USN-5358-1: Linux kernel vulnerabilities
It was discovered that the network traffic control implementation in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-1055) It was discovered that the IPsec implementation in the Linux kernel did not properly allocate enough memory when performing ESP transformations, leading to a heap-based buffer overflow. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-27666)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-5358-1?
The severity of USN-5358-1 is classified as high due to its potential for causing system crashes or arbitrary code execution.
How do I fix USN-5358-1?
To fix USN-5358-1, update the affected Linux kernel packages to the latest patched versions provided by Ubuntu.
Who is affected by USN-5358-1?
Users running Ubuntu 21.10 with specific kernel versions are affected by USN-5358-1.
What type of vulnerability is USN-5358-1?
USN-5358-1 is a use-after-free vulnerability located in the network traffic control implementation of the Linux kernel.
Can USN-5358-1 be exploited remotely?
No, USN-5358-1 is a local vulnerability, which means it can only be exploited by a local attacker.