Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2023-3609

Published: 21 July 2023

A use-after-free vulnerability in the Linux kernel's net/sched: cls_u32 component can be exploited to achieve local privilege escalation. If tcf_change_indev() fails, u32_set_parms() will immediately return an error after incrementing or decrementing the reference counter in tcf_bind_filter(). If an attacker can control the reference counter and set it to zero, they can cause the reference to be freed, leading to a use-after-free vulnerability. We recommend upgrading past commit 04c55383fa5689357bcdd2c8036725a55ed632bc.

From the Ubuntu Security Team

It was discovered that the universal 32bit network packet classifier implementation in the Linux kernel did not properly perform reference counting in some situations, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code.

Notes

AuthorNote
Priority reason:
By using unprivileged user namespaces, this can be exploited to achieve local privilege escalation.

Mitigation

If not needed, disable the ability for unprivileged users
to create namespaces. To do this temporarily, do:
  sudo sysctl -w kernel.unprivileged_userns_clone=0
To disable across reboots, do:
  echo kernel.unprivileged_userns_clone=0 | \
  sudo tee /etc/sysctl.d/99-disable-unpriv-userns.conf

Priority

High

Cvss 3 Severity Score

7.8

Score breakdown

Status

Package Release Status
linux
Launchpad, Ubuntu, Debian
bionic Not vulnerable
(4.13.0-16.19)
kinetic Ignored
(end of life, was needs-triage)
trusty Not vulnerable
(3.11.0-12.19)
upstream
Released (6.4~rc7)
xenial Not vulnerable
(4.4.0-2.16)
focal
Released (5.4.0-159.176)
lunar
Released (6.2.0-31.31)
jammy
Released (5.15.0-82.91)
Patches:
Introduced by

a51486266c3ba8e035a47fa96df67f274fe0c7d0

Fixed by 04c55383fa5689357bcdd2c8036725a55ed632bc
linux-hwe
Launchpad, Ubuntu, Debian
trusty Does not exist

bionic Needs triage

focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
xenial Not vulnerable
(4.8.0-39.42~16.04.1)
linux-hwe-5.4
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
bionic
Released (5.4.0-159.176~18.04.1)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only)
linux-hwe-5.8
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(superseded by linux-hwe-5.11)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-hwe-5.11)
linux-hwe-5.11
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(superseded by linux-hwe-5.13)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-hwe-5.13)
linux-hwe-5.13
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(superseded by linux-hwe-5.15)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-hwe-5.15)
linux-hwe-5.15
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
focal
Released (5.15.0-82.91~20.04.1)
linux-hwe-5.19
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

kinetic Does not exist

lunar Does not exist

jammy Needed

upstream
Released (6.4~rc7)
linux-hwe-edge
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Ignored
(superseded by linux-hwe)
bionic Ignored
(superseded by linux-hwe-5.4)
focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-lts-xenial
Launchpad, Ubuntu, Debian
xenial Does not exist

bionic Does not exist

focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

trusty Not vulnerable
(4.4.0-13.29~14.04.1)
upstream
Released (6.4~rc7)
linux-kvm
Launchpad, Ubuntu, Debian
trusty Does not exist

kinetic Ignored
(end of life, was needs-triage)
upstream
Released (6.4~rc7)
xenial Not vulnerable
(4.4.0-1004.9)
bionic Not vulnerable
(4.15.0-1002.2)
focal
Released (5.4.0-1097.103)
lunar
Released (6.2.0-1011.11)
jammy
Released (5.15.0-1040.45)
linux-allwinner
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

jammy Does not exist

lunar Ignored
(end of life, was needs-triage)
upstream
Released (6.4~rc7)
kinetic Ignored
(end of life, was needs-triage)
linux-allwinner-5.19
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

kinetic Does not exist

lunar Does not exist

jammy Needed

upstream
Released (6.4~rc7)
linux-aws-5.0
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Ignored
(superseded by linux-hwe-5.3)
focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-aws-5.3
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Ignored
(superseded by linux-hwe-5.4)
focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-aws-5.4)
linux-aws-5.4
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

