USN-5413-1

Advisory lineage Upstream: 12 Downstream: 0
Published: 12 May 2022, 00:03
Last modified:23 May 2026, 01:33

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

12 May 2022, 00:03
Published
Vulnerability first disclosed
23 May 2026, 01:33
Last Modified
Vulnerability information updated

Description

linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities Jeremy Cline discovered a use-after-free in the nouveau graphics driver of the Linux kernel during device removal. A privileged or physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2020-27820) It was discovered that a race condition existed in the network scheduling subsystem of the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-39713) It was discovered that the Parallel NFS (pNFS) implementation in the Linux kernel did not properly perform bounds checking in some situations. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-4157) It was discovered that the ST21NFCA NFC driver in the Linux kernel did not properly validate the size of certain data in EVT_TRANSACTION events. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-26490) It was discovered that the Xilinx USB2 device gadget driver in the Linux kernel did not properly validate endpoint indices from the host. A physically proximate attacker could possibly use this to cause a denial of service (system crash). (CVE-2022-27223) It was discovered that the EMS CAN/USB interface implementation in the Linux kernel contained a double-free vulnerability when handling certain error conditions. A local attacker could use this to cause a denial of service (memory exhaustion). (CVE-2022-28390)

Affected Systems

  • ubuntulinux

    < 4.4.0-224.257

  • ubuntulinux-aws

    < 4.4.0-1140.154

  • ubuntulinux-kvm

    < 4.4.0-1105.114

  • ubuntulinux-lts-xenial

    < 4.4.0-224.257~14.04.1

References (7)