USN-5094-2: Linux kernel (Raspberry Pi) vulnerabilities
Publication date
30 September 2021
Overview
Several security issues were fixed in the Linux kernel.
Releases
Packages
- linux-raspi2 - Linux kernel for Raspberry Pi systems
Details
It was discovered that the KVM hypervisor implementation in the Linux
kernel did not properly perform reference counting in some situations,
leading to a use-after-free vulnerability. An attacker who could start and
control a VM could possibly use this to expose sensitive information or
execute arbitrary code. (CVE-2021-22543)
It was discovered that the tracing subsystem in the Linux kernel did not
properly keep track of per-cpu ring buffer state. A privileged attacker
could use this to cause a denial of service. (CVE-2021-3679)
Alois Wohlschlager discovered that the overlay file system in the Linux
kernel did not restrict private clones in some situations. An attacker
could use this to expose sensitive information. (CVE-2021-3732)
It was discovered that the MAX-3421 host USB device driver in the Linux
kernel...
It was discovered that the KVM hypervisor implementation in the Linux
kernel did not properly perform reference counting in some situations,
leading to a use-after-free vulnerability. An attacker who could start and
control a VM could possibly use this to expose sensitive information or
execute arbitrary code. (CVE-2021-22543)
It was discovered that the tracing subsystem in the Linux kernel did not
properly keep track of per-cpu ring buffer state. A privileged attacker
could use this to cause a denial of service. (CVE-2021-3679)
Alois Wohlschlager discovered that the overlay file system in the Linux
kernel did not restrict private clones in some situations. An attacker
could use this to expose sensitive information. (CVE-2021-3732)
It was discovered that the MAX-3421 host USB device driver in the Linux
kernel did not properly handle device removal events. A physically
proximate attacker could use this to cause a denial of service (system
crash). (CVE-2021-38204)
It was discovered that the Xilinx 10/100 Ethernet Lite device driver in the
Linux kernel could report pointer addresses in some situations. An attacker
could use this information to ease the exploitation of another
vulnerability. (CVE-2021-38205)
Update instructions
After a standard system update you need to reboot your computer to make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Ubuntu Release | Package Version | ||
---|---|---|---|
18.04 bionic | linux-image-4.15.0-1096-raspi2 – 4.15.0-1096.102 | ||
linux-image-raspi2 – 4.15.0.1096.94 |
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.
References
Related notices
- USN-6014-1
- USN-6013-1
- USN-6001-1
- USN-5343-1
- USN-5299-1
- USN-5120-1
- USN-5116-1
- USN-5116-2
- USN-5115-1
- USN-5113-1
- USN-6014-1
- USN-6013-1
- USN-6001-1
- USN-5343-1
- USN-5299-1
- USN-5120-1
- USN-5116-1
- USN-5116-2
- USN-5115-1
- USN-5113-1
- USN-5106-1
- USN-5096-1
- USN-5094-1
- USN-5092-1
- USN-5092-2
- USN-5091-1
- USN-5091-2
- USN-5071-1
- USN-5071-2
- USN-5071-3
- USN-5070-1
Have additional questions?