{"id":"USN-6084-1","summary":"linux-gcp-4.15, linux-oracle vulnerabilities","details":"\nJordy Zomer and Alexandra Sandulescu discovered that the Linux kernel did\nnot properly implement speculative execution barriers in usercopy functions\nin certain situations. A local attacker could use this to expose sensitive\ninformation (kernel memory). (CVE-2023-0459)\n\nXingyuan Mo discovered that the x86 KVM implementation in the Linux kernel\ndid not properly initialize some data structures. A local attacker could\nuse this to expose sensitive information (kernel memory). (CVE-2023-1513)\n\nIt was discovered that a use-after-free vulnerability existed in the iSCSI\nTCP implementation in the Linux kernel. A local attacker could possibly use\nthis to cause a denial of service (system crash). (CVE-2023-2162)\n\nIt was discovered that the NET/ROM protocol implementation in the Linux\nkernel contained a race condition in some situations, leading to a use-\nafter-free vulnerability. A local attacker could use this to cause a denial\nof service (system crash) or possibly execute arbitrary code.\n(CVE-2023-32269)\n\nDuoming Zhou discovered that a race condition existed in the infrared\nreceiver/transceiver driver in the Linux kernel, leading to a use-after-\nfree vulnerability. A privileged attacker could use this to cause a denial\nof service (system crash) or possibly execute arbitrary code.\n(CVE-2023-1118)\n\n","modified":"2026-04-27T16:35:56.407414Z","published":"2023-05-17T17:52:55Z","related":["UBUNTU-CVE-2023-0459","UBUNTU-CVE-2023-1118","UBUNTU-CVE-2023-1513","UBUNTU-CVE-2023-2162","UBUNTU-CVE-2023-32269"],"upstream":["CVE-2023-0459","CVE-2023-1118","CVE-2023-1513","CVE-2023-2162","CVE-2023-32269","UBUNTU-CVE-2023-0459","UBUNTU-CVE-2023-1118","UBUNTU-CVE-2023-1513","UBUNTU-CVE-2023-2162","UBUNTU-CVE-2023-32269"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6084-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-0459"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-1118"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-1513"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-2162"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-32269"}],"affected":[{"package":{"name":"linux-oracle","ecosystem":"Ubuntu:Pro:16.04:LTS","purl":"pkg:deb/ubuntu/linux-oracle@4.15.0-1119.130~16.04.1?arch=source&distro=esm-infra/xenial"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.15.0-1119.130~16.04.1"}]}],"versions":["4.15.0-1007.9~16.04.1","4.15.0-1008.10~16.04.1","4.15.0-1009.11~16.04.1","4.15.0-1010.12~16.04.1","4.15.0-1011.13~16.04.1","4.15.0-1013.15~16.04.1","4.15.0-1014.16~16.04.1","4.15.0-1015.17~16.04.1","4.15.0-1017.19~16.04.2","4.15.0-1018.20~16.04.1","4.15.0-1021.23~16.04.1","4.15.0-1022.25~16.04.1","4.15.0-1023.26~16.04.1","4.15.0-1025.28~16.04.1","4.15.0-1026.29~16.04.1","4.15.0-1027.30~16.04.1","4.15.0-1029.32~16.04.1","4.15.0-1030.33~16.04.1","4.15.0-1031.34~16.04.1","4.15.0-1033.36~16.04.1","4.15.0-1035.38~16.04.1","4.15.0-1037.41~16.04.1","4.15.0-1038.42~16.04.1","4.15.0-1039.43~16.04.1","4.15.0-1045.49~16.04.1","4.15.0-1046.50~16.04.1","4.15.0-1050.54~16.04.1","4.15.0-1051.55~16.04.1","4.15.0-1053.57~16.04.1","4.15.0-1054.58~16.04.1","4.15.0-1056.61~16.04.1","4.15.0-1058.64~16.04.1","4.15.0-1059.65~16.04.1","4.15.0-1061.67~16.04.1","4.15.0-1062.68~16.04.1","4.15.0-1064.71~16.04.1","4.15.0-1065.73~16.04.1","4.15.0-1066.74~16.04.1","4.15.0-1067.75~16.04.1","4.15.0-1068.76~16.04.1","4.15.0-1069.77~16.04.1","4.15.0-1070.78~16.04.1","4.15.0-1071.79~16.04.1","4.15.0-1072.80~16.04.1","4.15.0-1075.83~16.04.1","4.15.0-1078.86~16.04.1","4.15.0-1079.87~16.04.1","4.15.0-1080.88~16.04.1","