USN-4324-1

Advisory lineage Upstream: 4 Downstream: 0
Published: 07 Apr 2020, 21:00
Last modified:03 Jun 2026, 14:03

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

07 Apr 2020, 21:00
Published
Vulnerability first disclosed
03 Jun 2026, 14:03
Last Modified
Vulnerability information updated

Description

linux-aws, linux-aws-hwe, linux-azure, linux-gcp, linux-gke-4.15, linux-kvm, linux-oem, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities Al Viro discovered that the vfs layer in the Linux kernel contained a use- after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information (kernel memory). (CVE-2020-8428) Shijie Luo discovered that the ext4 file system implementation in the Linux kernel did not properly check for a too-large journal size. An attacker could use this to construct a malicious ext4 image that, when mounted, could cause a denial of service (soft lockup). (CVE-2020-8992)

Affected Systems

  • ubuntulinux-aws

    < 4.15.0-1065.69

  • ubuntulinux-aws-hwe

    < 4.15.0-1065.69~16.04.1

  • ubuntulinux-azure

    < 4.15.0-1077.82~14.04.1 | < 4.15.0-1077.82

  • ubuntulinux-gcp

    < 4.15.0-1060.64

  • ubuntulinux-gke-4.15

    < 4.15.0-1057.60

  • ubuntulinux-kvm

    < 4.15.0-1058.59

  • ubuntulinux-oem

    < 4.15.0-1079.89

  • ubuntulinux-oracle

    < 4.15.0-1037.41~16.04.1 | < 4.15.0-1037.41

  • ubuntulinux-raspi2

    < 4.15.0-1060.64

  • ubuntulinux-snapdragon

    < 4.15.0-1076.83

References (3)