USN-4577-1: Linux kernel vulnerabilities
Publication date
14 October 2020
Overview
Several security issues were fixed in the Linux kernel.
Releases
Packages
- linux-gke-5.0 - Linux kernel for Google Container Engine (GKE) systems
- linux-gke-5.3 - Linux kernel for Google Container Engine (GKE) systems
- linux-hwe - Linux hardware enablement (HWE) kernel
- linux-oem-osp1 - Linux kernel for OEM systems
- linux-raspi2-5.3 - Linux kernel for Raspberry Pi (V8) systems
Details
Hadar Manor discovered that the DCCP protocol implementation in the Linux
kernel improperly handled socket reuse, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2020-16119)
Giuseppe Scrivano discovered that the overlay file system in the Linux
kernel did not properly perform permission checks in some situations. A
local attacker could possibly use this to bypass intended restrictions and
gain read access to restricted files. (CVE-2020-16120)
Hadar Manor discovered that the DCCP protocol implementation in the Linux
kernel improperly handled socket reuse, leading to a use-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly execute arbitrary code. (CVE-2020-16119)
Giuseppe Scrivano discovered that the overlay file system in the Linux
kernel did not properly perform permission checks in some situations. A
local attacker could possibly use this to bypass intended restrictions and
gain read access to restricted files. (CVE-2020-16120)
Update instructions
After a standard system update you need to reboot your computer to make all the necessary changes.
Learn more about how to get the fixes.The problem can be corrected by updating your system to the following package versions:
Reduce your security exposure
Ubuntu Pro provides ten-year security coverage to 25,000+ packages in Main and Universe repositories, and it is free for up to five machines.
Related notices
Have additional questions?