CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
31.6%
It was discovered that the Traffic-Control Index (TCINDEX) implementation
in the Linux kernel contained a use-after-free vulnerability. A local
attacker could use this to cause a denial of service (system crash) or
possibly execute arbitrary code. (CVE-2023-1281)
Lin Ma discovered a race condition in the io_uring subsystem in the Linux
kernel, leading to a null pointer dereference vulnerability. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2023-0468)
It was discovered that a use-after-free vulnerability existed in the SGI
GRU driver in the Linux kernel. A local attacker could possibly use this to
cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2022-3424)
Hyunwoo Kim discovered that the DVB Core driver in the Linux kernel did not
properly perform reference counting in some situations, leading to a use-
after-free vulnerability. A local attacker could use this to cause a denial
of service (system crash) or possibly execute arbitrary code.
(CVE-2022-41218)
It was discovered that the network queuing discipline implementation in the
Linux kernel contained a null pointer dereference in some situations. A
local attacker could use this to cause a denial of service (system crash).
(CVE-2022-47929)
Thadeu Cascardo discovered that the io_uring subsystem contained a double-
free vulnerability in certain memory allocation error conditions. A local
attacker could possibly use this to cause a denial of service (system
crash). (CVE-2023-1032)
It was discovered that the module decompression implementation in the Linux
kernel did not properly handle return values in certain error conditions. A
local attacker could use this to cause a denial of service (system crash).
(CVE-2023-22997)
Lianhui Tang discovered that the MPLS implementation in the Linux kernel
did not properly handle certain sysctl allocation failure conditions,
leading to a double-free vulnerability. An attacker could use this to cause
a denial of service or possibly execute arbitrary code. (CVE-2023-26545)
It was discovered that the NTFS file system implementation in the Linux
kernel did not properly handle a loop termination condition, leading to an
out-of-bounds read vulnerability. A local attacker could use this to cause
a denial of service (system crash) or possibly expose sensitive
information. (CVE-2023-26606)
Wei Chen discovered that the DVB USB AZ6027 driver in the Linux kernel
contained a null pointer dereference when handling certain messages from
user space. A local attacker could use this to cause a denial of service
(system crash). (CVE-2023-28328)
OS | Version | Architecture | Package | Version | Filename |
---|---|---|---|---|---|
Ubuntu | 22.10 | noarch | linux-image-5.19.0-40-generic-64k | < 5.19.0-40.41 | UNKNOWN |
Ubuntu | 22.10 | noarch | linux-image-5.19.0-40-generic | < 5.19.0-40.41 | UNKNOWN |
Ubuntu | 22.10 | noarch | linux-image-5.19.0-40-generic-dbgsym | < 5.19.0-40.41 | UNKNOWN |
Ubuntu | 22.10 | noarch | linux-image-virtual | < 5.19.0.40.36 | UNKNOWN |
Ubuntu | 22.10 | noarch | linux-cloud-tools-generic | < 5.19.0.40.36 | UNKNOWN |
Ubuntu | 22.10 | noarch | linux-cloud-tools-generic-hwe-22.04 | < 5.19.0.40.36 | UNKNOWN |
Ubuntu | 22.10 | noarch | linux-cloud-tools-generic-hwe-22.04-edge | < 5.19.0.40.36 | UNKNOWN |
Ubuntu | 22.10 | noarch | linux-cloud-tools-virtual | < 5.19.0.40.36 | UNKNOWN |
Ubuntu | 22.10 | noarch | linux-cloud-tools-virtual-hwe-22.04 | < 5.19.0.40.36 | UNKNOWN |
Ubuntu | 22.10 | noarch | linux-cloud-tools-virtual-hwe-22.04-edge | < 5.19.0.40.36 | UNKNOWN |
ubuntu.com/security/CVE-2022-3424
ubuntu.com/security/CVE-2022-41218
ubuntu.com/security/CVE-2022-47929
ubuntu.com/security/CVE-2023-0468
ubuntu.com/security/CVE-2023-1032
ubuntu.com/security/CVE-2023-1281
ubuntu.com/security/CVE-2023-22997
ubuntu.com/security/CVE-2023-26545
ubuntu.com/security/CVE-2023-26606
ubuntu.com/security/CVE-2023-28328