{"id":"USN-6439-2","summary":"linux-aws vulnerabilities","details":"It was discovered that the IPv6 implementation in the Linux kernel\ncontained a high rate of hash collisions in connection lookup table. A\nremote attacker could use this to cause a denial of service (excessive CPU\nconsumption). (CVE-2023-1206)\n\nYu Hao and Weiteng Chen discovered that the Bluetooth HCI UART driver in\nthe Linux kernel contained a race condition, leading to a null pointer\ndereference vulnerability. A local attacker could use this to cause a\ndenial of service (system crash). (CVE-2023-31083)\n\nRoss Lagerwall discovered that the Xen netback backend driver in the Linux\nkernel did not properly handle certain unusual packets from a\nparavirtualized network frontend, leading to a buffer overflow. An attacker\nin a guest VM could use this to cause a denial of service (host system\ncrash) or possibly execute arbitrary code. (CVE-2023-34319)\n\nLin Ma discovered that the Netlink Transformation (XFRM) subsystem in the\nLinux kernel contained a null pointer dereference vulnerability in some\nsituations. A local privileged attacker could use this to cause a denial of\nservice (system crash). (CVE-2023-3772)\n\nKyle Zeng discovered that the networking stack implementation in the Linux\nkernel did not properly validate skb object size in certain conditions. An\nattacker could use this cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2023-42752)\n\nKyle Zeng discovered that the netfiler subsystem in the Linux kernel did\nnot properly calculate array offsets, leading to a out-of-bounds write\nvulnerability. A local user could use this to cause a denial of service\n(system crash) or possibly execute arbitrary code. (CVE-2023-42753)\n\nKyle Zeng discovered that the IPv4 Resource Reservation Protocol (RSVP)\nclassifier implementation in the Linux kernel contained an out-of-bounds\nread vulnerability. A local attacker could use this to cause a denial of\nservice (system crash). Please note that kernel packet classifier support\nfor RSVP has been removed to resolve this vulnerability. (CVE-2023-42755)\n\nBing-Jhong Billy Jheng discovered that the Unix domain socket\nimplementation in the Linux kernel contained a race condition in certain\nsituations, leading to a use-after-free vulnerability. A local attacker\ncould use this to cause a denial of service (system crash) or possibly\nexecute arbitrary code. (CVE-2023-4622)\n\nBudimir Markovic discovered that the qdisc implementation in the Linux\nkernel did not properly validate inner classes, leading to a use-after-free\nvulnerability. A local user could use this to cause a denial of service\n(system crash) or possibly execute arbitrary code. (CVE-2023-4623)\n\nAlex Birnberg discovered that the netfilter subsystem in the Linux kernel\ndid not properly validate register length, leading to an out-of- bounds\nwrite vulnerability. A local attacker could possibly use this to cause a\ndenial of service (system crash). (CVE-2023-4881)\n\nIt was discovered that the Quick Fair Queueing scheduler implementation in\nthe Linux kernel did not properly handle network packets in certain\nconditions, leading to a use after free vulnerability. A local attacker\ncould use this to cause a denial of service (system crash) or possibly\nexecute arbitrary