linux, linux-aws, linux-azure, linux-azure-5.15, linux-azure-fde, linux-azure-fde-5.15, linux-gcp, linux-gke, linux-gkeop, linux-hwe-5.15, linux-ibm, linux-intel-iotg, linux-kvm, linux-lowlatency, linux-lowlatency-hwe-5.15, linux-nvidia, linux-nvidia-tegra, linux-nvidia-tegra-igx, linux-oracle, linux-raspi vulnerabilities
Jann Horn discovered that the watch_queue event notification subsystem in the Linux kernel contained an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service (system crash) or escalate their privileges. (CVE-2022-0995) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - File systems infrastructure; - NTFS3 file system; - Ethernet bridge; - Ethtool driver; - IPv6 networking; - Network traffic control; - VMware vSockets driver; (CVE-2025-21703, CVE-2024-56651, CVE-2024-50248, CVE-2025-21701, CVE-2024-26837, CVE-2024-46826, CVE-2025-21993, CVE-2025-21702, CVE-2024-50256, CVE-2025-21756, CVE-2025-21700)
02 / AFFECTED SOFTWARE
Affected packages
55 explicit affected versions
46 explicit affected versions
54 explicit affected versions
57 explicit affected versions
71 explicit affected versions
63 explicit affected versions
64 explicit affected versions
45 explicit affected versions
64 explicit affected versions
63 explicit affected versions
56 explicit affected versions
61 explicit affected versions
51 explicit affected versions
65 explicit affected versions
68 explicit affected versions
48 explicit affected versions
21 explicit affected versions
17 explicit affected versions
64 explicit affected versions
62 explicit affected versions
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
Jann Horn discovered that the watch_queue event notification subsystem in the Linux kernel contained an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service (system crash) or escalate their privileges. (CVE-2022-0995) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - Network drivers; - File systems infrastructure; - NTFS3 file system; - Ethernet bridge; - Ethtool driver; - IPv6 networking; - Network traffic control; - VMware vSockets driver; (CVE-2025-21703, CVE-2024-56651, CVE-2024-50248, CVE-2025-21701, CVE-2024-26837, CVE-2024-46826, CVE-2025-21993, CVE-2025-21702, CVE-2024-50256, CVE-2025-21756, CVE-2025-21700)
05 / REFERENCES
Further evidence
- https://ubuntu.com/security/CVE-2022-0995
- https://ubuntu.com/security/CVE-2024-26837
- https://ubuntu.com/security/CVE-2024-46826
- https://ubuntu.com/security/CVE-2024-50248
- https://ubuntu.com/security/CVE-2024-50256
- https://ubuntu.com/security/CVE-2024-56651
- https://ubuntu.com/security/CVE-2025-21700
- https://ubuntu.com/security/CVE-2025-21701
- https://ubuntu.com/security/CVE-2025-21702
- https://ubuntu.com/security/CVE-2025-21703
- https://ubuntu.com/security/CVE-2025-21756
- https://ubuntu.com/security/CVE-2025-21993
- https://ubuntu.com/security/notices/USN-7455-1