{"id":50537,"date":"2023-03-17T06:21:45","date_gmt":"2023-03-16T21:21:45","guid":{"rendered":"https:\/\/jirak.net\/wp\/usn-5962-1-linux-kernel-intel-iotg-vulnerabilities\/"},"modified":"2023-03-17T07:34:15","modified_gmt":"2023-03-16T22:34:15","slug":"usn-5962-1-linux-kernel-intel-iotg-vulnerabilities","status":"publish","type":"post","link":"https:\/\/jirak.net\/wp\/usn-5962-1-linux-kernel-intel-iotg-vulnerabilities\/","title":{"rendered":"USN-5962-1: Linux kernel (Intel IoTG) vulnerabilities"},"content":{"rendered":"<p>USN-5962-1: Linux kernel (Intel IoTG) vulnerabilities<\/p>\n<p>It was discovered that the Upper Level Protocol (ULP) subsystem in the<br \/>\nLinux kernel did not properly handle sockets entering the LISTEN state in<br \/>\ncertain protocols, leading to a use-after-free vulnerability. A local<br \/>\nattacker could use this to cause a denial of service (system crash) or<br \/>\npossibly execute arbitrary code. (CVE-2023-0461)<\/p>\n<p>Davide Ornaghi discovered that the netfilter subsystem in the Linux kernel<br \/>\ndid not properly handle VLAN headers in some situations. A local attacker<br \/>\ncould use this to cause a denial of service (system crash) or possibly<br \/>\nexecute arbitrary code. (CVE-2023-0179)<\/p>\n<p>It was discovered that the NVMe driver in the Linux kernel did not properly<br \/>\nhandle reset events in some situations. A local attacker could use this to<br \/>\ncause a denial of service (system crash). (CVE-2022-3169)<\/p>\n<p>Maxim Levitsky discovered that the KVM nested virtualization (SVM)<br \/>\nimplementation for AMD processors in the Linux kernel did not properly<br \/>\nhandle nested shutdown execution. An attacker in a guest vm could use this<br \/>\nto cause a denial of service (host kernel crash) (CVE-2022-3344)<\/p>\n<p>Gwangun Jung discovered a race condition in the IPv4 implementation in the<br \/>\nLinux kernel when deleting multipath routes, resulting in an out-of-bounds<br \/>\nread. An attacker could use this to cause a denial of service (system<br \/>\ncrash) or possibly expose sensitive information (kernel memory).<br \/>\n(CVE-2022-3435)<\/p>\n<p>It was discovered that a race condition existed in the Kernel Connection<br \/>\nMultiplexor (KCM) socket implementation in the Linux kernel when releasing<br \/>\nsockets in certain situations. A local attacker could use this to cause a<br \/>\ndenial of service (system crash). (CVE-2022-3521)<\/p>\n<p>It was discovered that the Netronome Ethernet driver in the Linux kernel<br \/>\ncontained a use-after-free vulnerability. A local attacker could use this<br \/>\nto cause a denial of service (system crash) or possibly execute arbitrary<br \/>\ncode. (CVE-2022-3545)<\/p>\n<p>It was discovered that the Intel i915 graphics driver in the Linux kernel<br \/>\ndid not perform a GPU TLB flush in some situations. A local attacker could<br \/>\nuse this to cause a denial of service or possibly execute arbitrary code.<br \/>\n(CVE-2022-4139)<\/p>\n<p>It was discovered that a race condition existed in the Xen network backend<br \/>\ndriver in the Linux kernel when handling dropped packets in certain<br \/>\ncircumstances. An attacker could use this to cause a denial of service<br \/>\n(kernel deadlock). (CVE-2022-42328, CVE-2022-42329)<\/p>\n<p>It was discovered that the NFSD implementation in the Linux kernel<br \/>\ncontained a use-after-free vulnerability. A remote attacker could possibly<br \/>\nuse this to cause a denial of service (system crash) or execute arbitrary<br \/>\ncode. (CVE-2022-4379)<\/p>\n<p>It was discovered that a race condition existed in the x86 KVM subsystem<br \/>\nimplementation in the Linux kernel when nested virtualization and the TDP<br \/>\nMMU are enabled. An attacker in a guest vm could use this to cause a denial<br \/>\nof service (host OS crash). (CVE-2022-45869)<\/p>\n<p>It