Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

Debian LTS DLA-2586-1 Critical: Linux Kernel DoS and Escalation Issues

debian lts
Calendar Grey March 9, 2021
Dist Debian Esm H88
Debian LTS advisory DLA-2587-1 highlights several critical vulnerabilities in the software core, requiring immediate attention for security patches.
Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks

Summary

"Team bobfuzzer" reported bugs in Btrfs that could lead to a
use-after-free or heap buffer overflow, and could be triggered by
crafted filesystem images. A user permitted to mount and access
arbitrary filesystems could use these to cause a denial of service
(crash or memory corruption) or possibly for privilege escalation.

CVE-2020-27815

A flaw was reported in the JFS filesystem code allowing a local
attacker with the ability to set extended attributes to cause a
denial of service.

CVE-2020-27825

Adam 'pi3' Zabrocki reported a use-after-free flaw in the ftrace
ring buffer resizing logic due to a race condition, which could
result in denial of service or information leak.

CVE-2020-28374

David Disseldorp discovered that the LIO SCSI target implementation
performed insufficient checking in certain XCOPY requests. An
attacker with access to a LUN and knowledge of Unit Serial Number

Read the Full Advisory


Severity
critical
Lowest
Low
Medium
High
Critical

-------------------------------------------------------------------------Package: linux
Version: 4.9.258-1
CVE ID: CVE-2019-19318 CVE-2019-19813 CVE-2019-19816 CVE-2020-27815

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here