Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 506
Alerts This Week
Warning Icon 1 506

Ubuntu 24.04 LTS USN-6817-3 Critical: Linux Kernel Denial Of Service Issues

ubuntu
Calendar Grey June 14, 2024
Scroller Ubuntu
Ubuntu Security Notice USN-6818-4 highlights essential kernel patches for linux-oem and linux-generic aimed at mitigating various vulnerabilities.
Several security issues were fixed in the Linux kernel.

Summary

Several security issues were fixed in the Linux kernel.

Software Description:

- linux-azure: Linux kernel for Microsoft Azure Cloud systems

- linux-gke: Linux kernel for Google Container Engine (GKE) systems

Details:

Ziming Zhang discovered that the DRM driver for VMware Virtual GPU did not

properly handle certain error conditions, leading to a NULL pointer

dereference. A local attacker could possibly trigger this vulnerability to

cause a denial of service. (CVE-2022-38096)

Zheng Wang discovered that the Broadcom FullMAC WLAN driver in the Linux

kernel contained a race condition during device removal, leading to a use-

after-free vulnerability. A physically proximate attacker could possibly

use this to cause a denial of service (system crash). (CVE-2023-47233)

It was discovered that the ATA over Ethernet (AoE) driver in the Linux

kernel contained a race condition, leading to a use-after-free

vulnerability. An attacker could use this to cause a denial of se...

Read the Full Advisory

Update Instructions

The problem can be corrected by updating your system to the following
package versions:

Ubuntu 24.04 LTS
   linux-image-6.8.0-1004-gke      6.8.0-1004.7
   linux-image-6.8.0-1008-azure    6.8.0-1008.8
   linux-image-6.8.0-1008-azure-fde  6.8.0-1008.8
   linux-image-azure               6.8.0-1008.8
   linux-image-azure-fde           6.8.0-1008.8
   linux-image-gke                 6.8.0-1004.7

After a standard system update you need to reboot your computer to make
all the necessary changes.

ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.

