{"id":50366,"date":"2023-03-08T04:29:56","date_gmt":"2023-03-07T19:29:56","guid":{"rendered":"https:\/\/jirak.net\/wp\/usn-5934-1-linux-kernel-raspberry-pi-vulnerabilities\/"},"modified":"2023-03-08T05:34:17","modified_gmt":"2023-03-07T20:34:17","slug":"usn-5934-1-linux-kernel-raspberry-pi-vulnerabilities","status":"publish","type":"post","link":"https:\/\/jirak.net\/wp\/usn-5934-1-linux-kernel-raspberry-pi-vulnerabilities\/","title":{"rendered":"USN-5934-1: Linux kernel (Raspberry Pi) vulnerabilities"},"content":{"rendered":"<p>USN-5934-1: Linux kernel (Raspberry Pi) vulnerabilities<\/p>\n<p>It was discovered that the Upper Level Protocol (ULP) subsystem in the<br \/>\nLinux kernel did not properly handle sockets entering the LISTEN state in<br \/>\ncertain protocols, leading to a use-after-free vulnerability. A local<br \/>\nattacker could use this to cause a denial of service (system crash) or<br \/>\npossibly execute arbitrary code. (CVE-2023-0461)<\/p>\n<p>It was discovered that the NVMe driver in the Linux kernel did not properly<br \/>\nhandle reset events in some situations. A local attacker could use this to<br \/>\ncause a denial of service (system crash). (CVE-2022-3169)<\/p>\n<p>It was discovered that a use-after-free vulnerability existed in the SGI<br \/>\nGRU driver in the Linux kernel. A local attacker could possibly use this to<br \/>\ncause a denial of service (system crash) or possibly execute arbitrary<br \/>\ncode. (CVE-2022-3424)<\/p>\n<p>Gwangun Jung discovered a race condition in the IPv4 implementation in the<br \/>\nLinux kernel when deleting multipath routes, resulting in an out-of-bounds<br \/>\nread. An attacker could use this to cause a denial of service (system<br \/>\ncrash) or possibly expose sensitive information (kernel memory).<br \/>\n(CVE-2022-3435)<\/p>\n<p>It was discovered that a race condition existed in the Kernel Connection<br \/>\nMultiplexor (KCM) socket implementation in the Linux kernel when releasing<br \/>\nsockets in certain situations. A local attacker could use this to cause a<br \/>\ndenial of service (system crash). (CVE-2022-3521)<\/p>\n<p>It was discovered that the Netronome Ethernet driver in the Linux kernel<br \/>\ncontained a use-after-free vulnerability. A local attacker could use this<br \/>\nto cause a denial of service (system crash) or possibly execute arbitrary<br \/>\ncode. (CVE-2022-3545)<\/p>\n<p>It was discovered that the hugetlb implementation in the Linux kernel<br \/>\ncontained a race condition in some situations. A local attacker could use<br \/>\nthis to cause a denial of service (system crash) or expose sensitive<br \/>\ninformation (kernel memory). (CVE-2022-3623)<\/p>\n<p>Ziming Zhang discovered that the VMware Virtual GPU DRM driver in the Linux<br \/>\nkernel contained an out-of-bounds write vulnerability. A local attacker<br \/>\ncould use this to cause a denial of service (system crash).<br \/>\n(CVE-2022-36280)<\/p>\n<p>Hyunwoo Kim discovered that the DVB Core driver in the Linux kernel did not<br \/>\nproperly perform reference counting in some situations, leading to a use-<br \/>\nafter-free vulnerability. A local attacker could use this to cause a denial<br \/>\nof service (system crash) or possibly execute arbitrary code.<br \/>\n(CVE-2022-41218)<\/p>\n<p>It was discovered that the Intel i915 graphics driver in the Linux kernel<br \/>\ndid not perform a GPU TLB flush in some situations. A local attacker could<br \/>\nuse this to cause a denial of service or possibly execute arbitrary code.<br \/>\n(CVE-2022-4139)<\/p>\n<p>It was discovered that a race condition existed in the Xen network backend<br \/>\ndriver in the Linux kernel when handling dropped packets in certain<br \/>\ncircumstances. An attacker could use this to cause a denial of service<br \/>\n(kernel deadlock). (CVE-2022-42328, CVE-2022-42329)<\/p>\n<p>It was discovered that the Atmel WILC1000 driver in the Linux kernel did<br \/>\nnot properly validate offsets, leading to an out-of-bounds read<br \/>\nvulnerability. An attacker could use this to cause a denial of service<br \/>\n(system crash). (CVE-2022-47520)<\/p>\n<p>It was discovered that the network queuing discipline implementation in the<br \/>\nLinux kernel contained a null pointer dereference in some situations. A<br \/>\nlocal attacker could use this to cause a denial of service (system crash).