USN-5562-1

Advisory lineage Upstream: 22 Downstream: 0
Published: 10 Aug 2022, 14:30
Last modified:03 Jun 2026, 13:34

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

10 Aug 2022, 14:30
Published
Vulnerability first disclosed
03 Jun 2026, 13:34
Last Modified
Vulnerability information updated

Description

linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gke, linux-gke-5.4, linux-gkeop, linux-gkeop-5.4, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4 vulnerabilities Zhenpeng Lin discovered that the network packet scheduler implementation in the Linux kernel did not properly remove all references to a route filter before freeing it in some situations. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-2588) It was discovered that the netfilter subsystem of the Linux kernel did not prevent one nft object from referencing an nft set in another nft table, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-2586) It was discovered that the block layer subsystem in the Linux kernel did not properly initialize memory in some situations. A privileged local attacker could use this to expose sensitive information (kernel memory). (CVE-2022-0494) Hu Jiahui discovered that multiple race conditions existed in the Advanced Linux Sound Architecture (ALSA) framework, leading to use-after-free vulnerabilities. A local attacker could use these to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-1048) Minh Yuan discovered that the floppy disk driver in the Linux kernel contained a race condition, leading to a use-after-free vulnerability. A local attacker could possibly use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-1652) It was discovered that the Atheros ath9k wireless device driver in the Linux kernel did not properly handle some error conditions, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-1679) It was discovered that the Marvell NFC device driver implementation in the Linux kernel did not properly perform memory cleanup operations in some situations, leading to a use-after-free vulnerability. A local attacker could possibly use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-1734) Duoming Zhou discovered a race condition in the NFC subsystem in the Linux kernel, leading to a use-after-free vulnerability. A privileged local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-1974) Duoming Zhou discovered that the NFC subsystem in the Linux kernel did not properly prevent context switches from occurring during certain atomic context operations. A privileged local attacker could use this to cause a denial of service (system crash). (CVE-2022-1975) Felix Fu discovered that the Sun RPC implementation in the Linux kernel did not properly handle socket states, leading to a use-after-free vulnerability. A remote attacker could possibly use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-28893) Arthur Mongodin discovered that the netfilter subsystem in the Linux kernel did not properly perform data validation. A local attacker could use this to escalate privileges in certain situations. (CVE-2022-34918)

Affected Systems

  • ubuntulinux

    < 5.4.0-124.140

  • ubuntulinux-aws

    < 5.4.0-1083.90

  • ubuntulinux-aws-5.4

    < 5.4.0-1083.90~18.04.1

  • ubuntulinux-azure

    < 5.4.0-1089.94

  • ubuntulinux-azure-5.4

    < 5.4.0-1089.94~18.04.1

  • ubuntulinux-bluefield

    < 5.4.0-1044.49

  • ubuntulinux-gcp

    < 5.4.0-1086.94

  • ubuntulinux-gcp-5.4

    < 5.4.0-1086.94~18.04.1

  • ubuntulinux-gke

    < 5.4.0-1080.86

  • ubuntulinux-gke-5.4

    < 5.4.0-1080.86~18.04.1

  • ubuntulinux-gkeop

    < 5.4.0-1051.54

  • ubuntulinux-gkeop-5.4

    < 5.4.0-1051.54~18.04.1

  • ubuntulinux-hwe-5.4

    < 5.4.0-124.140~18.04.1

  • ubuntulinux-ibm

    < 5.4.0-1031.35

  • ubuntulinux-ibm-5.4

    < 5.4.0-1031.35~18.04.1

  • ubuntulinux-kvm

    < 5.4.0-1073.78

  • ubuntulinux-oracle

    < 5.4.0-1081.89

  • ubuntulinux-oracle-5.4

    < 5.4.0-1081.89~18.04.1

  • ubuntulinux-raspi

    < 5.4.0-1068.78

  • ubuntulinux-raspi-5.4

    < 5.4.0-1068.78~18.04.1

References (12)