Ubuntu Security Notice USN-5976-1

Discussion in 'News Aggregator' started by Packet Storm, 29 Mar 2023.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 5976-1 - It was discovered that the Upper Level Protocol subsystem in the Linux kernel did not properly handle sockets entering the LISTEN state in certain protocols, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. It was discovered that the KVM VMX implementation in the Linux kernel did not properly handle indirect branch prediction isolation between L1 and L2 VMs. An attacker in a guest VM could use this to expose sensitive information from the host OS or other guest VMs.

    Continue reading...
     

Share This Page

Loading...