USN-4320-1

Advisory lineage Upstream: 2 Downstream: 0
Published: 06 Apr 2020, 20:15
Last modified:03 Jun 2026, 13:33

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

06 Apr 2020, 20:15
Published
Vulnerability first disclosed
03 Jun 2026, 13:33
Last Modified
Vulnerability information updated

Description

linux, linux-aws, linux-kvm, linux-raspi2, linux-snapdragon vulnerability Al Viro discovered that the vfs layer in the Linux kernel contained a use- after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information (kernel memory).

Affected Systems

  • ubuntulinux

    < 4.4.0-177.207

  • ubuntulinux-aws

    < 4.4.0-1065.69 | < 4.4.0-1105.116

  • ubuntulinux-kvm

    < 4.4.0-1069.76

  • ubuntulinux-lts-xenial

    < 4.4.0-177.207~14.04.1

  • ubuntulinux-raspi2

    < 4.4.0-1131.140

  • ubuntulinux-snapdragon

    < 4.4.0-1135.143

References (2)