USN-5592-1

Advisory lineage Upstream: 4 Downstream: 0
Published: 01 Sept 2022, 19:14
Last modified:14 Sept 2026, 11:17

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

01 Sept 2022, 19:14
Published
Vulnerability first disclosed
14 Sept 2026, 11:17
Last Modified
Vulnerability information updated

Description

linux-aws, linux-azure, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gke, linux-gkeop, linux-ibm, linux-ibm-5.4, linux-kvm, linux-oracle, linux-oracle-5.4 vulnerabilities Asaf Modelevsky discovered that the Intel(R) 10GbE PCI Express (ixgbe) Ethernet driver for the Linux kernel performed insufficient control flow management. A local attacker could possibly use this to cause a denial of service. (CVE-2021-33061) It was discovered that the virtual terminal driver in the Linux kernel did not properly handle VGA console font changes, leading to an out-of-bounds write. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-33656)

Affected Systems

  • ubuntulinux-aws

    < 5.4.0-1084.91

  • ubuntulinux-azure

    < 5.4.0-1090.95

  • ubuntulinux-bluefield

    < 5.4.0-1045.50

  • ubuntulinux-gcp

    < 5.4.0-1087.95

  • ubuntulinux-gcp-5.4

    < 5.4.0-1087.95~18.04.1

  • ubuntulinux-gke

    < 5.4.0-1081.87

  • ubuntulinux-gkeop

    < 5.4.0-1052.55

  • ubuntulinux-ibm

    < 5.4.0-1032.36

  • ubuntulinux-ibm-5.4

    < 5.4.0-1032.36~18.04.1

  • ubuntulinux-kvm

    < 5.4.0-1074.79

  • ubuntulinux-oracle

    < 5.4.0-1082.90

  • ubuntulinux-oracle-5.4

    < 5.4.0-1082.90~18.04.1

References (3)