USN-5358-1
Vulnerability Summary
Timeline
Description
linux, linux-aws, linux-azure, linux-gcp, linux-hwe-5.13, linux-hwe-5.4, linux-kvm, linux-oracle, linux-oracle-5.4 vulnerabilities It was discovered that the network traffic control implementation in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-1055) It was discovered that the IPsec implementation in the Linux kernel did not properly allocate enough memory when performing ESP transformations, leading to a heap-based buffer overflow. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-27666)
Affected Systems
- ubuntu•linux
< 5.4.0-107.121
- ubuntu•linux-aws
< 5.4.0-1071.76
- ubuntu•linux-azure
< 5.4.0-1074.77
- ubuntu•linux-hwe-5.13
< 5.13.0-39.44~20.04.1
- ubuntu•linux-hwe-5.4
< 5.4.0-107.121~18.04.1
- ubuntu•linux-kvm
< 5.4.0-1061.64
- ubuntu•linux-oracle
< 5.4.0-1069.75
- ubuntu•linux-oracle-5.4
< 5.4.0-1069.75~18.04.1