<br \/>\n(CVE-2022-47929)<\/p>\n<p>Jos\u00e9 Oliveira and Rodrigo Branco discovered that the prctl syscall<br \/>\nimplementation in the Linux kernel did not properly protect against<br \/>\nindirect branch prediction attacks in some situations. A local attacker<br \/>\ncould possibly use this to expose sensitive information. (CVE-2023-0045)<\/p>\n<p>It was discovered that a use-after-free vulnerability existed in the<br \/>\nAdvanced Linux Sound Architecture (ALSA) subsystem. A local attacker could<br \/>\nuse this to cause a denial of service (system crash). (CVE-2023-0266)<\/p>\n<p>Kyle Zeng discovered that the IPv6 implementation in the Linux kernel<br \/>\ncontained a NULL pointer dereference vulnerability in certain situations. A<br \/>\nlocal attacker could use this to cause a denial of service (system crash).<br \/>\n(CVE-2023-0394)<\/p>\n<p>It was discovered that the Android Binder IPC subsystem in the Linux kernel<br \/>\ndid not properly validate inputs in some situations, leading to a use-<br \/>\nafter-free vulnerability. A local attacker could use this to cause a denial<br \/>\nof service (system crash) or possibly execute arbitrary code.<br \/>\n(CVE-2023-20938)<\/p>\n<p>Kyle Zeng discovered that the class-based queuing discipline implementation<br \/>\nin the Linux kernel contained a type confusion vulnerability in some<br \/>\nsituations. An attacker could use this to cause a denial of service (system<br \/>\ncrash). (CVE-2023-23454)<\/p>\n<p>Kyle Zeng discovered that the ATM VC queuing discipline implementation in<br \/>\nthe Linux kernel contained a type confusion vulnerability in some<br \/>\nsituations. An attacker could use this to cause a denial of service (system<br \/>\ncrash). (CVE-2023-23455)<br \/>\nSource: <a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5934-1\" target=\"_blank\" rel=\"noopener\">USN-5934-1: Linux kernel (Raspberry Pi) vulnerabilities<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div class=\"mh-excerpt\"><p>USN-5934-1: Linux kernel (Raspberry Pi) vulnerabilities It was discovered that the Upper Level Protocol (ULP) subsystem in the Linux kernel did not properly handle sockets entering the LISTEN state in certain protocols, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-0461) It was discovered that the NVMe driver in the Linux kernel did not properly handle reset events in some situations. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-3169) It was discovered that a use-after-free vulnerability existed in the SGI GRU driver in the Linux kernel. A local attacker could possibly use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-3424) Gwangun Jung discovered a race condition in the IPv4 implementation <a class=\"mh-excerpt-more\" href=\"https:\/\/jirak.net\/wp\/usn-5934-1-linux-kernel-raspberry-pi-vulnerabilities\/\" title=\"USN-5934-1: Linux kernel (Raspberry Pi) vulnerabilities\">[ more&#8230; ]<\/a><\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[586],"tags":[587],"class_list":["post-50366","post","type-post","status-publish","format-standard","hentry","category-ubuntu-usn","tag-ubuntu-usn"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/50366","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/comments?post=50366"}],"version-history":[{"count":1,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/50366\/revisions"}],"predecessor-version":[{"id":50367,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/50366\/revisions\/50367"}],"wp:attachment":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/media?parent=50366"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/categories?post=50366"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/tags?post=50366"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}