USN-4320-1
Advisory lineage Upstream: 2 Downstream: 0
Upstream
Published: 06 Apr 2020, 20:15
Last modified:03 Jun 2026, 13:33
Vulnerability Summary
Overall Risk (default)
minimal
0/100 CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected
Timeline
06 Apr 2020, 20:15
Published
Vulnerability first disclosed
03 Jun 2026, 13:33
Last Modified
Vulnerability information updated
Description
linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerability Al Viro discovered that the vfs layer in the Linux kernel contained a use- after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information (kernel memory).
Affected Systems
- ubuntu•linux
< 4.4.0-177.207
- ubuntu•linux-aws
< 4.4.0-1065.69 | < 4.4.0-1105.116
- ubuntu•linux-kvm
< 4.4.0-1069.76
- ubuntu•linux-lts-xenial
< 4.4.0-177.207~14.04.1
- ubuntu•linux-raspi2
< 4.4.0-1131.140
- ubuntu•linux-snapdragon
< 4.4.0-1135.143