was discovered that the Atmel WILC1000 driver in the Linux kernel did<br \/>\nnot properly validate the number of channels, leading to an out-of-bounds<br \/>\nwrite vulnerability. An attacker could use this to cause a denial of<br \/>\nservice (system crash) or possibly execute arbitrary code. (CVE-2022-47518)<\/p>\n<p>It was discovered that the Atmel WILC1000 driver in the Linux kernel did<br \/>\nnot properly validate specific attributes, leading to an out-of-bounds<br \/>\nwrite vulnerability. An attacker could use this to cause a denial of<br \/>\nservice (system crash) or possibly execute arbitrary code. (CVE-2022-47519)<\/p>\n<p>It was discovered that the Atmel WILC1000 driver in the Linux kernel did<br \/>\nnot properly validate offsets, leading to an out-of-bounds read<br \/>\nvulnerability. An attacker could use this to cause a denial of service<br \/>\n(system crash). (CVE-2022-47520)<\/p>\n<p>It was discovered that the Atmel WILC1000 driver in the Linux kernel did<br \/>\nnot properly validate specific attributes, leading to a heap-based buffer<br \/>\noverflow. An attacker could use this to cause a denial of service (system<br \/>\ncrash) or possibly execute arbitrary code. (CVE-2022-47521)<\/p>\n<p>Lin Ma discovered a race condition in the io_uring subsystem in the Linux<br \/>\nkernel, leading to a null pointer dereference vulnerability. A local<br \/>\nattacker could use this to cause a denial of service (system crash).<br \/>\n(CVE-2023-0468)<\/p>\n<p>It was discovered that the file system writeback functionality in the Linux<br \/>\nkernel contained a user-after-free vulnerability. A local attacker could<br \/>\npossibly use this to cause a denial of service (system crash) or execute<br \/>\narbitrary code. (CVE-2023-26605)<br \/>\nSource: <a href=\"https:\/\/ubuntu.com\/security\/notices\/USN-5962-1\" target=\"_blank\" rel=\"noopener\">USN-5962-1: Linux kernel (Intel IoTG) vulnerabilities<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<div class=\"mh-excerpt\"><p>USN-5962-1: Linux kernel (Intel IoTG) vulnerabilities It was discovered that the Upper Level Protocol (ULP) subsystem in the Linux kernel did not properly handle sockets entering the LISTEN state in certain protocols, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-0461) Davide Ornaghi discovered that the netfilter subsystem in the Linux kernel did not properly handle VLAN headers in some situations. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-0179) It was discovered that the NVMe driver in the Linux kernel did not properly handle reset events in some situations. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-3169) Maxim Levitsky discovered that the KVM nested virtualization <a class=\"mh-excerpt-more\" href=\"https:\/\/jirak.net\/wp\/usn-5962-1-linux-kernel-intel-iotg-vulnerabilities\/\" title=\"USN-5962-1: Linux kernel (Intel IoTG) vulnerabilities\">[ more&#8230; ]<\/a><\/p>\n<\/div>","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[586],"tags":[587],"class_list":["post-50537","post","type-post","status-publish","format-standard","hentry","category-ubuntu-usn","tag-ubuntu-usn"],"amp_enabled":true,"_links":{"self":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/50537","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/comments?post=50537"}],"version-history":[{"count":1,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/50537\/revisions"}],"predecessor-version":[{"id":50538,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/posts\/50537\/revisions\/50538"}],"wp:attachment":[{"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/media?parent=50537"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/categories?post=50537"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/jirak.net\/wp\/wp-json\/wp\/v2\/tags?post=50537"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}