{"id":"USN-5879-1","summary":"linux-hwe-5.19 vulnerabilities","details":"Kyle Zeng discovered that the sysctl implementation in the Linux kernel\ncontained a stack-based buffer overflow. A local attacker could use this to\ncause a denial of service (system crash) or execute arbitrary code.\n(CVE-2022-4378)\n\nTamás Koczka discovered that the Bluetooth L2CAP handshake implementation\nin the Linux kernel contained multiple use-after-free vulnerabilities. A\nphysically proximate attacker could use this to cause a denial of service\n(system crash) or possibly execute arbitrary code. (CVE-2022-42896)\n\nIt was discovered that the Bluetooth HCI implementation in the Linux kernel\ndid not properly deallocate memory in some situations. An attacker could\npossibly use this cause a denial of service (memory exhaustion).\n(CVE-2022-3619)\n\nIt was discovered that the Broadcom FullMAC USB WiFi driver in the Linux\nkernel did not properly perform bounds checking in some situations. A\nphysically proximate attacker could use this to craft a malicious USB\ndevice that when inserted, could cause a denial of service (system crash)\nor possibly execute arbitrary code. (CVE-2022-3628)\n\nIt was discovered that a use-after-free vulnerability existed in the\nBluetooth stack in the Linux kernel. A local attacker could use this to\ncause a denial of service (system crash) or possibly execute arbitrary\ncode. (CVE-2022-3640)\n\nIt was discovered that the Xen netback driver in the Linux kernel did not\nproperly handle packets structured in certain ways. An attacker in a guest\nVM could possibly use this to cause a denial of service (host NIC\navailability). (CVE-2022-3643)\n\nTamás Koczka discovered that the Bluetooth L2CAP implementation in the\nLinux kernel did not properly initialize memory in some situations. A\nphysically proximate attacker could possibly use this to expose sensitive\ninformation (kernel memory). (CVE-2022-42895)\n\nIt was discovered that an integer overflow vulnerability existed in the\nBluetooth subsystem in the Linux kernel. A physically proximate attacker\ncould use this to cause a denial of service (system crash).\n(CVE-2022-45934)\n\nIt was discovered that a race condition existed in the qdisc implementation\nin the Linux kernel, leading to a use-after-free vulnerability. A local\nattacker could use this to cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2023-0590)\n\n","modified":"2026-02-10T04:42:57Z","published":"2023-02-16T14:38:12Z","related":["UBUNTU-CVE-2022-3619","UBUNTU-CVE-2022-3628","UBUNTU-CVE-2022-3640","UBUNTU-CVE-2022-3643","UBUNTU-CVE-2022-42895","UBUNTU-CVE-2022-42896","UBUNTU-CVE-2022-4378","UBUNTU-CVE-2022-45934","UBUNTU-CVE-2023-0590"],"upstream":["CVE-2022-3619","CVE-2022-3628","CVE-2022-3640","CVE-2022-3643","CVE-2022-42895","CVE-2022-42896","CVE-2022-4378","CVE-2022-45934","CVE-2023-0590","UBUNTU-CVE-2022-3619","UBUNTU-CVE-2022-3628","UBUNTU-CVE-2022-3640","UBUNTU-CVE-2022-3643","UBUNTU-CVE-2022-42895","UBUNTU-CVE-2022-42896","UBUNTU-CVE-2022-4378","UBUNTU-CVE-2022-45934","UBUNTU-CVE-2023-0590"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-5879-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-3619"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-3628"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-3640"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-3643"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-4378"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-42895"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-42896"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2022-45934"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-0590"}],"affected":[{"package":{"name":"linux-hwe-5.19","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/linux-hwe-5.19@5.19.0-32.33~22.04.1?arch=source&distro=jammy"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.19.0-32.33~22.04.1"}]}],"versions":["5.19.0-28.29~22.04.1"],"ecosystem_specific":{"availability":"No subscription required","binaries":[{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-buildinfo-5.19.0-32-generic"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-buildinfo-5.19.0-32-generic-64k"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-buildinfo-5.19.0-32-generic-lpae"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-cloud-tools-5.19.0-32-generic"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-headers-5.19.0-32-generic"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-headers-5.19.0-32-generic-64k"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-headers-5.19.0-32-generic-lpae"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-hwe-5.19-cloud-tools-5.19.0-32"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-hwe-5.19-cloud-tools-common"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-hwe-5.19-headers-5.19.0-32"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-hwe-5.19-tools-5.19.0-32"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-hwe-5.19-tools-common"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-hwe-5.19-tools-host"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-image-5.19.0-32-generic"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-image-5.19.0-32-generic-lpae"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-image-unsigned-5.19.0-32-generic"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-image-unsigned-5.19.0-32-generic-64k"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-modules-5.19.0-32-generic"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-modules-5.19.0-32-generic-64k"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-modules-5.19.0-32-generic-lpae"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-modules-extra-5.19.0-32-generic"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-modules-ipu6-5.19.0-32-generic"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-modules-ivsc-5.19.0-32-generic"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-modules-iwlwifi-5.19.0-32-generic"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-source-5.19.0"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-tools-5.19.0-32-generic"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-tools-5.19.0-32-generic-64k"},{"binary_version":"5.19.0-32.33~22.04.1","binary_name":"linux-tools-5.19.0-32-generic-lpae"}]},"database_specific":{"cves_map":{"ecosystem":"Ubuntu:22.04:LTS","cves":[{"id":"CVE-2022-3619","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2022-3628","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:P/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2022-3640","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2022-3643","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2022-4378","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"high"}]},{"id":"CVE-2022-42895","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2022-42896","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"high"}]},{"id":"CVE-2022-45934","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}]},{"id":"CVE-2023-0590","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}]},"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-5879-1.json"}}],"schema_version":"1.7.3"}