First published: Thu Nov 30 2023(Updated: )
Yu Hao discovered that the UBI driver in the Linux kernel did not properly check for MTD with zero erasesize during device attachment. A local privileged attacker could use this to cause a denial of service (system crash). (CVE-2023-31085) Manfred Rudigier discovered that the Intel(R) PCI-Express Gigabit (igb) Ethernet driver in the Linux kernel did not properly validate received frames that are larger than the set MTU size, leading to a buffer overflow vulnerability. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-45871)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/linux-image-5.4.0-1081-gkeop | <5.4.0-1081.85 | 5.4.0-1081.85 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-5.4.0-1118-gcp | <5.4.0-1118.127 | 5.4.0-1118.127 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-5.4.0-1120-azure | <5.4.0-1120.127 | 5.4.0-1120.127 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-azure-lts-20.04 | <5.4.0.1120.113 | 5.4.0.1120.113 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-gcp-lts-20.04 | <5.4.0.1118.120 | 5.4.0.1118.120 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-gkeop | <5.4.0.1081.79 | 5.4.0.1081.79 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-gkeop-5.4 | <5.4.0.1081.79 | 5.4.0.1081.79 |
Ubuntu Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-5.4.0-1118-gcp | <5.4.0-1118.127~18.04.1 | 5.4.0-1118.127~18.04.1 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/linux-image-5.4.0-1120-azure | <5.4.0-1120.127~18.04.1 | 5.4.0-1120.127~18.04.1 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/linux-image-azure | <5.4.0.1120.93 | 5.4.0.1120.93 |
Ubuntu Ubuntu | =18.04 | |
All of | ||
ubuntu/linux-image-gcp | <5.4.0.1118.94 | 5.4.0.1118.94 |
Ubuntu Ubuntu | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of USN-6495-2 is not mentioned in the provided information.
A local privileged attacker can exploit CVE-2023-31085 by causing a denial of service (system crash) through improper checks in the UBI driver.
The Linux kernel versions affected by USN-6495-2 are: 5.4.0-1081-gkeop, 5.4.0-1118-gcp, 5.4.0-1120-azure, 5.4.0.1120.113, 5.4.0.1118.120, 5.4.0.1081.79, 5.4.0-1118-gcp, 5.4.0-1120-azure, 5.4.0.1120.93, and 5.4.0.1118.94.
To fix the Linux kernel vulnerabilities, update to the respective kernel versions provided: 5.4.0-1081.85, 5.4.0-1118.127, 5.4.0-1120.127, 5.4.0.1120.113, 5.4.0.1118.120, 5.4.0.1081.79, 5.4.0-1118.127~18.04.1, 5.4.0-1120.127~18.04.1, 5.4.0.1120.93, and 5.4.0.1118.94.
More information about USN-6495-2 can be found at the following references: [link1], [link2], [link3]