LSN-0085-1
Vulnerability Summary
Timeline
Description
Kernel Live Patch Security Notice Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the Linux kernel did not properly restrict access to the cgroups v1 release_agent feature. A local attacker could use this to gain administrative privileges.(CVE-2022-0492) Nick Gregory discovered that the Linux kernel incorrectly handled network offload functionality. A local attacker could use this to cause a denial of service or possibly execute arbitrary code.(CVE-2022-25636)
Affected Systems
- ubuntu•linux
all | < 4.4.0-222.255 | < 4.15.0-173.182 | < 5.4.0-105.119
- ubuntu•linux-aws
all | < 4.4.0-1138.152 | < 4.15.0-1124.133 | < 5.4.0-1069.73
- ubuntu•linux-azure
all | < 4.15.0-1134.147~16.04.1 | < 5.4.0-1073.76
- ubuntu•linux-azure-4.15
all | < 4.15.0-1134.147
- ubuntu•linux-gcp
all | < 5.4.0-1068.72
- ubuntu•linux-gke
all | < 5.4.0-1066.69
- ubuntu•linux-gke-4.15
all
- ubuntu•linux-gke-5.4
all | < 5.4.0-1066.69~18.04.1
- ubuntu•linux-gkeop
all | < 5.4.0-1037.38
- ubuntu•linux-gkeop-5.4
all | < 5.4.0-1037.38~18.04.1
- ubuntu•linux-hwe
all | < 4.15.0-173.182~16.04.1
- ubuntu•linux-hwe-5.4
all | < 5.4.0-105.119~18.04.1
- ubuntu•linux-ibm
all | < 5.4.0-1018.20
- ubuntu•linux-ibm-5.4
all | < 5.4.0-1018.20~18.04.1
- ubuntu•linux-lts-xenial
all | < 4.4.0-222.255~14.04.1
- ubuntu•linux-oem
all