USN-6973-3: Linux kernel (AWS) vulnerabilities
It was discovered that a race condition existed in the Bluetooth subsystem in the Linux kernel, leading to a null pointer dereference vulnerability. A privileged local attacker could use this to possibly cause a denial of service (system crash). (CVE-2024-24860) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems:
Affected Software
Event History
Child vulnerabilities
Contains the following vulnerabilities.
Frequently Asked Questions
What is the severity of USN-6973-3?
USN-6973-3 is considered a high severity vulnerability due to its potential to cause a denial of service.
How do I fix USN-6973-3?
To fix USN-6973-3, update the Linux kernel package to version 5.4.0-1131.141~18.04.1 or higher.
Who is affected by USN-6973-3?
Users running Ubuntu 18.04 with the Bluetooth subsystem in the Linux kernel are affected by USN-6973-3.
What type of vulnerability is USN-6973-3?
USN-6973-3 is a null pointer dereference vulnerability caused by a race condition in the Bluetooth subsystem.
Can USN-6973-3 be exploited remotely?
No, USN-6973-3 requires local privileges, so only a local attacker can exploit it.