LSN-0091-1
Vulnerability Summary
Timeline
Description
Kernel Live Patch Security Notice It was discovered that a race condition existed in the memory address space accounting implementation in the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.(CVE-2022-41222) Sönke Huster discovered that a use-after-free vulnerability existed in the WiFi driver stack in the Linux kernel. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.(CVE-2022-42719)
Affected Systems
- ubuntu•linux
all | < 5.4.0-132.148 | < 5.15.0-52.58
- ubuntu•linux-aws
all | < 5.4.0-1089.97 | < 5.15.0-1022.26
- ubuntu•linux-aws-5.4
all | < 5.4.0-1089.97~18.04.1
- ubuntu•linux-azure
all | < 5.4.0-1095.101 | < 5.15.0-1022.27
- ubuntu•linux-azure-5.4
all | < 5.4.0-1095.101~18.04.1
- ubuntu•linux-gcp
all | < 5.4.0-1093.102 | < 5.15.0-1021.28
- ubuntu•linux-gcp-5.4
all | < 5.4.0-1093.102~18.04.1
- ubuntu•linux-gke
all | < 5.4.0-1087.94 | < 5.15.0-1019.23
- ubuntu•linux-gke-5.4
all
- ubuntu•linux-gkeop
all | < 5.4.0-1057.61
- ubuntu•linux-gkeop-5.4
all
- ubuntu•linux-hwe-5.4
all | < 5.4.0-132.148~18.04.1
- ubuntu•linux-ibm
all | < 5.4.0-1037.42 | < 5.15.0-1017.20
- ubuntu•linux-ibm-5.4
all | < 5.4.0-1037.42~18.04.1