LSN-0083-1

Advisory lineage Upstream: 10 Downstream: 0
Published: 06 Jan 2022, 08:48
Last modified:03 Jun 2026, 13:33

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Jan 2022, 08:48
Published
Vulnerability first disclosed
03 Jun 2026, 13:33
Last Modified
Vulnerability information updated

Description

Kernel Live Patch Security Notice The BPF subsystem in the Linux kernel before 4.17 mishandles situations with a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions, leading to an overflow. This affects kernel/bpf/core.c and net/core/filter.c.(CVE-2018-25020) Maxim Levitsky discovered that the KVM hypervisor implementation for AMD processors in the Linux kernel did not properly prevent a guest VM from enabling AVIC in nested guest VMs. An attacker in a guest VM could use this to write to portions of the host's physical memory.(CVE-2021-3653) Nadav Amit discovered that the hugetlb implementation in the Linux kernel did not perform TLB flushes under certain conditions. A local attacker could use this to leak or alter data from other processes that use huge pages.(CVE-2021-4002) Andy Nguyen discovered that the netfilter subsystem in the Linux kernel contained an out-of-bounds write in its setsockopt() implementation. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.(CVE-2021-22555) It was discovered that the virtual file system implementation in the Linux kernel contained an unsigned to signed integer conversion error. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code.(CVE-2021-33909)

Affected Systems

  • ubuntulinux

    all | < 4.4.0-218.251 | < 4.15.0-166.174 | < 5.4.0-92.103

  • ubuntulinux-aws

    all | < 4.4.0-1134.148 | < 4.15.0-1118.125 | < 5.4.0-1061.64

  • ubuntulinux-azure

    all | < 4.15.0-1129.142~16.04.1 | < 5.4.0-1065.68

  • ubuntulinux-gcp

    all | < 5.4.0-1059.63

  • ubuntulinux-gke

    all | < 5.4.0-1057.60

  • ubuntulinux-gke-4.15

    all

  • ubuntulinux-gke-5.4

    all | < 5.4.0-1057.60~18.04.1

  • ubuntulinux-gkeop

    all | < 5.4.0-1029.30

  • ubuntulinux-gkeop-5.4

    all | < 5.4.0-1029.30~18.04.2

  • ubuntulinux-hwe

    all | < 4.15.0-166.174~16.04.1

  • ubuntulinux-oem

    all

References (6)