linux, linux-aws, linux-aws-hwe, linux-azure, linux-azure-4.15, linux-gcp, linux-gcp-4.15, linux-hwe, linux-kvm, linux-oracle vulnerabilities
Demi Marie Obenour and Simon Gaiser discovered that several Xen para- virtualization device frontends did not properly restrict the access rights of device backends. An attacker could possibly use a malicious Xen backend to gain access to memory pages of a guest VM or cause a denial of service in the guest. (CVE-2022-23041) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - HID subsystem; - Network drivers; - Mellanox network drivers; - SCSI subsystem; - SuperH / SH-Mobile drivers; - File systems infrastructure; - Ext4 file system; - JFS file system; - IP tunnels definitions; - Network namespace; - BPF subsystem; - Networking core; - HSR network protocol; - IPv4 networking; - IPv6 networking; - Network traffic control; (CVE-2024-56615, CVE-2024-56600, CVE-2025-21700, CVE-2024-56658, CVE-2024-35960, CVE-2024-50265, CVE-2025-21702, CVE-2024-53227, CVE-2024-53165, CVE-2024-50167, CVE-2024-26863, CVE-2024-35973, CVE-2024-46826, CVE-2021-47119, CVE-2024-50302, CVE-2024-49952, CVE-2021-47101, CVE-2024-49948, CVE-2024-56595)
02 / AFFECTED SOFTWARE
Affected packages
105 explicit affected versions
99 explicit affected versions
126 explicit affected versions
122 explicit affected versions
150 explicit affected versions
98 explicit affected versions
136 explicit affected versions
122 explicit affected versions
75 explicit affected versions
76 explicit affected versions
115 explicit affected versions
101 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Demi Marie Obenour and Simon Gaiser discovered that several Xen para- virtualization device frontends did not properly restrict the access rights of device backends. An attacker could possibly use a malicious Xen backend to gain access to memory pages of a guest VM or cause a denial of service in the guest. (CVE-2022-23041) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - HID subsystem; - Network drivers; - Mellanox network drivers; - SCSI subsystem; - SuperH / SH-Mobile drivers; - File systems infrastructure; - Ext4 file system; - JFS file system; - IP tunnels definitions; - Network namespace; - BPF subsystem; - Networking core; - HSR network protocol; - IPv4 networking; - IPv6 networking; - Network traffic control; (CVE-2024-56615, CVE-2024-56600, CVE-2025-21700, CVE-2024-56658, CVE-2024-35960, CVE-2024-50265, CVE-2025-21702, CVE-2024-53227, CVE-2024-53165, CVE-2024-50167, CVE-2024-26863, CVE-2024-35973, CVE-2024-46826, CVE-2021-47119, CVE-2024-50302, CVE-2024-49952, CVE-2021-47101, CVE-2024-49948, CVE-2024-56595)
05 / REFERENCES
Further evidence
- https://ubuntu.com/security/CVE-2021-47101
- https://ubuntu.com/security/CVE-2021-47119
- https://ubuntu.com/security/CVE-2022-23041
- https://ubuntu.com/security/CVE-2024-26863
- https://ubuntu.com/security/CVE-2024-35960
- https://ubuntu.com/security/CVE-2024-35973
- https://ubuntu.com/security/CVE-2024-46826
- https://ubuntu.com/security/CVE-2024-49948
- https://ubuntu.com/security/CVE-2024-49952
- https://ubuntu.com/security/CVE-2024-50167
- https://ubuntu.com/security/CVE-2024-50265
- https://ubuntu.com/security/CVE-2024-50302
- https://ubuntu.com/security/CVE-2024-53165
- https://ubuntu.com/security/CVE-2024-53227
- https://ubuntu.com/security/CVE-2024-56595
- https://ubuntu.com/security/CVE-2024-56600
- https://ubuntu.com/security/CVE-2024-56615
- https://ubuntu.com/security/CVE-2024-56658
- https://ubuntu.com/security/CVE-2025-21700
- https://ubuntu.com/security/CVE-2025-21702
- https://ubuntu.com/security/notices/USN-7428-1