USN-4369-1
Vulnerability Summary
Timeline
Description
linux, linux-aws, linux-aws-5.3, linux-azure, linux-azure-5.3, linux-gcp, linux-gcp-5.3, linux-gke-5.3, linux-hwe, linux-kvm, linux-oracle, linux-oracle-5.3, linux-raspi2 vulnerabilities It was discovered that the btrfs implementation in the Linux kernel did not properly detect that a block was marked dirty in some situations. An attacker could use this to specially craft a file system image that, when unmounted, could cause a denial of service (system crash). (CVE-2019-19377) Tristan Madani discovered that the file locking implementation in the Linux kernel contained a race condition. A local attacker could possibly use this to cause a denial of service or expose sensitive information. (CVE-2019-19769) It was discovered that the Serial CAN interface driver in the Linux kernel did not properly initialize data. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2020-11494) It was discovered that the linux kernel did not properly validate certain mount options to the tmpfs virtual memory file system. A local attacker with the ability to specify mount options could use this to cause a denial of service (system crash). (CVE-2020-11565) It was discovered that the OV51x USB Camera device driver in the Linux kernel did not properly validate device metadata. A physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2020-11608) It was discovered that the STV06XX USB Camera device driver in the Linux kernel did not properly validate device metadata. A physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2020-11609) It was discovered that the Xirlink C-It USB Camera device driver in the Linux kernel did not properly validate device metadata. A physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2020-11668) It was discovered that the block layer in the Linux kernel contained a race condition leading to a use-after-free vulnerability. A local attacker could possibly use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2020-12657)
Affected Systems
- ubuntu•linux-aws-5.3
< 5.3.0-1019.21~18.04.1
- ubuntu•linux-azure-5.3
< 5.3.0-1022.23~18.04.1
- ubuntu•linux-gcp-5.3
< 5.3.0-1020.22~18.04.1
- ubuntu•linux-gke-5.3
< 5.3.0-1020.22~18.04.1
- ubuntu•linux-hwe
< 5.3.0-53.47~18.04.1
- ubuntu•linux-oracle-5.3
< 5.3.0-1018.20~18.04.1
References (10)
- https://ubuntu.com/security/notices/USN-4369-1
- https://ubuntu.com/security/CVE-2019-19377
- https://ubuntu.com/security/CVE-2019-19769
- https://ubuntu.com/security/CVE-2020-11494
- https://ubuntu.com/security/CVE-2020-11565
- https://ubuntu.com/security/CVE-2020-11608
- https://ubuntu.com/security/CVE-2020-11609
- https://ubuntu.com/security/CVE-2020-11668
- https://ubuntu.com/security/CVE-2020-12657
- https://ubuntu.com/security/CVE-2020-12826