Skip to main content

USN-7194-1: Linux kernel (Azure) vulnerabilities

Andy Nguyen discovered that the Bluetooth L2CAP implementation in the Linux kernel contained a type-confusion error. A physically proximate remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-12351) Andy Nguyen discovered that the Bluetooth A2MP implementation in the Linux kernel did not properly initialize memory in some situations. A physically proximate remote attacker could use this to expose sensitive information (kernel memory). (CVE-2020-12352) Andy Nguyen discovered that the Bluetooth HCI event packet parser in the Linux kernel did not properly handle event advertisements of certain sizes, leading to a heap-based buffer overflow. A physically proximate remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-24490) It was discovered that the CIFS network file system implementation in the Linux kernel did not properly validate certain SMB messages, leading to an out-of-bounds read vulnerability. An attacker could use this to cause a denial of service (system crash) or possibly expose sensitive information. (CVE-2023-6610) Supraja Sridhara, Benedict Schlüter, Mark Kuhne, Andrin Bertschi, and Shweta Shinde discovered that the Confidential Computing framework in the Linux kernel for x86 platforms did not properly handle 32-bit emulation on TDX and SEV. An attacker with access to the VMM could use this to cause a denial of service (guest crash) or possibly execute arbitrary code. (CVE-2024-25744) Several security issues were discovered in the Linux kernel. An attacker could possibly use these to compromise the system. This update corrects flaws in the following subsystems: - ARM32 architecture; - ARM64 architecture; - MIPS architecture; - PowerPC architecture; - RISC-V architecture; - S390 architecture; - User-Mode Linux (UML); - x86 architecture; - Block layer subsystem; - ACPI drivers; - Android drivers; - Serial ATA and Parallel ATA drivers; - ATM drivers; - Drivers core; - ATA over ethernet (AOE) driver; - Null block device driver; - TPM device driver; - Character device driver; - Clock framework and drivers; - Buffer Sharing and Synchronization framework; - ARM SCMI message protocol; - EFI core; - GPIO subsystem; - GPU drivers; - HID subsystem; - Hardware monitoring drivers; - I2C subsystem; - I3C subsystem; - InfiniBand drivers; - Input Device core drivers; - Input Device (Miscellaneous) drivers; - IOMMU subsystem; - IRQ chip drivers; - ISDN/mISDN subsystem; - LED subsystem; - Mailbox framework; - Multiple devices driver; - Media drivers; - VMware VMCI Driver; - MMC subsystem; - Ethernet bonding driver; - Network drivers; - Mellanox network drivers; - Microsoft Azure Network Adapter (MANA) driver; - STMicroelectronics network drivers; - Near Field Communication (NFC) drivers; - NTB driver; - Virtio pmem driver; - NVME drivers; - Device tree and open firmware driver; - Parport drivers; - PCI subsystem; - Pin controllers subsystem; - x86 platform drivers; - Remote Processor subsystem; - S/390 drivers; - SCSI subsystem; - QCOM SoC drivers; - SPI subsystem; - Direct Digital Synthesis drivers; - Thermal drivers; - Thunderbolt