bionic
Released (5.4.0-1108.116~18.04.1)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only)
upstream
Released (6.4~rc7)
linux-aws-5.8
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(superseded by linux-aws-5.11)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-aws-5.11)
linux-aws-5.11
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(superseded by linux-aws-5.13)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-aws-5.13)
linux-aws-5.13
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(superseded by linux-aws-5.15)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-aws-5.15)
linux-aws-5.15
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal
Released (5.15.0-1043.48~20.04.1)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-aws-5.19
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

kinetic Does not exist

lunar Does not exist

jammy Ignored
(end of life, was needs-triage)
upstream
Released (6.4~rc7)
linux-aws-hwe
Launchpad, Ubuntu, Debian
trusty Does not exist

bionic Does not exist

focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
xenial Not vulnerable
(4.15.0-1030.31~16.04.1)
linux-azure
Launchpad, Ubuntu, Debian
bionic Ignored
(superseded by linux-azure-5.3)
kinetic Ignored
(end of life, was needs-triage)
focal
Released (5.4.0-1114.120)
jammy
Released (5.15.0-1045.52)
lunar
Released (6.2.0-1010.10)
upstream
Released (6.4~rc7)
trusty Not vulnerable
(4.15.0-1023.24~14.04.1)
xenial Not vulnerable
(4.11.0-1009.9)
linux-azure-4.15
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
bionic Not vulnerable
(4.15.0-1082.92)
linux-azure-5.3
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Ignored
(superseded by linux-azure-5.4)
focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-azure-5.4)
linux-azure-5.4
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
bionic Pending

linux-azure-5.8
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(superseded by linux-azure-5.11)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-azure-5.11)
linux-azure-5.11
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(superseded by linux-azure-5.13)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-azure-5.13)
linux-azure-5.13
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(superseded by linux-azure-5.15)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-azure-5.15)
linux-azure-5.15
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
focal
Released (5.15.0-1045.52~20.04.1)
linux-azure-5.19
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

kinetic Does not exist

lunar Does not exist

jammy Ignored
(end of life, was needs-triage)
upstream
Released (6.4~rc7)
linux-azure-fde
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
focal Pending
(5.4.0-1115.122)
jammy
Released (5.15.0-1045.52.1)
linux-azure-fde-5.15
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

focal Pending

upstream
Released (6.4~rc7)
linux-azure-fde-5.19
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

jammy Needs triage

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-bluefield
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

kinetic Does not exist

lunar Does not exist

focal Needed

jammy Pending

upstream
Released (6.4~rc7)
linux-dell300x
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Ignored
(end of standard support)
focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-azure-edge
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Ignored
(superseded by linux-azure-5.3)
focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-fips
Launchpad, Ubuntu, Debian
trusty Ignored
(end of standard support)
xenial Ignored
(end of standard support)
bionic Does not exist

focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-gcp
Launchpad, Ubuntu, Debian
trusty Does not exist

bionic Ignored
(superseded by linux-gcp-5.3)
kinetic Ignored
(end of life, was needs-triage)
upstream
Released (6.4~rc7)
lunar
Released (6.2.0-1012.12)
xenial Not vulnerable
(4.10.0-1004.4)
focal
Released (5.4.0-1111.120)
jammy
Released (5.15.0-1040.48)
linux-gcp-4.15
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
bionic Not vulnerable
(4.15.0-1071.81)
linux-gcp-5.3
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Ignored
(superseded by linux-gcp-5.4)
focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-gcp-5.4)
linux-gcp-5.4
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

bionic
Released (5.4.0-1111.120~18.04.1)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only)
upstream
Released (6.4~rc7)
linux-gcp-5.8
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(superseded by linux-gcp-5.11)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-gcp-5.11)
linux-gcp-5.11
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(superseded by linux-gcp-5.13)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-gcp-5.13)
linux-gcp-5.13
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(superseded by linux-gcp-5.15)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-gcp-5.15)
linux-gcp-5.15
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
focal
Released (5.15.0-1040.48~20.04.1)
linux-gcp-5.19
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

