USN-4302-1

Advisory lineage Upstream: 18 Downstream: 0
Published: 25 Mar 2020, 03:12
Last modified:23 May 2026, 01:48

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

25 Mar 2020, 03:12
Published
Vulnerability first disclosed
23 May 2026, 01:48
Last Modified
Vulnerability information updated

Description

linux, linux-aws, linux-aws-hwe, linux-gcp, linux-gke-4.15, linux-hwe, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon, linux-azure vulnerabilities Paulo Bonzini discovered that the KVM hypervisor implementation in the Linux kernel could improperly let a nested (level 2) guest access the resources of a parent (level 1) guest in certain situations. An attacker could use this to expose sensitive information. (CVE-2020-2732) Gregory Herrero discovered that the fix for CVE-2019-14615 to address the Linux kernel not properly clearing data structures on context switches for certain Intel graphics processors was incomplete. A local attacker could use this to expose sensitive information. (CVE-2020-8832) It was discovered that the IPMI message handler implementation in the Linux kernel did not properly deallocate memory in certain situations. A local attacker could use this to cause a denial of service (kernel memory exhaustion). (CVE-2019-19046) It was discovered that the Intel WiMAX 2400 driver in the Linux kernel did not properly deallocate memory in certain situations. A local attacker could use this to cause a denial of service (kernel memory exhaustion). (CVE-2019-19051) It was discovered that the Marvell Wi-Fi device driver in the Linux kernel did not properly deallocate memory in certain error conditions. A local attacker could use this to possibly cause a denial of service (kernel memory exhaustion). (CVE-2019-19056) It was discovered that the Intel(R) Wi-Fi device driver in the Linux kernel device driver in the Linux kernel did not properly deallocate memory in certain error conditions. A local attacker could possibly use this to cause a denial of service (kernel memory exhaustion). (CVE-2019-19058) It was discovered that the Brocade BFA Fibre Channel device driver in the Linux kernel did not properly deallocate memory in certain error conditions. A local attacker could possibly use this to cause a denial of service (kernel memory exhaustion). (CVE-2019-19066) It was discovered that the Realtek RTL8xxx USB Wi-Fi device driver in the Linux kernel did not properly deallocate memory in certain error conditions. A local attacker could possibly use this to cause a denial of service (kernel memory exhaustion). (CVE-2019-19068) It was discovered that ZR364XX Camera USB device driver for the Linux kernel did not properly initialize memory. A physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2019-15217)

Affected Systems

  • ubuntulinux

    < 4.15.0-91.92

  • ubuntulinux-aws

    < 4.15.0-1063.67

  • ubuntulinux-aws-hwe

    < 4.15.0-1063.67~16.04.1

  • ubuntulinux-azure

    < 4.15.0-1074.79~14.04.1 | < 4.15.0-1075.80

  • ubuntulinux-gcp

    < 4.15.0-1058.62

  • ubuntulinux-gke-4.15

    < 4.15.0-1055.58

  • ubuntulinux-hwe

    < 4.15.0-91.92~16.04.1

  • ubuntulinux-kvm

    < 4.15.0-1056.57

  • ubuntulinux-oem

    < 4.15.0-1076.86

  • ubuntulinux-oracle

    < 4.15.0-1035.38~16.04.1 | < 4.15.0-1035.39

  • ubuntulinux-raspi2

    < 4.15.0-1057.61

  • ubuntulinux-snapdragon

    < 4.15.0-1074.81

References (10)