FlawAtlas
Search the atlas
USN-6868-1 Not scored

linux, linux-aws, linux-azure, linux-azure-5.4, linux-bluefield, linux-gcp, linux-gkeop, linux-hwe-5.4, linux-ibm, linux-ibm-5.4, linux-iot, linux-kvm, linux-oracle, linux-oracle-5.4, linux-raspi, linux-raspi-5.4, linux-xilinx-zynqmp vulnerabilities

Sander Wiebing, Alvise de Faveri Tron, Herbert Bos, and Cristiano Giuffrida discovered that the Linux kernel mitigations for the initial Branch History Injection vulnerability (CVE-2022-0001) were insufficient for Intel processors. A local attacker could potentially use this to expose sensitive information. (CVE-2024-2201) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Netfilter; (CVE-2024-26925, CVE-2024-26643)

Exploit probability Not scored
Published July 3, 2024
Required by Not available
Last source change August 6, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:20.04:LTS linux

100 explicit affected versions

Ubuntu:20.04:LTS linux-aws

92 explicit affected versions

Ubuntu:20.04:LTS linux-azure

88 explicit affected versions

Ubuntu:20.04:LTS linux-bluefield

51 explicit affected versions

Ubuntu:20.04:LTS linux-gcp

92 explicit affected versions

Ubuntu:20.04:LTS linux-gkeop

69 explicit affected versions

Ubuntu:20.04:LTS linux-ibm

57 explicit affected versions

Ubuntu:20.04:LTS linux-iot

30 explicit affected versions

Ubuntu:20.04:LTS linux-kvm

87 explicit affected versions

Ubuntu:20.04:LTS linux-oracle

91 explicit affected versions

Ubuntu:20.04:LTS linux-raspi

80 explicit affected versions

Ubuntu:20.04:LTS linux-xilinx-zynqmp

26 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-azure-5.4

77 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-hwe-5.4

89 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-ibm-5.4

50 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-oracle-5.4

80 explicit affected versions

Ubuntu:Pro:18.04:LTS linux-raspi-5.4

76 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-6868-1

Sander Wiebing, Alvise de Faveri Tron, Herbert Bos, and Cristiano Giuffrida discovered that the Linux kernel mitigations for the initial Branch History Injection vulnerability (CVE-2022-0001) were insufficient for Intel processors. A local attacker could potentially use this to expose sensitive information. (CVE-2024-2201) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Netfilter; (CVE-2024-26925, CVE-2024-26643)

View original source

05 / REFERENCES

Further evidence