kinetic Does not exist

lunar Does not exist

jammy Ignored
(end of life, was needs-triage)
upstream
Released (6.4~rc7)
linux-gke
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Ignored
(end of standard support)
bionic Does not exist

kinetic Does not exist

lunar Does not exist

jammy
Released (5.15.0-1040.45)
upstream
Released (6.4~rc7)
focal Ignored
(end of life, was needed)
linux-gke-4.15
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Needs triage

focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-gke-5.0
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Ignored
(end of standard support)
focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-gke-5.3
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Ignored
(end of standard support)
focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-gke-5.4)
linux-gke-5.4
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Needs triage

focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-gke-5.15
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(end of life, was needed)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-gkeop
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
focal
Released (5.4.0-1075.79)
jammy
Released (5.15.0-1026.31)
linux-gkeop-5.4
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Needs triage

focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-gkeop-5.15
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
focal
Released (5.15.0-1026.31~20.04.1)
linux-ibm
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

kinetic Ignored
(end of life, was needs-triage)
upstream
Released (6.4~rc7)
focal Pending

lunar
Released (6.2.0-1008.8)
jammy
Released (5.15.0-1036.39)
linux-ibm-5.4
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

bionic Needed

upstream
Released (6.4~rc7)
linux-intel-5.13
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

focal Ignored
(end of life, was needs-triage)
upstream
Released (6.4~rc7)
linux-intel-iotg
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

jammy
Released (5.15.0-1038.43)
kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-intel-iotg-5.15
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
focal Pending

linux-iot
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
focal Pending

linux-lowlatency
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

kinetic Ignored
(end of life, was needs-triage)
upstream
Released (6.4~rc7)
lunar
Released (6.2.0-1011.11)
jammy
Released (5.15.0-82.91)
linux-lowlatency-hwe-5.15
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
focal
Released (5.15.0-82.91~20.04.1)
linux-lowlatency-hwe-5.19
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

kinetic Does not exist

lunar Does not exist

jammy Needed

upstream
Released (6.4~rc7)
linux-nvidia
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

kinetic Does not exist

lunar Does not exist

jammy
Released (5.15.0-1031.31)
upstream
Released (6.4~rc7)
linux-oracle
Launchpad, Ubuntu, Debian
trusty Does not exist

kinetic Ignored
(end of life, was needs-triage)
focal
Released (5.4.0-1107.116)
jammy
Released (5.15.0-1041.47)
lunar
Released (6.2.0-1010.10)
upstream
Released (6.4~rc7)
bionic Not vulnerable
(4.15.0-1007.9)
xenial Not vulnerable
(4.15.0-1007.9~16.04.1)
linux-oracle-5.0
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Ignored
(superseded by linux-oracle-5.3)
focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-oracle-5.3
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Ignored
(superseded by linux-oracle-5.4)
focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-oracle-5.4)
linux-oracle-5.4
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
bionic
Released (5.4.0-1107.116~18.04.1)
Available with Ubuntu Pro or Ubuntu Pro (Infra-only)
linux-oracle-5.8
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(superseded by linux-oracle-5.11)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-oracle-5.11)
linux-oracle-5.11
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(superseded by linux-oracle-5.13)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-oracle-5.13)
linux-oracle-5.13
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

focal Ignored
(end of life, was needs-triage)
upstream
Released (6.4~rc7)
linux-oracle-5.15
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
focal
Released (5.15.0-1041.47~20.04.1)
linux-oem
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Ignored
(end of standard support)
bionic Needs triage

focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-oem-5.6
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

focal Ignored
(end of life, was needs-triage)
upstream
Released (6.4~rc7)
linux-oem-5.10
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(end of life, was needs-triage)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-oem-5.13
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(superseded by linux-oem-5.14)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-oem-5.14)
linux-oem-5.14
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

