FlawAtlas
Search the atlas
USN-6605-1 Not scored

linux, linux-aws, linux-aws-5.4, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gcp-5.4, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4, linux-xilinx-zynqmp vulnerabilities

Lin Ma discovered that the netfilter subsystem in the Linux kernel did not properly validate network family support while creating a new netfilter table. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2023-6040) It was discovered that the CIFS network file system implementation in the Linux kernel did not properly validate the server frame size in certain situation, leading to an out-of-bounds read vulnerability. An attacker could use this to construct a malicious CIFS image that, when operated on, could cause a denial of service (system crash) or possibly expose sensitive information. (CVE-2023-6606) Budimir Markovic, Lucas De Marchi, and Pengfei Xu discovered that the perf subsystem in the Linux kernel did not properly validate all event sizes when attaching new events, leading to an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-6931) It was discovered that the IGMP protocol implementation in the Linux kernel contained a race condition, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-6932)

Exploit probability Not scored
Published January 25, 2024
Required by Not available
Last source change June 3, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:20.04:LTS linux

90 explicit affected versions

Ubuntu:20.04:LTS linux-aws

82 explicit affected versions

Ubuntu:20.04:LTS linux-azure

79 explicit affected versions

Ubuntu:20.04:LTS linux-bluefield

41 explicit affected versions

Ubuntu:20.04:LTS linux-gcp

82 explicit affected versions

Ubuntu:20.04:LTS linux-gkeop

59 explicit affected versions

Ubuntu:20.04:LTS linux-ibm

47 explicit affected versions

Ubuntu:20.04:LTS linux-iot

20 explicit affected versions

Ubuntu:20.04:LTS linux-oracle

81 explicit affected versions

Ubuntu:20.04:LTS linux-raspi

70 explicit affected versions

Ubuntu:20.04:LTS linux-xilinx-zynqmp

16 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-aws-5.4

69 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-azure-5.4

68 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-gcp-5.4

71 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-hwe-5.4

79 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-ibm-5.4

40 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-oracle-5.4

70 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-raspi-5.4

66 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-6605-1

Lin Ma discovered that the netfilter subsystem in the Linux kernel did not properly validate network family support while creating a new netfilter table. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2023-6040) It was discovered that the CIFS network file system implementation in the Linux kernel did not properly validate the server frame size in certain situation, leading to an out-of-bounds read vulnerability. An attacker could use this to construct a malicious CIFS image that, when operated on, could cause a denial of service (system crash) or possibly expose sensitive information. (CVE-2023-6606) Budimir Markovic, Lucas De Marchi, and Pengfei Xu discovered that the perf subsystem in the Linux kernel did not properly validate all event sizes when attaching new events, leading to an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-6931) It was discovered that the IGMP protocol implementation in the Linux kernel contained a race condition, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-6932)

View original source

05 / REFERENCES

Further evidence