First published: Fri Mar 28 2025(Updated: )
Chenyuan Yang discovered that the CEC driver driver in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2024-23848) Attila Szász discovered that the HFS+ file system implementation in the Linux Kernel contained a heap overflow vulnerability. An attacker could use a specially crafted file system image that, when mounted, could cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2025-0927) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems:
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
ubuntu/linux-image-5.4.0-1060-xilinx-zynqmp | <5.4.0-1060.64 | 5.4.0-1060.64 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-5.4.0-1088-ibm | <5.4.0-1088.93 | 5.4.0-1088.93 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-5.4.0-1101-bluefield | <5.4.0-1101.108 | 5.4.0-1101.108 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-5.4.0-1129-kvm | <5.4.0-1129.138 | 5.4.0-1129.138 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-5.4.0-1140-oracle | <5.4.0-1140.150 | 5.4.0-1140.150 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-5.4.0-1145-gcp | <5.4.0-1145.154 | 5.4.0-1145.154 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-5.4.0-1147-azure | <5.4.0-1147.154 | 5.4.0-1147.154 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-azure-lts-20.04 | <5.4.0.1147.141 | 5.4.0.1147.141 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-bluefield | <5.4.0.1101.97 | 5.4.0.1101.97 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-gcp-lts-20.04 | <5.4.0.1145.147 | 5.4.0.1145.147 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-ibm-lts-20.04 | <5.4.0.1088.117 | 5.4.0.1088.117 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-kvm | <5.4.0.1129.125 | 5.4.0.1129.125 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-oracle-lts-20.04 | <5.4.0.1140.134 | 5.4.0.1140.134 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-xilinx-zynqmp | <5.4.0.1060.60 | 5.4.0.1060.60 |
Ubuntu | =20.04 | |
All of | ||
ubuntu/linux-image-5.4.0-1140-oracle | <5.4.0-1140.149~18.04.1 | 5.4.0-1140.149~18.04.1 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/linux-image-5.4.0-1145-gcp | <5.4.0-1145.154~18.04.1 | 5.4.0-1145.154~18.04.1 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/linux-image-5.4.0-1147-azure | <5.4.0-1147.154~18.04.1 | 5.4.0-1147.154~18.04.1 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/linux-image-azure | <5.4.0.1147.154~18.04.1 | 5.4.0.1147.154~18.04.1 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/linux-image-gcp | <5.4.0.1145.154~18.04.1 | 5.4.0.1145.154~18.04.1 |
Ubuntu | =18.04 | |
All of | ||
ubuntu/linux-image-oracle | <5.4.0.1140.149~18.04.1 | 5.4.0.1140.149~18.04.1 |
Ubuntu | =18.04 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
(Contains the following vulnerabilities)
The severity of USN-7392-1 is significant as it involves a use-after-free vulnerability that could lead to denial of service or arbitrary code execution.
To fix USN-7392-1, update your Ubuntu system to the specified Linux kernel versions that address the vulnerability.
USN-7392-1 affects Ubuntu 20.04 systems running specific Linux kernel versions listed in the announcement.
A local attacker could exploit the vulnerability in USN-7392-1 to cause a denial of service or potentially execute arbitrary code.
After updating for USN-7392-1, it is recommended to monitor your system for any unusual activity to ensure the vulnerability has been fully mitigated.