USN-6702-2
Vulnerability Summary
Timeline
Description
linux-aws, linux-aws-5.4, linux-gcp-5.4, linux-raspi, linux-raspi-5.4, linux-xilinx-zynqmp vulnerabilities It was discovered that the NVIDIA Tegra XUSB pad controller driver in the Linux kernel did not properly handle return values in certain error conditions. A local attacker could use this to cause a denial of service (system crash). (CVE-2023-23000) It was discovered that the ARM Mali Display Processor driver implementation in the Linux kernel did not properly handle certain error conditions. A local attacker could possibly use this to cause a denial of service (system crash). (CVE-2023-23004) Notselwyn discovered that the netfilter subsystem in the Linux kernel did not properly handle verdict parameters in certain cases, leading to a use- after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2024-1086) It was discovered that a race condition existed in the SCSI Emulex LightPulse Fibre Channel driver in the Linux kernel when unregistering FCF and re-scanning an HBA FCF table, leading to a null pointer dereference vulnerability. A local attacker could use this to cause a denial of service (system crash). (CVE-2024-24855)
Affected Systems
- ubuntu•linux-aws
< 5.4.0-1121.131
- ubuntu•linux-aws-5.4
< 5.4.0-1121.131~18.04.1
- ubuntu•linux-gcp-5.4
< 5.4.0-1125.134~18.04.1
- ubuntu•linux-raspi
< 5.4.0-1105.117
- ubuntu•linux-raspi-5.4
< 5.4.0-1105.117~18.04.1
- ubuntu•linux-xilinx-zynqmp
< 5.4.0-1040.44