FlawAtlas
Search the atlas
USN-6923-1 Not scored

linux, linux-aws, linux-gcp, linux-gke, linux-gkeop, linux-gkeop-5.15, linux-hwe-5.15, linux-intel-iotg, linux-intel-iotg-5.15, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-oracle vulnerabilities

Benedict Schlüter, Supraja Sridhara, Andrin Bertschi, and Shweta Shinde discovered that an untrusted hypervisor could inject malicious #VC interrupts and compromise the security guarantees of AMD SEV-SNP. This flaw is known as WeSee. A local attacker in control of the hypervisor could use this to expose sensitive information or possibly execute arbitrary code in the trusted execution environment. (CVE-2024-25742) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - TTY drivers; - SMB network file system; - Netfilter; - Bluetooth subsystem; (CVE-2024-26886, CVE-2024-26952, CVE-2023-52752, CVE-2024-27017, CVE-2024-36016)

Exploit probability Not scored
Published July 29, 2024
Required by Not available
Last source change August 6, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:20.04:LTS linux-gkeop-5.15

38 explicit affected versions

Ubuntu:20.04:LTS linux-hwe-5.15

41 explicit affected versions

Ubuntu:20.04:LTS linux-intel-iotg-5.15

32 explicit affected versions

Ubuntu:20.04:LTS linux-lowlatency-hwe-5.15

41 explicit affected versions

Ubuntu:22.04:LTS linux

55 explicit affected versions

Ubuntu:22.04:LTS linux-aws

50 explicit affected versions

Ubuntu:22.04:LTS linux-gcp

49 explicit affected versions

Ubuntu:22.04:LTS linux-gke

48 explicit affected versions

Ubuntu:22.04:LTS linux-gkeop

41 explicit affected versions

Ubuntu:22.04:LTS linux-intel-iotg

38 explicit affected versions

Ubuntu:22.04:LTS linux-kvm

52 explicit affected versions

Ubuntu:22.04:LTS linux-lowlatency

52 explicit affected versions

Ubuntu:22.04:LTS linux-nvidia

33 explicit affected versions

Ubuntu:22.04:LTS linux-oracle

49 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-6923-1

Benedict Schlüter, Supraja Sridhara, Andrin Bertschi, and Shweta Shinde discovered that an untrusted hypervisor could inject malicious #VC interrupts and compromise the security guarantees of AMD SEV-SNP. This flaw is known as WeSee. A local attacker in control of the hypervisor could use this to expose sensitive information or possibly execute arbitrary code in the trusted execution environment. (CVE-2024-25742) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - TTY drivers; - SMB network file system; - Netfilter; - Bluetooth subsystem; (CVE-2024-26886, CVE-2024-26952, CVE-2023-52752, CVE-2024-27017, CVE-2024-36016)

View original source

05 / REFERENCES

Further evidence