References

https://ubuntu.com/security/notices/USN-6817-3

https://ubuntu.com/security/notices/USN-6817-1

CVE-2022-38096, CVE-2022-48669, CVE-2023-47233, CVE-2023-52644,

CVE-2023-52647, CVE-2023-52648, CVE-2023-52649, CVE-2023-52650,

CVE-2023-52652, CVE-2023-52653, CVE-2023-52659, CVE-2023-52661,

CVE-2023-52662, CVE-2023-52663, CVE-2023-6270, CVE-2023-7042,

CVE-2024-23307, CVE-2024-24861, CVE-2024-25739, CVE-2024-26651,

CVE-2024-26653, CVE-2024-26654, CVE-2024-26655, CVE-2024-26656,

CVE-2024-26657, CVE-2024-26809, CVE-2024-26810, CVE-2024-26812,

CVE-2024-26813, CVE-2024-26814, CVE-2024-26815, CVE-2024-26816,

CVE-2024-26848, CVE-2024-26859, CVE-2024-26860, CVE-2024-26861,

CVE-2024-26862, CVE-2024-26863, CVE-2024-26864, CVE-2024-26865,

CVE-2024-26866, CVE-2024-26868, CVE-2024-26869, CVE-2024-26870,

CVE-2024-26871, CVE-2024-26872, CVE-2024-26873, CVE-2024-26874,

CVE-2024-26875, CVE-2024-26876, CVE-2024-26877, CVE-2024-26878,

CVE-2024-26879, CVE-2024-26880, CVE-2024-26881, CVE-2024-26882,

CVE-2024-26883, CVE-2024-26884, CVE-2024-26885, CVE-2024-26886,

CVE-2024-26887, CVE-2024-26888, CVE-2024-26889, CVE-2024-26890,

CVE-2024-26891, CVE-2024-26892, CVE-2024-26893, CVE-2024-26894,

CVE-2024-26895, CVE-2024-26896, CVE-2024-26897, CVE-2024-26898,

CVE-2024-26899, CVE-2024-26900, CVE-2024-26901, CVE-2024-26927,

CVE-2024-26929, CVE-2024-26930, CVE-2024-26931, CVE-2024-26932,

CVE-2024-26933, CVE-2024-26934, CVE-2024-26935, CVE-2024-26937,

CVE-2024-26938, CVE-2024-26939, CVE-2024-26940, CVE-2024-26941,

CVE-2024-26942, CVE-2024-26943, CVE-2024-26944, CVE-2024-26945,

CVE-2024-26946, CVE-2024-26947, CVE-2024-26948, CVE-2024-26949,

CVE-2024-26950, CVE-2024-26951, CVE-2024-26952, CVE-2024-26953,

CVE-2024-26954, CVE-2024-26955, CVE-2024-26956, CVE-2024-26957,

CVE-2024-26958, CVE-2024-26959, CVE-2024-26960, CVE-2024-26961,

CVE-2024-26962, CVE-2024-26963, CVE-2024-26964, CVE-2024-26965,

CVE-2024-26966, CVE-2024-26967, CVE-2024-26968, CVE-2024-26969,

CVE-2024-26970, CVE-2024-26971, CVE-2024-26972, CVE-2024-26973,

CVE-2024-26975, CVE-2024-26976, CVE-2024-26977, CVE-2024-26978,

CVE-2024-26979, CVE-2024-27026, CVE-2024-27027, CVE-2024-27028,

CVE-2024-27029, CVE-2024-27030, CVE-2024-27031, CVE-2024-27032,

CVE-2024-27033, CVE-2024-27034, CVE-2024-27035, CVE-2024-27036,

CVE-2024-27037, CVE-2024-27038, CVE-2024-27039, CVE-2024-27040,

CVE-2024-27041, CVE-2024-27042, CVE-2024-27043, CVE-2024-27044,

CVE-2024-27045, CVE-2024-27046, CVE-2024-27047, CVE-2024-27048,

CVE-2024-27049, CVE-2024-27050, CVE-2024-27051, CVE-2024-27052,

CVE-2024-27053, CVE-2024-27054, CVE-2024-27058, CVE-2024-27063,

CVE-2024-27064, CVE-2024-27065, CVE-2024-27066, CVE-2024-27067,

CVE-2024-27068, CVE-2024-27069, CVE-2024-27070, CVE-2024-27071,

CVE-2024-27072, CVE-2024-27073, CVE-2024-27074, CVE-2024-27075,

CVE-2024-27076, CVE-2024-27077, CVE-2024-27078, CVE-2024-27079,

CVE-2024-27080, CVE-2024-27388, CVE-2024-27389, CVE-2024-27390,

CVE-2024-27391, CVE-2024-27392, CVE-2024-27432, CVE-2024-27433,

CVE-2024-27434, CVE-2024-27435, CVE-2024-27436, CVE-2024-27437,

CVE-2024-35787, CVE-2024-35788, CVE-2024-35789, CVE-2024-35793,

CVE-2024-35794, CVE-2024-35795, CVE-2024-35796, CVE-2024-35797,

CVE-2024-35798, CVE-2024-35799, CVE-2024-35800, CVE-2024-35801,

CVE-2024-35803, CVE-2024-35805, CVE-2024-35806, CVE-2024-35807,

CVE-2024-35808, CVE-2024-35809, CVE-2024-35810, CVE-2024-35811,

CVE-2024-35813, CVE-2024-35814, CVE-2024-35817, CVE-2024-35819,

CVE-2024-35821, CVE-2024-35822, CVE-2024-35826, CVE-2024-35827,

CVE-2024-35828, CVE-2024-35829, CVE-2024-35830, CVE-2024-35831,

CVE-2024-35843, CVE-2024-35844, CVE-2024-35845, CVE-2024-35874

Severity
critical
Lowest
Low
Medium
High
Critical

Ubuntu Security Notice USN-6817-3

Package Information

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.