1016-azure",
"binary_version": "6.5.0-1016.16~22.04.1"
},
{
"binary_name": "linux-image-unsigned-6.5.0-1016-azure",
"binary_version": "6.5.0-1016.16~22.04.1"
},
{
"binary_name": "linux-modules-6.5.0-1016-azure",
"binary_version": "6.5.0-1016.16~22.04.1"
},
{
"binary_name": "linux-modules-extra-6.5.0-1016-azure",
"binary_version": "6.5.0-1016.16~22.04.1"
},
{
"binary_name": "linux-modules-ipu6-6.5.0-1016-azure",
"binary_version": "6.5.0-1016.16~22.04.1"
},
{
"binary_name": "linux-modules-ivsc-6.5.0-1016-azure",
"binary_version": "6.5.0-1016.16~22.04.1"
},
{
"binary_name": "linux-modules-iwlwifi-6.5.0-1016-azure",
"binary_version": "6.5.0-1016.16~22.04.1"
},
{
"binary_name": "linux-tools-6.5.0-1016-azure",
"binary_version": "6.5.0-1016.16~22.04.1"
}
]
}
{
"ecosystem": "Ubuntu:22.04:LTS",
"cves": [
{
"id": "CVE-2023-6121",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2023-6560",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2023-46343",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2023-51779",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2023-51782",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2024-0607",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2024-25744",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
]
}
{
"availability": "No subscription required",
"binaries": [
{
"binary_name": "linux-buildinfo-6.5.0-25-generic",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-buildinfo-6.5.0-25-generic-64k",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-cloud-tools-6.5.0-25-generic",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-headers-6.5.0-25-generic",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-headers-6.5.0-25-generic-64k",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-hwe-6.5-cloud-tools-6.5.0-25",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-hwe-6.5-cloud-tools-common",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-hwe-6.5-headers-6.5.0-25",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-hwe-6.5-tools-6.5.0-25",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-hwe-6.5-tools-common",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-hwe-6.5-tools-host",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-image-6.5.0-25-generic",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-image-unsigned-6.5.0-25-generic",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-image-unsigned-6.5.0-25-generic-64k",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-modules-6.5.0-25-generic",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-modules-6.5.0-25-generic-64k",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-modules-extra-6.5.0-25-generic",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-modules-ipu6-6.5.0-25-generic",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-modules-ivsc-6.5.0-25-generic",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-modules-iwlwifi-6.5.0-25-generic",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-source-6.5.0",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-tools-6.5.0-25-generic",
"binary_version": "6.5.0-25.25~22.04.1"
},
{
"binary_name": "linux-tools-6.5.0-25-generic-64k",
"binary_version": "6.5.0-25.25~22.04.1"
}
]
}
{
"ecosystem": "Ubuntu:22.04:LTS",
"cves": [
{
"id": "CVE-2023-6121",
"severity": [
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2023-6560",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2023-46343",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2023-51779",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2023-51782",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2024-0607",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
},
{
"id": "CVE-2024-25744",
"severity": [
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H",
"type": "CVSS_V3"
},
{
"score": "medium",
"type": "Ubuntu"
}
]
}
]
}