USN-6192-1: Linux kernel vulnerabilities
Hangyu Hua discovered that the Flower classifier implementation in the Linux kernel contained an out-of-bounds write vulnerability. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-35788, LP: #2023577) Xingyuan Mo and Gengjia Chen discovered that the iouring subsystem in the Linux kernel did not properly handle locking when IOPOLL mode is being used. A local attacker could use this to cause a denial of service (system crash). (CVE-2023-2430) It was discovered that for some Intel processors the INVLPG instruction implementation did not properly flush global TLB entries when PCIDs are enabled. An attacker could use this to expose sensitive information (kernel memory) or possibly cause undesired behaviors. (LP: #2023220)
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6192-1?
USN-6192-1 is classified as a high severity vulnerability due to potential denial of service and arbitrary code execution risks.
How do I fix USN-6192-1?
To remediate USN-6192-1, update your system to the latest kernel version according to the provided software remedies.
What systems are affected by USN-6192-1?
USN-6192-1 affects Ubuntu 22.10 systems running various versions of the Linux kernel.
What is CVE-2023-35788 related to USN-6192-1?
CVE-2023-35788 is the identifier for the out-of-bounds write vulnerability addressed in USN-6192-1.
What might an attacker do if USN-6192-1 is not addressed?
If left unpatched, an attacker could exploit USN-6192-1 to crash the system or execute malicious code.