LSN-0074-1

Published: 26 Jan 2021, 07:25
Last modified:03 Jun 2026, 13:33

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

26 Jan 2021, 07:25
Published
Vulnerability first disclosed
03 Jun 2026, 13:33
Last Modified
Vulnerability information updated

Description

Kernel Live Patch Security Notice Elena Petrova discovered that the pin controller device tree implementation in the Linux kernel did not properly handle string references. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2020-0427) Andy Nguyen discovered that the Bluetooth A2MP implementation in the Linux kernel did not properly initialize memory in some situations. A physically proximate remote attacker could use this to expose sensitive information (kernel memory). (CVE-2020-12352) It was discovered that the GENEVE tunnel implementation in the Linux kernel when combined with IPSec did not properly select IP routes in some situations. An attacker could use this to expose sensitive information (unencrypted network traffic). (CVE-2020-25645) It was discovered that the LIO SCSI target implementation in the Linux kernel performed insufficient identifier checking in certain XCOPY requests. An attacker with access to at least one LUN in a multiple backstore environment could use this to expose sensitive information or modify data. (CVE-2020-28374)

Affected Systems

  • ubuntulinux

    all | < 4.4.0-262.296 | < 4.15.0-132.136 | < 5.4.0-62.70

  • ubuntulinux-aws

    all | < 4.4.0-1121.135 | < 5.4.0-1037.39

  • ubuntulinux-aws-fips

    all | < 4.15.0-2036.38

  • ubuntulinux-azure

    all | < 4.15.0-1106.118~16.04.1 | < 5.4.0-1039.41

  • ubuntulinux-azure-fips

    all | < 4.15.0-2018.21

  • ubuntulinux-fips

    all | < 4.4.0-1108.115 | < 4.15.0-1051.59

  • ubuntulinux-gcp

    all | < 5.4.0-1036.39

  • ubuntulinux-gkeop

    all | < 5.4.0-1009.10

  • ubuntulinux-gkeop-5.4

    all | < 5.4.0-1009.10~18.04.1

  • ubuntulinux-lts-xenial

    all | < 4.4.0-262.296~14.04.1

  • ubuntulinux-oem

    all | < 4.15.0-1103.114

References (5)