USN-7234-1

Advisory lineage Upstream: 10 Downstream: 0
Published: 28 Jan 2025, 19:30
Last modified:06 Aug 2026, 03:07

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

28 Jan 2025, 19:30
Published
Vulnerability first disclosed
06 Aug 2026, 03:07
Last Modified
Vulnerability information updated

Description

linux, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-ibm, linux-ibm-5.4, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi vulnerabilities Ye Zhang and Nicolas Wu discovered that the io_uring subsystem in the Linux kernel did not properly handle locking for rings with IOPOLL, leading to a double-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-21400) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - TTY drivers; - Netfilter; - Network traffic control; - VMware vSockets driver; (CVE-2024-53141, CVE-2024-53103, CVE-2024-40967, CVE-2024-53164)

Affected Systems

  • ubuntulinux

    < 5.4.0-205.225

  • ubuntulinux-bluefield

    < 5.4.0-1098.105

  • ubuntulinux-gcp

    < 5.4.0-1142.151

  • ubuntulinux-gcp-5.4

    < 5.4.0-1142.151~18.04.1

  • ubuntulinux-ibm

    < 5.4.0-1085.90

  • ubuntulinux-ibm-5.4

    < 5.4.0-1085.90~18.04.1

  • ubuntulinux-kvm

    < 5.4.0-1126.134

  • ubuntulinux-oracle

    < 5.4.0-1137.146

  • ubuntulinux-oracle-5.4

    < 5.4.0-1137.146~18.04.1

  • ubuntulinux-raspi

    < 5.4.0-1122.134

References (6)