4.15.0-1081.89~16.04.1","4.15.0-1082.90~16.04.1","4.15.0-1083.91~16.04.1","4.15.0-1084.92~16.04.1","4.15.0-1085.93~16.04.1","4.15.0-1086.94~16.04.1","4.15.0-1087.95~16.04.1","4.15.0-1089.98~16.04.1","4.15.0-1090.99~16.04.1","4.15.0-1091.100~16.04.1","4.15.0-1092.101~16.04.1","4.15.0-1093.102~16.04.1","4.15.0-1095.104~16.04.1","4.15.0-1098.108~16.04.1","4.15.0-1101.112~16.04.1","4.15.0-1102.113~16.04.1","4.15.0-1104.115~16.04.1","4.15.0-1105.116~16.04.1","4.15.0-1106.117~16.04.1","4.15.0-1107.118~16.04.1","4.15.0-1108.119~16.04.1","4.15.0-1111.122~16.04.2","4.15.0-1112.123~16.04.1","4.15.0-1113.124~16.04.1","4.15.0-1115.126~16.04.1","4.15.0-1116.127~16.04.1","4.15.0-1117.128~16.04.1","4.15.0-1118.129~16.04.1"],"ecosystem_specific":{"binaries":[{"binary_version":"4.15.0-1119.130~16.04.1","binary_name":"linux-buildinfo-4.15.0-1119-oracle"},{"binary_version":"4.15.0-1119.130~16.04.1","binary_name":"linux-headers-4.15.0-1119-oracle"},{"binary_version":"4.15.0-1119.130~16.04.1","binary_name":"linux-image-unsigned-4.15.0-1119-oracle"},{"binary_version":"4.15.0-1119.130~16.04.1","binary_name":"linux-modules-4.15.0-1119-oracle"},{"binary_version":"4.15.0-1119.130~16.04.1","binary_name":"linux-modules-extra-4.15.0-1119-oracle"},{"binary_version":"4.15.0-1119.130~16.04.1","binary_name":"linux-oracle-headers-4.15.0-1119"},{"binary_version":"4.15.0-1119.130~16.04.1","binary_name":"linux-oracle-tools-4.15.0-1119"},{"binary_version":"4.15.0-1119.130~16.04.1","binary_name":"linux-tools-4.15.0-1119-oracle"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6084-1.json","cves_map":{"ecosystem":"Ubuntu:Pro:16.04:LTS","cves":[{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2023-0459"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"negligible","type":"Ubuntu"}],"id":"CVE-2023-1118"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2023-1513"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2023-2162"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2023-32269"}]}}},{"package":{"name":"linux-gcp-4.15","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/linux-gcp-4.15@4.15.0-1150.166?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.15.0-1150.166"}]}],"versions":["4.15.0-1071.81","4.15.0-1077.87","4.15.0-1078.88","4.15.0-1080.90","4.15.0-1081.92","4.15.0-1083.94","4.15.0-1084.95","4.15.0-1086.98","4.15.0-1087.100","4.15.0-1088.101","4.15.0-1090.103","4.15.0-1091.104","4.15.0-1092.105","4.15.0-1093.106","4.15.0-1094.107","4.15.0-1095.108","4.15.0-1096.109","4.15.0-1097.110","4.15.0-1098.111","4.15.0-1099.112","4.15.0-1100.113","4.15.0-1103.116","4.15.0-1106.120","4.15.0-1107.121","4.15.0-1108.122","4.15.0-1109.123","4.15.0-1110.124","4.15.0-1111.125","4.15.0-1112.126","4.15.0-1114.128","4.15.0-1115.129","4.15.0-1116.130","4.15.0-1118.132","4.15.0-1119.133","4.15.0-1120.134","4.15.0-1121.135","4.15.0-1122.136","4.15.0-1124.138","4.15.0-1127.142","4.15.0-1130.146","4.15.0-1131.147","4.15.0-1134.150","4.15.0-1135.151","4.15.0-1136.152","4.15.0-1137.153","4.15.0-1138.154","4.15.0-1141.157","4.15.0-1142.158","4.15.0-1143.159","4.15.0-1145.161","4.15.0-1146.162","4.15.0-1147.163","4.15.0-1148.164","4.15.0-1149.165"],"ecosystem_specific":{"binaries":[{"binary_version":"4.15.0-1150.166","binary_name":"linux-buildinfo-4.15.0-1150-gcp"},{"binary_version":"4.15.0-1150.166","binary_name":"linux-gcp-4.15-headers-4.15.0-1150"},{"binary_version":"4.15.0-1150.166","binary_name":"linux-gcp-4.15-tools-4.15.0-1150"},{"binary_version":"4.15.0-1150.166","binary_name":"linux-headers-4.15.0-1150-gcp"},{"binary_version":"4.15.0-1150.166","binary_name":"linux-image-unsigned-4.15.0-1150-gcp"},{"binary_version":"4.15.