linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities
It was discovered that the JFS file system contained an out-of-bounds read vulnerability when printing xattr debug information. A local attacker could use this to cause a denial of service (system crash). Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - GPU drivers; - Greybus drivers; - Modular ISDN driver; - Multiple devices driver; - Network drivers; - SCSI drivers; - VFIO drivers; - F2FS file system; - GFS2 file system; - JFS file system; - NILFS2 file system; - Kernel debugger infrastructure; - Bluetooth subsystem; - IPv4 networking; - L2TP protocol; - Netfilter; - RxRPC session sockets; (CVE-2024-42154, CVE-2023-52527, CVE-2024-26733, CVE-2024-42160, CVE-2021-47188, CVE-2024-38570, CVE-2024-26851, CVE-2024-26984, CVE-2024-26677, CVE-2024-39480, CVE-2024-27398, CVE-2022-48791, CVE-2024-42224, CVE-2024-38583, CVE-2024-40902, CVE-2023-52809, CVE-2024-39495, CVE-2024-26651, CVE-2024-26880, CVE-2024-42228, CVE-2024-27437, CVE-2022-48863)
02 / AFFECTED SOFTWARE
Affected packages
93 explicit affected versions
120 explicit affected versions
116 explicit affected versions
143 explicit affected versions
92 explicit affected versions
129 explicit affected versions
116 explicit affected versions
69 explicit affected versions
70 explicit affected versions
109 explicit affected versions
95 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
It was discovered that the JFS file system contained an out-of-bounds read vulnerability when printing xattr debug information. A local attacker could use this to cause a denial of service (system crash). Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - GPU drivers; - Greybus drivers; - Modular ISDN driver; - Multiple devices driver; - Network drivers; - SCSI drivers; - VFIO drivers; - F2FS file system; - GFS2 file system; - JFS file system; - NILFS2 file system; - Kernel debugger infrastructure; - Bluetooth subsystem; - IPv4 networking; - L2TP protocol; - Netfilter; - RxRPC session sockets; (CVE-2024-42154, CVE-2023-52527, CVE-2024-26733, CVE-2024-42160, CVE-2021-47188, CVE-2024-38570, CVE-2024-26851, CVE-2024-26984, CVE-2024-26677, CVE-2024-39480, CVE-2024-27398, CVE-2022-48791, CVE-2024-42224, CVE-2024-38583, CVE-2024-40902, CVE-2023-52809, CVE-2024-39495, CVE-2024-26651, CVE-2024-26880, CVE-2024-42228, CVE-2024-27437, CVE-2022-48863)
05 / REFERENCES
Further evidence
- https://ubuntu.com/security/CVE-2021-47188
- https://ubuntu.com/security/CVE-2022-48791
- https://ubuntu.com/security/CVE-2022-48863
- https://ubuntu.com/security/CVE-2023-52527
- https://ubuntu.com/security/CVE-2023-52809
- https://ubuntu.com/security/CVE-2024-26651
- https://ubuntu.com/security/CVE-2024-26677
- https://ubuntu.com/security/CVE-2024-26733
- https://ubuntu.com/security/CVE-2024-26851
- https://ubuntu.com/security/CVE-2024-26880
- https://ubuntu.com/security/CVE-2024-26984
- https://ubuntu.com/security/CVE-2024-27398
- https://ubuntu.com/security/CVE-2024-27437
- https://ubuntu.com/security/CVE-2024-38570
- https://ubuntu.com/security/CVE-2024-38583
- https://ubuntu.com/security/CVE-2024-39480
- https://ubuntu.com/security/CVE-2024-39495
- https://ubuntu.com/security/CVE-2024-40902
- https://ubuntu.com/security/CVE-2024-42154
- https://ubuntu.com/security/CVE-2024-42160
- https://ubuntu.com/security/CVE-2024-42224
- https://ubuntu.com/security/CVE-2024-42228
- https://ubuntu.com/security/notices/USN-7028-1