FlawAtlas
Search the atlas
USN-5339-1 Not scored

linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-dell300x, linux-hwe, linux-gcp, linux-gcp-4.15, linux-kvm, linux-oracle, linux-raspi2, linux-snapdragon vulnerabilities

Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the Linux kernel did not properly restrict access to the cgroups v1 release_agent feature. A local attacker could use this to gain administrative privileges. (CVE-2022-0492) It was discovered that an out-of-bounds (OOB) memory access flaw existed in the f2fs module of the Linux kernel. A local attacker could use this issue to cause a denial of service (system crash). (CVE-2021-3506) Brendan Dolan-Gavitt discovered that the Marvell WiFi-Ex USB device driver in the Linux kernel did not properly handle some error conditions. A physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2021-43976) It was discovered that the ARM Trusted Execution Environment (TEE) subsystem in the Linux kernel contained a race condition leading to a use- after-free vulnerability. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2021-44733) It was discovered that the Phone Network protocol (PhoNet) implementation in the Linux kernel did not properly perform reference counting in some error conditions. A local attacker could possibly use this to cause a denial of service (memory exhaustion). (CVE-2021-45095) Samuel Page discovered that the Transparent Inter-Process Communication (TIPC) protocol implementation in the Linux kernel contained a stack-based buffer overflow. A remote attacker could use this to cause a denial of service (system crash) for systems that have a TIPC bearer configured. (CVE-2022-0435)

Exploit probability Not scored
Published March 22, 2022
Required by Not available
Last source change June 29, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:18.04:LTS linux

90 explicit affected versions

Ubuntu:18.04:LTS linux-aws

78 explicit affected versions

Ubuntu:18.04:LTS linux-azure-4.15

34 explicit affected versions

Ubuntu:18.04:LTS linux-dell300x

22 explicit affected versions

Ubuntu:18.04:LTS linux-gcp-4.15

33 explicit affected versions

Ubuntu:18.04:LTS linux-kvm

72 explicit affected versions

Ubuntu:18.04:LTS linux-oracle

58 explicit affected versions

Ubuntu:18.04:LTS linux-raspi2

76 explicit affected versions

Ubuntu:18.04:LTS linux-snapdragon

56 explicit affected versions

Ubuntu:Pro:14.04:LTS linux-azure

65 explicit affected versions

Ubuntu:Pro:16.04:LTS linux-aws-hwe

57 explicit affected versions

Ubuntu:Pro:16.04:LTS linux-azure

88 explicit affected versions

Ubuntu:Pro:16.04:LTS linux-gcp

80 explicit affected versions

Ubuntu:Pro:16.04:LTS linux-hwe

105 explicit affected versions

Ubuntu:Pro:16.04:LTS linux-oracle

56 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-5339-1

Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the Linux kernel did not properly restrict access to the cgroups v1 release_agent feature. A local attacker could use this to gain administrative privileges. (CVE-2022-0492) It was discovered that an out-of-bounds (OOB) memory access flaw existed in the f2fs module of the Linux kernel. A local attacker could use this issue to cause a denial of service (system crash). (CVE-2021-3506) Brendan Dolan-Gavitt discovered that the Marvell WiFi-Ex USB device driver in the Linux kernel did not properly handle some error conditions. A physically proximate attacker could use this to cause a denial of service (system crash). (CVE-2021-43976) It was discovered that the ARM Trusted Execution Environment (TEE) subsystem in the Linux kernel contained a race condition leading to a use- after-free vulnerability. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2021-44733) It was discovered that the Phone Network protocol (PhoNet) implementation in the Linux kernel did not properly perform reference counting in some error conditions. A local attacker could possibly use this to cause a denial of service (memory exhaustion). (CVE-2021-45095) Samuel Page discovered that the Transparent Inter-Process Communication (TIPC) protocol implementation in the Linux kernel contained a stack-based buffer overflow. A remote attacker could use this to cause a denial of service (system crash) for systems that have a TIPC bearer configured. (CVE-2022-0435)

View original source

05 / REFERENCES

Further evidence