0-1150.166","binary_name":"linux-modules-4.15.0-1150-gcp"},{"binary_version":"4.15.0-1150.166","binary_name":"linux-modules-extra-4.15.0-1150-gcp"},{"binary_version":"4.15.0-1150.166","binary_name":"linux-tools-4.15.0-1150-gcp"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6084-1.json","cves_map":{"ecosystem":"Ubuntu:18.04:LTS","cves":[{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2023-0459"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"negligible","type":"Ubuntu"}],"id":"CVE-2023-1118"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2023-1513"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2023-2162"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2023-32269"}]}}},{"package":{"name":"linux-oracle","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/linux-oracle@4.15.0-1119.130?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.15.0-1119.130"}]}],"versions":["4.15.0-1007.9","4.15.0-1008.10","4.15.0-1009.11","4.15.0-1010.12","4.15.0-1011.13","4.15.0-1013.15","4.15.0-1014.16","4.15.0-1015.17","4.15.0-1017.19","4.15.0-1018.20","4.15.0-1021.23","4.15.0-1022.25","4.15.0-1023.26","4.15.0-1025.28","4.15.0-1026.29","4.15.0-1027.30","4.15.0-1029.32","4.15.0-1030.33","4.15.0-1031.34","4.15.0-1033.36","4.15.0-1035.39","4.15.0-1037.41","4.15.0-1038.42","4.15.0-1039.43","4.15.0-1045.49","4.15.0-1047.51","4.15.0-1048.52","4.15.0-1050.54","4.15.0-1051.55","4.15.0-1053.57","4.15.0-1054.58","4.15.0-1057.62","4.15.0-1058.64","4.15.0-1059.65","4.15.0-1061.67","4.15.0-1062.68","4.15.0-1063.70","4.15.0-1064.71","4.15.0-1065.73","4.15.0-1066.74","4.15.0-1067.75","4.15.0-1068.76","4.15.0-1069.77","4.15.0-1070.78","4.15.0-1071.79","4.15.0-1072.80","4.15.0-1075.83","4.15.0-1078.86","4.15.0-1079.87","4.15.0-1080.88","4.15.0-1081.89","4.15.0-1082.90","4.15.0-1083.91","4.15.0-1084.92","4.15.0-1085.93","4.15.0-1086.94","4.15.0-1087.95","4.15.0-1089.98","4.15.0-1090.99","4.15.0-1091.100","4.15.0-1092.101","4.15.0-1093.102","4.15.0-1095.104","4.15.0-1098.108","4.15.0-1101.112","4.15.0-1102.113","4.15.0-1104.115","4.15.0-1105.116","4.15.0-1106.117","4.15.0-1107.118","4.15.0-1108.119","4.15.0-1111.122","4.15.0-1112.123","4.15.0-1113.124","4.15.0-1114.125","4.15.0-1115.126","4.15.0-1116.127","4.15.0-1117.128","4.15.0-1118.129"],"ecosystem_specific":{"binaries":[{"binary_version":"4.15.0-1119.130","binary_name":"linux-buildinfo-4.15.0-1119-oracle"},{"binary_version":"4.15.0-1119.130","binary_name":"linux-headers-4.15.0-1119-oracle"},{"binary_version":"4.15.0-1119.130","binary_name":"linux-image-unsigned-4.15.0-1119-oracle"},{"binary_version":"4.15.0-1119.130","binary_name":"linux-modules-4.15.0-1119-oracle"},{"binary_version":"4.15.0-1119.130","binary_name":"linux-modules-extra-4.15.0-1119-oracle"},{"binary_version":"4.15.0-1119.130","binary_name":"linux-oracle-headers-4.15.0-1119"},{"binary_version":"4.15.0-1119.130","binary_name":"linux-oracle-tools-4.15.0-1119"},{"binary_version":"4.15.0-1119.130","binary_name":"linux-tools-4.15.0-1119-oracle"}],"availability":"No subscription required"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6084-1.json","cves_map":{"ecosystem":"Ubuntu:18.04:LTS","cves":[{"severity":[{"score":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2023-0459"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"negligible","type":"Ubuntu"}],"id":"CVE-2023-1118"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N","type":"CVSS_V3"},{"score":"low","type":"Ubuntu"}],"id":"CVE-2023-1513"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2023-2162"},{"severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}],"id":"CVE-2023-32269"}]}}}],"schema_version":"1.7.5"}