The sgdisk utility of GPT fdisk could be made to crash or possibly allow for elevated privileges.. =========================================================================Ubuntu Security Notice USN-5262-1 February 03, 2022 gdisk vulnerabilities ========================================================================= A security issue affects these releases of Ubuntu and its derivatives: - Ubuntu 16.04 ESM Summary: The sgdisk utility of GPT fdisk could be made to crash or possibly allow for elevated privileges. Software Description: - gdisk: GPT fdisk text-mode partitioning tool Details: The potential for an out of bounds write due to a missing bounds check was discovered to impact the sgdisk utility of GPT fdisk. Exploitation requires the use of a maliciously formatted storage device and could cause sgdisk to crash as well as possibly allow for local privilege escalation. Update instructions: The problem can be corrected by updating your system to the following package versions: Ubuntu 16.04 ESM: gdisk 1.0.1-1ubuntu0.1~esm2 In general, a standard system update will make all the necessary changes. References: https://ubuntu.com/security/notices/USN-5262-1 CVE-2020-0256, CVE-2021-0308 . Ubuntu 5262-1 addresses gdisk security flaws that could lead to local privilege elevation and system failures from malicious storage hardware.. Ubuntu Security, gdisk Utility, Elevated Privileges, Out of Bounds Write. . Severity: Critical. LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.