USN-5443-1: Linux kernel vulnerabilities
Kyle Zeng discovered that the Network Queuing and Scheduling subsystem of the Linux kernel did not properly perform reference counting in some situations, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code. (CVE-2022-29581) Jann Horn discovered that the Linux kernel did not properly enforce seccomp restrictions in some situations. A local attacker could use this to bypass intended seccomp sandbox restrictions. (CVE-2022-30594)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-5443-1?
The USN-5443-1 vulnerability is categorized as a medium severity issue due to its potential for denial of service and possible code execution.
How do I fix USN-5443-1?
To fix USN-5443-1, update your package to the latest version released by Ubuntu, which addresses the vulnerabilities identified.
What systems are affected by USN-5443-1?
USN-5443-1 affects Ubuntu version 22.04 with specific kernel package versions including linux-image-5.15.0-33 and other related packages.
Who discovered the vulnerability in USN-5443-1?
The vulnerability in USN-5443-1 was discovered by researcher Kyle Zeng.
What type of vulnerability is USN-5443-1?
USN-5443-1 is a use-after-free vulnerability related to the Network Queuing and Scheduling subsystem in the Linux kernel.