and USB4 drivers; - TTY drivers; - Userspace I/O drivers; - USB Device Class drivers; - DesignWare USB3 driver; - USB Gadget drivers; - USB Host Controller drivers; - USB Type-C Port Controller Manager driver; - USB Type-C Connector System Software Interface driver; - USB over IP driver; - VFIO drivers; - Virtio Host (VHOST) subsystem; - Framebuffer layer; - 9P distributed file system; - File systems infrastructure; - BTRFS file system; - Ceph distributed file system; - Ext4 file system; - F2FS file system; - GFS2 file system; - JFS file system; - Network file system (NFS) client; - Network file system (NFS) server daemon; - NILFS2 file system; - File system notification infrastructure; - NTFS3 file system; - Proc file system; - SMB network file system; - Bitmap API; - Network file system (NFS) superblock; - Objagg library; - Perf events; - Virtio network driver; - Bluetooth subsystem; - KCM (Kernel Connection Multiplexor) sockets driver; - Network traffic control; - Network sockets; - TCP network protocol; - BPF subsystem; - Control group (cgroup); - DMA mapping infrastructure; - Kernel thread helper (kthread); - Locking primitives; - Padata parallel execution mechanism; - RCU subsystem; - Arbitrary resource management; - Scheduler infrastructure; - Static call mechanism; - Tracing infrastructure; - Radix Tree data structure library; - Kernel userspace event delivery library; - Memory management; - Amateur Radio drivers; - Ethernet bridge; - CAN network layer; - Networking core; - Ethtool driver; - IPv4 networking; - IPv6 networking; - IUCV driver; - MAC80211 subsystem; - Multipath TCP; - Netfilter; - Netlink; - SCTP protocol; - Sun RPC protocol; - TIPC protocol; - TLS protocol; - VMware vSockets driver; - Wireless networking; - AppArmor security module; - Landlock security; - SELinux security module; - Simplified Mandatory Access Control Kernel framework; - FireWire sound drivers; - AudioScience HPI driver; - Amlogic Meson SoC drivers; - SoC audio core drivers; - USB sound devices; (CVE-2024-41091, CVE-2024-46800, CVE-2024-49924, CVE-2024-47659, CVE-2024-42295, CVE-2024-42284, CVE-2024-38577, CVE-2024-49902, CVE-2024-45011, CVE-2024-47673, CVE-2024-38538, CVE-2024-45008, CVE-2024-47667, CVE-2024-46832, CVE-2024-43879, CVE-2024-41059, CVE-2024-43853, CVE-2024-44940, CVE-2024-44947, CVE-2024-43828, CVE-2024-41090, CVE-2024-44944, CVE-2024-43834, CVE-2024-46777, CVE-2024-46689, CVE-2024-35965, CVE-2024-42276, CVE-2024-50264, CVE-2024-44965, CVE-2024-49977, CVE-2024-42079, CVE-2024-46744, CVE-2024-42299, CVE-2024-43909, CVE-2024-41098, CVE-2024-46731, CVE-2024-44946, CVE-2024-50024, CVE-2024-49858, CVE-2024-49892, CVE-2024-44989, CVE-2024-47663, CVE-2024-49983, CVE-2024-42286, CVE-2024-42310, CVE-2024-44974, CVE-2024-43892, CVE-2024-46840, CVE-2024-47695, CVE-2024-46780, CVE-2024-46757, CVE-2024-46707, CVE-2024-49894, CVE-2024-50007, CVE-2024-47705, CVE-2024-49890, CVE-2024-46815, CVE-2024-36968, CVE-2024-40915, CVE-2024-44995, CVE-2024-49871, CVE-2024-42265, CVE-2024-42283, CVE-2024-50000, CVE-2024-42309, CVE-2024-47748, CVE-2024-35967, CVE-2023-52904, CVE-2024-46745, CVE-2024-41016, CVE-2024-49868, CVE