USN-6576-1: Linux kernel (OEM) vulnerability
Lonial Con discovered that the netfilter subsystem in the Linux kernel did not properly handle an expired catchall element in some situations, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.
Affected Software
Event History
Frequently Asked Questions
What is the severity of USN-6576-1?
The severity of USN-6576-1 is classified as potentially high due to the use-after-free vulnerability that may lead to a denial of service or execution of arbitrary code.
How do I fix USN-6576-1?
To fix USN-6576-1, upgrade to the indicated package versions, specifically linux-image-6.1.0-1028.29 or newer for affected Ubuntu 22.04 installations.
Who is affected by USN-6576-1?
Users running Ubuntu 22.04 with affected Linux kernel versions are at risk from the vulnerability outlined in USN-6576-1.
What type of vulnerability is USN-6576-1?
USN-6576-1 describes a use-after-free vulnerability within the netfilter subsystem of the Linux kernel.
Can USN-6576-1 lead to system compromise?
Yes, USN-6576-1 can lead to system compromise through a local attacker causing a denial of service or potentially executing code.