USN-4879-1: Linux kernel vulnerabilities
It was discovered that the Marvell WiFi-Ex device driver in the Linux kernel did not properly validate ad-hoc SSIDs. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-36158) Loris Reiff discovered that the BPF implementation in the Linux kernel did not properly validate attributes in the getsockopt BPF hook. A local attacker could possibly use this to cause a denial of service (system crash). (CVE-2021-20194)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-4879-1?
The severity of USN-4879-1 is classified as potentially critical, as it allows local attackers to cause denial of service or potentially execute arbitrary code.
How do I fix USN-4879-1?
To fix USN-4879-1, ensure you update to the recommended kernel versions, such as linux-image-5.8.0-1017.20 or later.
What systems are affected by USN-4879-1?
USN-4879-1 affects Ubuntu 20.10 systems using the specific versions of the Linux kernel mentioned in this advisory.
What vulnerabilities are addressed by USN-4879-1?
USN-4879-1 addresses vulnerabilities including CVE-2020-36158, which involves improper validation in the Marvell WiFi-Ex device driver.
Can USN-4879-1 lead to system crashes?
Yes, USN-4879-1 can lead to system crashes if exploited due to the denial of service vulnerabilities present in certain device drivers.