LSN-0076-1
Vulnerability Summary
Timeline
Description
Kernel Live Patch Security Notice It was discovered that the overlayfs implementation in the Linux kernel did not properly validate the application of file system capabilities with respect to user namespaces. A local attacker could use this to gain elevated privileges.(CVE-2021-3493) Piotr Krysiuk discovered that the BPF JIT compiler for x86 in the Linux kernel did not properly validate computation of branch displacements in some situations. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.(CVE-2021-29154)
Affected Systems
- ubuntu•linux
all | < 4.4.0-209.241 | < 4.15.0-142.146 | < 5.4.0-72.80
- ubuntu•linux-aws
all | < 4.4.0-1127.141 | < 4.15.0-1099.106 | < 5.4.0-1045.47
- ubuntu•linux-azure
all | < 4.15.0-1113.126~16.04.1 | < 5.4.0-1046.48
- ubuntu•linux-gcp
all | < 5.4.0-1042.45
- ubuntu•linux-gke
all | < 5.4.0-1042.44
- ubuntu•linux-gke-4.15
all
- ubuntu•linux-gke-5.4
all | < 5.4.0-1042.44~18.04.1
- ubuntu•linux-gkeop
all | < 5.4.0-1014.15
- ubuntu•linux-gkeop-5.4
all | < 5.4.0-1014.15~18.04.1
- ubuntu•linux-hwe
all | < 4.15.0-142.146~16.04.1
- ubuntu•linux-hwe-5.4
all | < 5.4.0-72.80~18.04.1
- ubuntu•linux-lts-xenial
all | < 4.4.0-209.241~14.04.1
- ubuntu•linux-oem
all