No Image

USN-6129-1: Avahi vulnerability

2023-06-01 KENNETH 0

USN-6129-1: Avahi vulnerability It was discovered that Avahi incorrectly handled certain DBus messages. A local attacker could possibly use this issue to cause Avahi to crash, resulting in a denial of service. Source: USN-6129-1: Avahi vulnerability

No Image

USN-6128-1: CUPS vulnerability

2023-06-01 KENNETH 0

USN-6128-1: CUPS vulnerability It was discovered that CUPS incorrectly handled logging. A remote attacker could use this issue to cause CUPS to crash, resulting in a denial of service, or possibly execute arbitrary code. Source: USN-6128-1: CUPS vulnerability

No Image

USN-6127-1: Linux kernel vulnerabilities

2023-06-01 KENNETH 0

USN-6127-1: Linux kernel vulnerabilities Patryk Sondej and Piotr Krysiuk discovered that a race condition existed in the netfilter subsystem of the Linux kernel when processing batch requests, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-32233) Gwangun Jung discovered that the Quick Fair Queueing scheduler implementation in the Linux kernel contained an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-31436) Reima Ishii discovered that the nested KVM implementation for Intel x86 processors in the Linux kernel did not properly validate control registers in certain situations. An attacker in a guest VM could use this to cause a denial of service (guest crash). (CVE-2023-30456) It was discovered that the Broadcom [ more… ]

No Image

USN-6126-1: libvirt vulnerabilities

2023-05-31 KENNETH 0

USN-6126-1: libvirt vulnerabilities It was discovered that libvirt incorrectly handled the nwfilter driver. A local attacker could possibly use this issue to cause libvirt to crash, resulting in a denial of service. This issue only affected Ubuntu 22.04 LTS. (CVE-2022-0897) It was discovered that libvirt incorrectly handled queries for the SR-IOV PCI device capabilities. A local attacker could possibly use this issue to cause libvirt to consume resources, leading to a denial of service. (CVE-2023-2700) Source: USN-6126-1: libvirt vulnerabilities

No Image

USN-6125-1: snapd vulnerability

2023-05-31 KENNETH 0

USN-6125-1: snapd vulnerability It was discovered that the snap sandbox did not restrict the use of the ioctl system call with a TIOCLINUX request. This could be exploited by a malicious snap to inject commands into the controlling terminal which would then be executed outside of the snap sandbox once the snap had exited. This could allow an attacker to execute arbitrary commands outside of the confined snap sandbox. Note: graphical terminal emulators like xterm, gnome-terminal and others are not affected – this can only be exploited when snaps are run on a virtual console. Source: USN-6125-1: snapd vulnerability