First published: Thu Nov 30 2023(Updated: )
Ivan D Barrera, Christopher Bednarz, Mustafa Ismail, and Shiraz Saleem discovered that the InfiniBand RDMA driver in the Linux kernel did not properly check for zero-length STAG or MR registration. A remote attacker could possibly use this to execute arbitrary code. (CVE-2023-25775) Yu Hao discovered that the UBI driver in the Linux kernel did not properly check for MTD with zero erasesize during device attachment. A local privileged attacker could use this to cause a denial of service (system crash). (CVE-2023-31085) Manfred Rudigier discovered that the Intel(R) PCI-Express Gigabit (igb) Ethernet driver in the Linux kernel did not properly validate received frames that are larger than the set MTU size, leading to a buffer overflow vulnerability. An attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-45871)
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/linux-image-5.15.0-1033-gkeop | <5.15.0-1033.39 | 5.15.0-1033.39 |
=22.04 | ||
All of | ||
ubuntu/linux-image-5.15.0-1047-gcp | <5.15.0-1047.55 | 5.15.0-1047.55 |
=22.04 | ||
All of | ||
ubuntu/linux-image-5.15.0-1047-gke | <5.15.0-1047.52 | 5.15.0-1047.52 |
=22.04 | ||
All of | ||
ubuntu/linux-image-5.15.0-1052-azure | <5.15.0-1052.60 | 5.15.0-1052.60 |
=22.04 | ||
All of | ||
ubuntu/linux-image-5.15.0-1052-azure-fde | <5.15.0-1052.60.1 | 5.15.0-1052.60.1 |
=22.04 | ||
All of | ||
ubuntu/linux-image-azure-fde-lts-22.04 | <5.15.0.1052.60.30 | 5.15.0.1052.60.30 |
=22.04 | ||
All of | ||
ubuntu/linux-image-azure-lts-22.04 | <5.15.0.1052.48 | 5.15.0.1052.48 |
=22.04 | ||
All of | ||
ubuntu/linux-image-gcp-lts-22.04 | <5.15.0.1047.43 | 5.15.0.1047.43 |
=22.04 | ||
All of | ||
ubuntu/linux-image-gke | <5.15.0.1047.46 | 5.15.0.1047.46 |
=22.04 | ||
All of | ||
ubuntu/linux-image-gke-5.15 | <5.15.0.1047.46 | 5.15.0.1047.46 |
=22.04 | ||
All of | ||
ubuntu/linux-image-gkeop | <5.15.0.1033.32 | 5.15.0.1033.32 |
=22.04 | ||
All of | ||
ubuntu/linux-image-gkeop-5.15 | <5.15.0.1033.32 | 5.15.0.1033.32 |
=22.04 | ||
All of | ||
ubuntu/linux-image-5.15.0-1033-gkeop | <5.15.0-1033.39~20.04.1 | 5.15.0-1033.39~20.04.1 |
=20.04 | ||
All of | ||
ubuntu/linux-image-5.15.0-1047-gcp | <5.15.0-1047.55~20.04.1 | 5.15.0-1047.55~20.04.1 |
=20.04 | ||
All of | ||
ubuntu/linux-image-5.15.0-1052-azure | <5.15.0-1052.60~20.04.1 | 5.15.0-1052.60~20.04.1 |
=20.04 | ||
All of | ||
ubuntu/linux-image-5.15.0-1052-azure-fde | <5.15.0-1052.60~20.04.1.1 | 5.15.0-1052.60~20.04.1.1 |
=20.04 | ||
All of | ||
ubuntu/linux-image-azure | <5.15.0.1052.60~20.04.41 | 5.15.0.1052.60~20.04.41 |
=20.04 | ||
All of | ||
ubuntu/linux-image-azure-cvm | <5.15.0.1052.60~20.04.41 | 5.15.0.1052.60~20.04.41 |
=20.04 | ||
All of | ||
ubuntu/linux-image-azure-fde | <5.15.0.1052.60~20.04.1.30 | 5.15.0.1052.60~20.04.1.30 |
=20.04 | ||
All of | ||
ubuntu/linux-image-gcp | <5.15.0.1047.55~20.04.1 | 5.15.0.1047.55~20.04.1 |
=20.04 | ||
All of | ||
ubuntu/linux-image-gkeop-5.15 | <5.15.0.1033.39~20.04.29 | 5.15.0.1033.39~20.04.29 |
=20.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-6496-2 is high.
The vulnerability ID associated with USN-6496-2 is CVE-2023-25775.
A remote attacker can exploit CVE-2023-25775 by using the InfiniBand RDMA driver vulnerability to execute arbitrary code.
Ubuntu versions 22.04 and 20.04 are affected by USN-6496-2, with specific packages like linux-image-5.15.0-1033-gkeop, linux-image-5.15.0-1047-gcp, etc.
You can find more information about USN-6496-2 on the Ubuntu Security website.