Ubuntu Security Notice USN-6724-2

Discussion in 'News Aggregator' started by Packet Storm, 18 Apr 2024.

  1. Packet Storm

    Packet Storm Guest

    Ubuntu Security Notice 6724-2 - Pratyush Yadav discovered that the Xen network backend implementation in the Linux kernel did not properly handle zero length data request, leading to a null pointer dereference vulnerability. An attacker in a guest VM could possibly use this to cause a denial of service. It was discovered that the Habana's AI Processors driver in the Linux kernel did not properly initialize certain data structures before passing them to user space. A local attacker could use this to expose sensitive information.

    Continue reading...
     

Share This Page

Loading...