focal Ignored
(end of life, was needs-triage)
upstream
Released (6.4~rc7)
linux-oem-5.17
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

lunar Does not exist

kinetic Ignored
(end of life, was needs-triage)
jammy Pending

upstream
Released (6.4~rc7)
linux-oem-6.0
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
jammy Pending

linux-oem-6.1
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
jammy
Released (6.1.0-1019.19)
linux-oem-osp1
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Ignored
(end of standard support)
focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-raspi
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

kinetic Ignored
(end of life, was needs-triage)
upstream
Released (6.4~rc7)
focal Pending
(5.4.0-1093.104)
jammy Pending
(5.15.0-1037.40)
lunar
Released (6.2.0-1011.13)
linux-raspi2
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Ignored
(end of standard support)
bionic Ignored
(end of standard support)
focal Ignored
(replaced by linux-raspi)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-raspi2-5.3
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Ignored
(end of standard support)
focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-raspi2-5.4)
linux-raspi-5.4
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Needed

focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-riscv
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(superseded by linux-riscv-5.8)
kinetic Ignored
(end of life, was needs-triage)
jammy Ignored
(end of life, was needs-triage)
upstream
Released (6.4~rc7)
lunar
Released (6.2.0-31.31.1)
linux-riscv-5.8
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(superseded by linux-riscv-5.11)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-riscv-5.11)
linux-riscv-5.11
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Ignored
(superseded by linux-riscv-5.13)
jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream Ignored
(superseded by linux-riscv-5.13)
linux-riscv-5.15
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
focal
Released (5.15.0-1039.43~20.04.2)
linux-riscv-5.19
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

kinetic Does not exist

lunar Does not exist

jammy Ignored
(end of life, was needs-triage)
upstream
Released (6.4~rc7)
linux-snapdragon
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Ignored
(end of standard support)
bionic Ignored
(end of standard support)
focal Does not exist

jammy Does not exist

kinetic Does not exist

lunar Does not exist

upstream
Released (6.4~rc7)
linux-starfive
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

jammy Does not exist

upstream
Released (6.4~rc7)
kinetic Ignored
(end of life, was needs-triage)
lunar
Released (6.2.0-1003.3)
linux-starfive-5.19
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

kinetic Does not exist

lunar Does not exist

jammy Ignored
(end of life, was needs-triage)
upstream
Released (6.4~rc7)
linux-xilinx-zynqmp
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

kinetic Does not exist

lunar Does not exist

jammy Ignored
(end of life, was needs-triage)
upstream
Released (6.4~rc7)
focal
Released (5.4.0-1028.32)
linux-aws
Launchpad, Ubuntu, Debian
kinetic Ignored
(end of life, was needs-triage)
trusty Not vulnerable
(4.4.0-1002.2)
upstream
Released (6.4~rc7)
xenial Not vulnerable
(4.4.0-1001.10)
bionic Not vulnerable
(4.15.0-1001.1)
focal
Released (5.4.0-1108.116)
lunar
Released (6.2.0-1010.10)
jammy
Released (5.15.0-1043.48)
linux-aws-6.2
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

lunar Does not exist

jammy
Released (6.2.0-1010.10~22.04.1)
upstream
Released (6.4~rc7)
linux-hwe-6.2
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

lunar Does not exist

jammy
Released (6.2.0-31.31~22.04.1)
upstream
Released (6.4~rc7)
linux-lowlatency-hwe-6.2
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

lunar Does not exist

jammy
Released (6.2.0-1011.11~22.04.1)
upstream
Released (6.4~rc7)
linux-ibm-5.15
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Not vulnerable

jammy Does not exist

lunar Does not exist

upstream Needs triage

linux-gcp-6.2
Launchpad, Ubuntu, Debian
trusty Does not exist

xenial Does not exist

bionic Does not exist

focal Does not exist

jammy Not vulnerable

lunar Does not exist

upstream Needs triage

Severity score breakdown

Parameter Value
Base score 7.8
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality High
Integrity impact High
Availability impact High
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H