USN-7234-1
Vulnerability Summary
Timeline
Description
linux, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi vulnerabilities Ye Zhang and Nicolas Wu discovered that the io_uring subsystem in the Linux kernel did not properly handle locking for rings with IOPOLL, leading to a double-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-21400) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - TTY drivers; - Netfilter; - Network traffic control; - VMware vSockets driver; (CVE-2024-53141, CVE-2024-53103, CVE-2024-40967, CVE-2024-53164)
Affected Systems
- ubuntu•linux
< 5.4.0-205.225
- ubuntu•linux-bluefield
< 5.4.0-1098.105
- ubuntu•linux-gcp
< 5.4.0-1142.151
- ubuntu•linux-gcp-5.4
< 5.4.0-1142.151~18.04.1
- ubuntu•linux-ibm
< 5.4.0-1085.90
- ubuntu•linux-ibm-5.4
< 5.4.0-1085.90~18.04.1
- ubuntu•linux-kvm
< 5.4.0-1126.134
- ubuntu•linux-oracle
< 5.4.0-1137.146
- ubuntu•linux-oracle-5.4
< 5.4.0-1137.146~18.04.1
- ubuntu•linux-raspi
< 5.4.0-1122.134