Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Debian DSA-5594-1 Urgent: Array of Kernel Vulnerabilities and DOS Risks

debian
Calendar Grey January 2, 2024
Debian Logo
Critical kernel vulnerabilities in Debian lead to denial of service, privilege escalation, and information leaks.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks

Summary

CVE-2021-44879

Wenqing Liu reported a NULL pointer dereference in the f2fs
implementation. An attacker able to mount a specially crafted image
can take advantage of this flaw for denial of service.

CVE-2023-5178

Alon Zahavi reported a use-after-free flaw in the NVMe-oF/TCP
subsystem in the queue initialization setup, which may result in
denial of service or privilege escalation.

CVE-2023-5197

Kevin Rich discovered a use-after-free flaw in the netfilter
subsystem which may result in denial of service or privilege
escalation for a user with the CAP_NET_ADMIN capability in any user
or network namespace.

CVE-2023-5717

Budimir Markovic reported a heap out-of-bounds write vulnerability
in the Linux kernel's Performance Events system caused by improper
handling of event groups, which may result in denial of service or
privilege escalation. The default settings in Debian prevent
exploitation unless more permissive settings have been applied in
th...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Package: linux
CVE ID: CVE-2021-44879 CVE-2023-5178 CVE-2023-5197 CVE-2023-5717

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here