Lucene search

K
ubuntuUbuntuUSN-6973-3
HistoryAug 26, 2024 - 12:00 a.m.

Linux kernel (AWS) vulnerabilities

2024-08-2600:00:00
ubuntu.com
8
ubuntu 18.04 esm
linux kernel
aws
bluetooth subsystem
null pointer dereference
denial of service
superh risc architecture
mmc subsystem
network drivers
scsi drivers
gfs2 file system
ipv4 networking
ipv6 networking
hd-audio driver

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.2

Confidence

Low

Releases

  • Ubuntu 18.04 ESM

Packages

  • linux-aws-5.4 - Linux kernel for Amazon Web Services (AWS) systems

Details

It was discovered that a race condition existed in the Bluetooth subsystem
in the Linux kernel, leading to a null pointer dereference vulnerability. A
privileged local attacker could use this to possibly cause a denial of
service (system crash). (CVE-2024-24860)

Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:

  • SuperH RISC architecture;
  • MMC subsystem;
  • Network drivers;
  • SCSI drivers;
  • GFS2 file system;
  • IPv4 networking;
  • IPv6 networking;
  • HD-audio driver;
    (CVE-2024-26830, CVE-2024-39484, CVE-2024-36901, CVE-2024-26929,
    CVE-2024-26921, CVE-2021-46926, CVE-2023-52629, CVE-2023-52760)

CVSS3

8.4

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

7.2

Confidence

Low