USN-5358-2: Linux kernel vulnerabilities
It was discovered that the network traffic control implementation in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-1055) It was discovered that the IPsec implementation in the Linux kernel did not properly allocate enough memory when performing ESP transformations, leading to a heap-based buffer overflow. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-27666)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-5358-2?
The USN-5358-2 vulnerability is classified as critical due to its potential to cause a denial of service or execute arbitrary code.
How do I fix USN-5358-2?
To fix USN-5358-2, update your system to the recommended Linux kernel version specified in the advisory.
What systems are affected by USN-5358-2?
USN-5358-2 affects various versions of the Ubuntu Linux kernel, specifically those prior to the patched versions.
Can USN-5358-2 be exploited remotely?
No, USN-5358-2 requires local access, meaning an attacker needs to be able to run code on the affected machine.
What is the CVE associated with USN-5358-2?
The USN-5358-2 vulnerability is associated with CVE-2022-1055, which describes the use-after-free flaw.