-2024-41011, CVE-2024-50186, CVE-2024-50033, CVE-2024-38545, CVE-2024-42267, CVE-2024-46852, CVE-2024-44987, CVE-2024-46783, CVE-2024-47671, CVE-2024-46721, CVE-2024-46853, CVE-2024-43914, CVE-2024-43907, CVE-2024-47734, CVE-2024-36484, CVE-2024-46781, CVE-2024-47693, CVE-2024-46791, CVE-2024-49913, CVE-2024-49900, CVE-2024-50191, CVE-2024-43860, CVE-2024-45018, CVE-2024-46854, CVE-2024-42246, CVE-2024-42156, CVE-2024-47660, CVE-2024-49878, CVE-2024-44982, CVE-2024-43867, CVE-2024-49938, CVE-2024-47737, CVE-2024-46743, CVE-2024-42292, CVE-2024-50181, CVE-2024-41020, CVE-2024-43863, CVE-2024-46817, CVE-2024-42281, CVE-2023-52621, CVE-2024-47749, CVE-2024-46804, CVE-2024-47747, CVE-2024-50045, CVE-2024-41065, CVE-2023-52434, CVE-2024-50095, CVE-2024-45025, CVE-2024-50179, CVE-2024-49946, CVE-2024-46782, CVE-2024-43839, CVE-2024-43904, CVE-2024-44958, CVE-2024-44934, CVE-2024-45006, CVE-2024-49969, CVE-2024-44986, CVE-2024-46752, CVE-2024-35966, CVE-2024-39463, CVE-2024-49883, CVE-2024-46805, CVE-2024-44935, CVE-2023-52532, CVE-2024-41071, CVE-2024-46807, CVE-2024-43846, CVE-2024-50015, CVE-2024-26661, CVE-2024-43841, CVE-2024-46819, CVE-2024-44931, CVE-2024-53057, CVE-2024-49982, CVE-2023-52757, CVE-2024-47735, CVE-2024-49866, CVE-2024-46763, CVE-2024-45021, CVE-2024-46814, CVE-2024-46673, CVE-2024-43873, CVE-2024-49997, CVE-2024-38602, CVE-2024-46795, CVE-2024-26822, CVE-2024-47670, CVE-2024-46755, CVE-2024-43902, CVE-2024-46859, CVE-2024-43883, CVE-2024-49966, CVE-2024-42305, CVE-2024-49959, CVE-2024-42280, CVE-2024-49965, CVE-2024-47674, CVE-2024-46723, CVE-2024-50031, CVE-2024-50184, CVE-2024-36893, CVE-2024-43875, CVE-2023-52918, CVE-2024-49867, CVE-2024-49981, CVE-2024-43861, CVE-2024-49895, CVE-2024-26669, CVE-2024-38544, CVE-2024-49973, CVE-2024-41015, CVE-2024-42296, CVE-2024-46722, CVE-2024-42158, CVE-2024-49881, CVE-2024-27072, CVE-2024-47739, CVE-2024-46828, CVE-2024-46724, CVE-2024-44999, CVE-2024-44971, CVE-2024-40973, CVE-2023-52572, CVE-2024-47709, CVE-2024-47742, CVE-2024-46818, CVE-2024-50035, CVE-2024-50188, CVE-2024-47679, CVE-2024-38667, CVE-2024-41078, CVE-2024-46844, CVE-2024-47672, CVE-2024-42306, CVE-2024-46758, CVE-2024-43869, CVE-2024-50062, CVE-2024-49875, CVE-2024-41017, CVE-2024-41077, CVE-2024-50038, CVE-2024-50013, CVE-2024-46746, CVE-2024-49962, CVE-2024-50049, CVE-2023-52751, CVE-2024-47684, CVE-2024-47701, CVE-2024-41070, CVE-2024-44942, CVE-2024-35904, CVE-2024-26607, CVE-2024-50019, CVE-2024-46714, CVE-2024-46738, CVE-2024-42312, CVE-2024-44948, CVE-2024-43890, CVE-2024-43893, CVE-2024-26800, CVE-2024-35963, CVE-2024-49884, CVE-2024-49930, CVE-2024-46829, CVE-2024-50046, CVE-2024-49985, CVE-2024-41022, CVE-2024-43894, CVE-2024-43830, CVE-2024-45009, CVE-2024-35951, CVE-2024-49889, CVE-2024-42301, CVE-2024-38632, CVE-2024-42114, CVE-2024-42290, CVE-2024-43858, CVE-2024-50002, CVE-2024-41060, CVE-2024-47696, CVE-2024-43870, CVE-2024-49948, CVE-2024-46759, CVE-2024-26947, CVE-2024-46713, CVE-2024-47740, CVE-2024-44960, CVE-2024-46756, CVE-2024-46737, CVE-2024-41068, CVE-2024-46677, CVE-2024-41063, CVE-2024-41019, CVE-2023-52917, CVE-2024-38611, CVE-2024-49852, CVE-2024-49