USN-5071-3: Linux kernel (Raspberry Pi) vulnerabilities
It was discovered that the KVM hypervisor implementation in the Linux kernel did not properly perform reference counting in some situations, leading to a use-after-free vulnerability. An attacker who could start and control a VM could possibly use this to expose sensitive information or execute arbitrary code. (CVE-2021-22543) Murray McAllister discovered that the joystick device interface in the Linux kernel did not properly validate data passed via an ioctl(). A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code on systems with a joystick device registered. (CVE-2021-3612)
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Linux kernel vulnerability?
The vulnerability ID for this Linux kernel vulnerability is USN-5071-3.
What is the severity of the USN-5071-3 vulnerability?
The severity of the USN-5071-3 vulnerability is not mentioned in the provided information.
What is the affected software for the USN-5071-3 vulnerability?
The affected software for the USN-5071-3 vulnerability is Linux kernel (Raspberry Pi).
How can an attacker exploit the USN-5071-3 vulnerability?
An attacker who could start and control a VM could possibly exploit the USN-5071-3 vulnerability to expose sensitive information or execute arbitrary code.
How can I fix the USN-5071-3 vulnerability?
To fix the USN-5071-3 vulnerability, update the Linux kernel to version 5.4.0-1043.47 or later.