{"id":"USN-5860-1","summary":"linux-gke vulnerabilities","details":"\nKyle Zeng discovered that the sysctl implementation in the Linux kernel\ncontained a stack-based buffer overflow. A local attacker could use this to\ncause a denial of service (system crash) or execute arbitrary code.\n(CVE-2022-4378)\n\nTamás Koczka discovered that the Bluetooth L2CAP handshake implementation\nin the Linux kernel contained multiple use-after-free vulnerabilities. A\nphysically proximate attacker could use this to cause a denial of service\n(system crash) or possibly execute arbitrary code. (CVE-2022-42896)\n\nIt was discovered that a memory leak existed in the Unix domain socket\nimplementation of the Linux kernel. A local attacker could use this to\ncause a denial of service (memory exhaustion). (CVE-2022-3543)\n\nIt was discovered that the Bluetooth HCI implementation in the Linux kernel\ndid not properly deallocate memory in some situations. An attacker could\npossibly use this cause a denial of service (memory exhaustion).\n(CVE-2022-3619)\n\nIt was discovered that the hugetlb implementation in the Linux kernel\ncontained a race condition in some situations. A local attacker could use\nthis to cause a denial of service (system crash) or expose sensitive\ninformation (kernel memory). (CVE-2022-3623)\n\nIt was discovered that the Broadcom FullMAC USB WiFi driver in the Linux\nkernel did not properly perform bounds checking in some situations. A\nphysically proximate attacker could use this to craft a malicious USB\ndevice that when inserted, could cause a denial of service (system crash)\nor possibly execute arbitrary code. (CVE-2022-3628)\n\nIt was discovered that a use-after-free vulnerability existed in the\nBluetooth stack in the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2022-3640)\n\nIt was discovered that the Xen netback driver in the Linux kernel did not\nproperly handle packets structured in certain ways. An attacker in a guest\nVM could possibly use this to cause a denial of service (host NIC\navailability). (CVE-2022-3643)\n\nIt was discovered that a race condition existed in the SMSC UFX USB driver\nimplementation in the Linux kernel, leading to a use-after-free\nvulnerability. A physically proximate attacker could use this to cause a\ndenial of service (system crash) or possibly execute arbitrary code.\n(CVE-2022-41849)\n\nIt was discovered that a race condition existed in the Roccat HID driver in\nthe Linux kernel, leading to a use-after-free vulnerability. A local\nattacker could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2022-41850)\n\nTamás Koczka discovered that the Bluetooth L2CAP implementation in the\nLinux kernel did not properly initialize memory in some situations. A\nphysically proximate attacker could possibly use this to expose sensitive\ninformation (kernel memory). (CVE-2022-42895)\n\nIt was discovered that an integer overflow vulnerability existed in the\nBluetooth subsystem in the Linux kernel. A physically proximate attacker\ncould use this to cause a denial of service (system crash).\n(CVE-2022-45934)\n\nArnaud Gatignol, Quentin Minster, Florent Saudel and Guillaume Teissier\ndiscovered that the KSMBD implementation in the Linux kernel did not\nproperly validate user-supplied data in some situations. An authenticated\nattacker could use this to cause a denial of service (system crash), expose\nsensitive information (kernel memory) or possibly execute arbitrary code.\n(CVE-2022-47940)\n\nIt was discovered that a race condition existed in the qdisc implementation\nin the Linux kernel, leading to a use-after-free vulnerability. A local\nattacker could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2023-0590)\n\n","modified":"2026-02-10T04:42:57Z","published":"2023-02-09T22:31:43Z","related":["UBUNTU-CVE-2022-3543","UBUNTU-CVE-2022-3619","UBUNTU-CVE-2022-3623","UBUNTU-CVE-2022-3628","UBUNTU-CVE-2022-3640","UBUNTU-CVE-2022-3643","UBUNTU-CVE-2022-41849","UBUNTU-CVE-2022-41850","UBUNTU-CVE-2022-42895","UBUNTU-CVE-2022-42896","UBUNTU-CVE-2022-4378","UBUNTU-CVE-2022-45934","UBUNTU-CVE-2022-47940","UBUNTU-CVE-2023-0590"],"upstream":["CVE-2022-3543","CVE-2022-3619","CVE-2022-3623","CVE-2022-3628","CVE-2022-3640","CVE-2022-3643","CVE-2022-41849","CVE-2022-41850","CVE-2022-42895","CVE-2022-42896","CVE-2022-4378","CVE-2022-45934","CVE-2022-47940","CVE-2023-0590","UBUNTU-CVE-2022-3543","UBUNTU-CVE-2022-3619","UBUNTU-CVE-2022-3623","UBUNTU-CVE-2022-3628","UBUNTU-CVE-2022-3640","UBUNTU-CVE-2022-3643","UBUNTU-CVE-2022-41849","UBUNTU-CVE-2022-41850","UBUNTU-CVE-2022-42895","UBUNTU-CVE-2022-42896","UBUNTU-CVE-2022-4378","UBUNTU-CVE-2022-45934","UBUNTU-CVE-2022-47940","UBUNTU-CVE-2023-0590"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-5860-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-3543"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-3619"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-3623"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-3628"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-3640"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-3643"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-4378"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-41849"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-41850"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-42895"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-42896"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-45934"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-47940"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-0590"}],"affected":[{"package":{"name":"linux-gke","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/linux-gke@5.15.0-1027.32?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.15.0-1027.32"}]}],"versions":["5.15.0-1002.2","5.15.0-1003.3","5.15.0-1004.5","5.15.0-1005.6","5.15.0-1006.7","5.15.0-1008.10","5.15.0-1010.13","5.15.0-1011.14","5.15.0-1014.17","5.15.0-1015.18","5.15.0-1016.19","5.15.0-1017.20","5.15.0-1019.23","5.15.0-1020.25","5.15.0-1023.28","5.15.0-1024.29"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"5.15.0-1027.32","binary_name":"linux-buildinfo-5.15.0-1027-gke"},{"binary_version":"5.15.0-1027.32","binary_name":"linux-gke-headers-5.15.0-1027"},{"binary_version":"5.15.0-1027.32","binary_name":"linux-gke-tools-5.15.0-1027"},{"binary_version":"5.15.0-1027.32","binary_name":"linux-headers-5.15.0-1027-gke"},{"binary_version":"5.15.0-1027.32","binary_name":"linux-image-unsigned-5.15.0-1027-gke"},{"binary_version":"5.15.0-1027.32","binary_name":"linux-modules-5.15.0-1027-gke"},{"binary_version":"5.15.0-1027.32","binary_name":"linux-modules-extra-5.15.0-1027-gke"},{"binary_version":"5.15.0-1027.32","binary_name":"linux-modules-iwlwifi-5.15.0-1027-gke"},{"binary_version":"5.15.0-1027.32","binary_name":"linux-tools-5.15.0-1027-gke"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5860-1.json","cves_map":{"cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2022-3543"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2022-3619"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2022-3623"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2022-3628"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2022-3640"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2022-3643"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"high"}],"id":"CVE-2022-4378"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:P/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2022-41849"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2022-41850"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2022-42895"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"high"}],"id":"CVE-2022-42896"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2022-45934"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2022-47940"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2023-0590"}],"ecosystem":"Ubuntu:22.04:LTS"}}}],"schema_version":"1.7.3"}