Ubuntu Security Notice USN-5385-1

Discussion in 'News Aggregator' started by Packet Storm, 22 Apr 2022.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 5385-1 - Brendan Dolan-Gavitt discovered that the aQuantia AQtion Ethernet device driver in the Linux kernel did not properly validate meta-data coming from the device. A local attacker who can control an emulated device can use this to cause a denial of service or possibly execute arbitrary code. It was discovered that the UDF file system implementation in the Linux kernel could attempt to dereference a null pointer in some situations. An attacker could use this to construct a malicious UDF image that, when mounted and operated on, could cause a denial of service.

    Continue reading...
     

Share This Page

Loading...