FlawAtlas
Search the atlas
USN-6938-1 Not scored

linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities

It was discovered that the device input subsystem in the Linux kernel did not properly handle the case when an event code falls outside of a bitmap. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-48619) 黄思聪 discovered that the NFC Controller Interface (NCI) implementation in the Linux kernel did not properly handle certain memory allocation failure conditions, leading to a null pointer dereference vulnerability. A local attacker could use this to cause a denial of service (system crash). (CVE-2023-46343) It was discovered that a race condition existed in the Bluetooth subsystem in the Linux kernel when modifying certain settings values through debugfs. A privileged local attacker could use this to cause a denial of service. (CVE-2024-24857, CVE-2024-24858, CVE-2024-24859) Chenyuan Yang discovered that the Unsorted Block Images (UBI) flash device volume management subsystem did not properly validate logical eraseblock sizes in certain situations. An attacker could possibly use this to cause a denial of service (system crash). (CVE-2024-25739) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - GPU drivers; - HID subsystem; - I2C subsystem; - Input Device Drivers (Mouse); - MTD block device drivers; - Network drivers; - TTY drivers; - USB subsystem; - File systems infrastructure; - F2FS file system; - SMB network file system; - BPF subsystem; - B.A.T.M.A.N. meshing protocol; - Bluetooth subsystem; - IPv4 networking; - IPv6 networking; - Netfilter; - Unix domain sockets; - Wireless networking; (CVE-2024-26901, CVE-2021-46932, CVE-2024-26857, CVE-2024-26882, CVE-2024-26934, CVE-2023-52449, CVE-2024-35982, CVE-2021-46933, CVE-2023-52620, CVE-2023-52444, CVE-2024-26923, CVE-2023-52469, CVE-2024-26886, CVE-2024-36902, CVE-2023-52436, CVE-2024-36016, CVE-2024-26884, CVE-2021-46960, CVE-2021-47194, CVE-2023-52752, CVE-2024-27020, CVE-2024-26840, CVE-2024-35997, CVE-2024-35984, CVE-2024-35978)

Exploit probability Not scored
Published July 31, 2024
Required by Not available
Last source change August 6, 2026

02 / AFFECTED SOFTWARE

Affected packages

Ubuntu:Pro:14.04:LTS linux-aws

97 explicit affected versions

Ubuntu:Pro:14.04:LTS linux-lts-xenial

141 explicit affected versions

Ubuntu:Pro:16.04:LTS linux

164 explicit affected versions

Ubuntu:Pro:16.04:LTS linux-aws

121 explicit affected versions

Ubuntu:Pro:16.04:LTS linux-kvm

98 explicit affected versions

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities USN-6938-1

It was discovered that the device input subsystem in the Linux kernel did not properly handle the case when an event code falls outside of a bitmap. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-48619) 黄思聪 discovered that the NFC Controller Interface (NCI) implementation in the Linux kernel did not properly handle certain memory allocation failure conditions, leading to a null pointer dereference vulnerability. A local attacker could use this to cause a denial of service (system crash). (CVE-2023-46343) It was discovered that a race condition existed in the Bluetooth subsystem in the Linux kernel when modifying certain settings values through debugfs. A privileged local attacker could use this to cause a denial of service. (CVE-2024-24857, CVE-2024-24858, CVE-2024-24859) Chenyuan Yang discovered that the Unsorted Block Images (UBI) flash device volume management subsystem did not properly validate logical eraseblock sizes in certain situations. An attacker could possibly use this to cause a denial of service (system crash). (CVE-2024-25739) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - GPU drivers; - HID subsystem; - I2C subsystem; - Input Device Drivers (Mouse); - MTD block device drivers; - Network drivers; - TTY drivers; - USB subsystem; - File systems infrastructure; - F2FS file system; - SMB network file system; - BPF subsystem; - B.A.T.M.A.N. meshing protocol; - Bluetooth subsystem; - IPv4 networking; - IPv6 networking; - Netfilter; - Unix domain sockets; - Wireless networking; (CVE-2024-26901, CVE-2021-46932, CVE-2024-26857, CVE-2024-26882, CVE-2024-26934, CVE-2023-52449, CVE-2024-35982, CVE-2021-46933, CVE-2023-52620, CVE-2023-52444, CVE-2024-26923, CVE-2023-52469, CVE-2024-26886, CVE-2024-36902, CVE-2023-52436, CVE-2024-36016, CVE-2024-26884, CVE-2021-46960, CVE-2021-47194, CVE-2023-52752, CVE-2024-27020, CVE-2024-26840, CVE-2024-35997, CVE-2024-35984, CVE-2024-35978)

View original source

05 / REFERENCES

Further evidence