863, CVE-2024-46739, CVE-2024-43908, CVE-2024-47697, CVE-2024-46810, CVE-2024-41072, CVE-2024-42302, CVE-2024-50003, CVE-2024-45026, CVE-2024-45028, CVE-2024-42259, CVE-2022-48666, CVE-2024-49995, CVE-2024-50093, CVE-2024-46865, CVE-2024-49886, CVE-2024-43889, CVE-2024-42285, CVE-2024-50006, CVE-2024-42271, CVE-2024-42274, CVE-2024-49957, CVE-2024-42289, CVE-2024-46719, CVE-2024-46858, CVE-2024-49958, CVE-2024-50041, CVE-2024-46675, CVE-2024-41064, CVE-2024-39472, CVE-2024-42287, CVE-2024-46822, CVE-2024-49877, CVE-2024-43849, CVE-2024-50040, CVE-2024-49879, CVE-2024-46798, CVE-2024-46855, CVE-2024-49944, CVE-2024-46676, CVE-2024-26893, CVE-2024-43835, CVE-2024-47665, CVE-2024-47669, CVE-2024-43882, CVE-2024-46740, CVE-2024-49851, CVE-2024-46849, CVE-2024-42311, CVE-2024-44985, CVE-2024-47757, CVE-2024-50001, CVE-2024-46750, CVE-2024-47706, CVE-2024-50039, CVE-2024-46702, CVE-2024-46725, CVE-2024-43817, CVE-2024-49907, CVE-2024-46695, CVE-2024-38553, CVE-2024-42272, CVE-2024-49882, CVE-2024-42269, CVE-2024-44954, CVE-2024-42318, CVE-2024-42297, CVE-2024-49975, CVE-2024-44988, CVE-2024-49963, CVE-2024-47692, CVE-2024-41042, CVE-2024-41081, CVE-2024-43854, CVE-2024-46771, CVE-2024-46732, CVE-2024-47712, CVE-2024-47699, CVE-2024-49927, CVE-2024-49860, CVE-2024-45003, CVE-2024-49954, CVE-2024-42304, CVE-2024-49933, CVE-2024-42277, CVE-2024-49955, CVE-2024-47710, CVE-2024-43905, CVE-2024-49903, CVE-2024-43856, CVE-2024-50180, CVE-2024-44966, CVE-2024-46685, CVE-2024-49935, CVE-2024-44990, CVE-2023-52889, CVE-2024-49896, CVE-2024-44969, CVE-2024-50189, CVE-2024-50008, CVE-2024-47720, CVE-2024-42313, CVE-2024-44983, CVE-2024-49949, CVE-2024-46761, CVE-2024-47690, CVE-2024-50059, CVE-2024-41073, CVE-2024-47723, CVE-2024-46747, CVE-2024-49952, CVE-2024-50096, CVE-2024-42288, CVE-2024-43871, CVE-2024-42126, CVE-2024-44998, CVE-2024-47685, CVE-2024-46679, CVE-2024-43884, CVE-2024-47668, CVE-2024-49936, CVE-2024-43829, CVE-2024-47756, CVE-2024-43880, CVE-2024-45007, CVE-2024-40910, CVE-2024-50044, CVE-2023-52639, CVE-2024-47698, CVE-2024-41012, CVE-2024-49856, CVE-2024-47713, CVE-2024-47718, CVE-2024-49967)

About

Kenya Education Network CERT(KENET-CERT) is a Cybersecurity Emergency Response Team and Co-ordination Center operated by the National Research and Education Network of Kenya. KENET-CERT coordination center promotes awareness on cybersecurity incidences as well as coordinates and assists member institutions in responding effectively to cyber security threats and incidences. KENET-CERT works closely with Kenya's National CIRT coordination center (CIRT/CC) as a sector CIRT for the academic institutions. KENET promotes use of ICT in Teaching, Learning and Research in Higher Education Institutions in Kenya. KENET aims to interconnect all the Universities, Tertiary and Research Institutions in Kenya by setting up a cost effective and sustainable private network with high speed access to the global Internet. KENET also facilitates electronic communication among students and faculties in member institutions, share learning and teaching resources by collaboration in Research and Development of Educational content.