USN-5390-1
Vulnerability Summary
Timeline
Description
linux, linux-aws, linux-azure, linux-gcp, linux-gke, linux-ibm, linux-kvm, linux-lowlatency vulnerabilities David Bouman discovered that the netfilter subsystem in the Linux kernel did not properly validate passed user register indices. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2022-1015) David Bouman discovered that the netfilter subsystem in the Linux kernel did not initialize memory in some situations. A local attacker could use this to expose sensitive information (kernel memory). (CVE-2022-1016) It was discovered that the ST21NFCA NFC driver in the Linux kernel did not properly validate the size of certain data in EVT_TRANSACTION events. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-26490)
Affected Systems
- ubuntu•linux
< 5.15.0-27.28
- ubuntu•linux-aws
< 5.15.0-1005.7
- ubuntu•linux-azure
< 5.15.0-1005.6
- ubuntu•linux-gcp
< 5.15.0-1004.7
- ubuntu•linux-gke
< 5.15.0-1003.3
- ubuntu•linux-ibm
< 5.15.0-1003.3
- ubuntu•linux-kvm
< 5.15.0-1005.5
- ubuntu•linux-lowlatency
< 5.15.0-27.28
- ubuntu•linux-oracle
< 5.15.0-1003.5