code. (CVE-2023-4921)\n","modified":"2026-02-10T04:43:23Z","published":"2023-10-23T17:41:07Z","related":["UBUNTU-CVE-2023-1206","UBUNTU-CVE-2023-31083","UBUNTU-CVE-2023-34319","UBUNTU-CVE-2023-3772","UBUNTU-CVE-2023-42752","UBUNTU-CVE-2023-42753","UBUNTU-CVE-2023-42755","UBUNTU-CVE-2023-4622","UBUNTU-CVE-2023-4623","UBUNTU-CVE-2023-4881","UBUNTU-CVE-2023-4921"],"upstream":["CVE-2023-1206","CVE-2023-31083","CVE-2023-34319","CVE-2023-3772","CVE-2023-42752","CVE-2023-42753","CVE-2023-42755","CVE-2023-4622","CVE-2023-4623","CVE-2023-4881","CVE-2023-4921","UBUNTU-CVE-2023-1206","UBUNTU-CVE-2023-31083","UBUNTU-CVE-2023-34319","UBUNTU-CVE-2023-3772","UBUNTU-CVE-2023-42752","UBUNTU-CVE-2023-42753","UBUNTU-CVE-2023-42755","UBUNTU-CVE-2023-4622","UBUNTU-CVE-2023-4623","UBUNTU-CVE-2023-4881","UBUNTU-CVE-2023-4921"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6439-2"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-1206"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-3772"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-4622"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-4623"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-4881"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-4921"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-31083"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-34319"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-42752"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-42753"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-42755"}],"affected":[{"package":{"name":"linux-aws","ecosystem":"Ubuntu:Pro:14.04:LTS","purl":"pkg:deb/ubuntu/linux-aws@4.4.0-1124.130?arch=source&distro=trusty/esm"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.4.0-1124.130"}]}],"versions":["4.4.0-1002.2","4.4.0-1003.3","4.4.0-1005.5","4.4.0-1006.6","4.4.0-1009.9","4.4.0-1010.10","4.4.0-1011.11","4.4.0-1012.12","4.4.0-1014.14","4.4.0-1016.16","4.4.0-1017.17","4.4.0-1019.19","4.4.0-1022.22","4.4.0-1023.23","4.4.0-1024.25","4.4.0-1025.26","4.4.0-1027.30","4.4.0-1028.31","4.4.0-1029.32","4.4.0-1031.34","4.4.0-1032.35","4.4.0-1034.37","4.4.0-1036.39","4.4.0-1037.40","4.4.0-1038.41","4.4.0-1039.42","4.4.0-1040.43","4.4.0-1042.45","4.4.0-1044.47","4.4.0-1045.48","4.4.0-1046.50","4.4.0-1048.52","4.4.0-1050.54","4.4.0-1052.56","4.4.0-1054.58","4.4.0-1055.59","4.4.0-1056.60","4.4.0-1058.62","4.4.0-1059.63","4.4.0-1060.64","4.4.0-1061.65","4.4.0-1062.66","4.4.0-1064.68","4.4.0-1065.69","4.4.0-1066.70","4.4.0-1067.71","4.4.0-1073.77","4.4.0-1074.78","4.4.0-1075.79","4.4.0-1076.80","4.4.0-1077.81","4.4.0-1078.82","4.4.0-1081.85","4.4.0-1082.86","4.4.0-1083.87","4.4.0-1085.89","4.4.0-1086.90","4.4.0-1087.91","4.4.0-1088.92","4.4.0-1090.94","4.4.0-1091.95","4.4.0-1092.96","4.4.0-1093.97","4.4.0-1094.99","4.4.0-1095.100","4.4.0-1096.101","4.4.0-1097.102","4.4.0-1098.103","4.4.0-1099.104","4.4.0-1101.106","4.4.0-1102.107","4.4.0-1103.108","4.4.0-1104.109","4.4.0-1107.113","4.4.0-1109.115","4.4.0-1110.116","4.4.0-1111.117","4.4.0-1112.118","4.4.0-1113.119","4.4.0-1114.120","4.4.0-1115.121","4.4.0-1116.122","4.4.0-1117.123","4.4.0-1118.124","4.4.0-1119.125","4.4.0-1120.126","4.4.0-1121.127","4.4.0-1122.128","4.4.0-1123.129"],"ecosystem_specific":{"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro","binaries":[{"binary_name":"linux-aws-cloud-tools-4.4.0-1124","binary_version":"4.4.0-1124.130"},{"binary_name":"linux-aws-headers-4.4.0-1124","binary_version":"4.4.0-1124.130"},{"binary_name":"linux-aws-tools-4.4.0-1124","binary_version":"4.4.0-1124.130"},{"binary_name":"linux-buildinfo-4.4.0-1124-aws","binary_version":"4.4.0-1124.130"},{"binary_name":"linux-cloud-tools-4.4.0-1124-aws","binary_version":"4.4.0-1124.130"},{"binary_name":"linux-headers-4.4.0-1124-aws","binary_version":"4.4.0-1124.130"},{"binary_name":"linux-image-4.4.0-1124-aws","binary_version":"4.4.0-1124.130"},{"binary_name":"linux-modules-4.4.0-1124-aws","binary_version":"4.4.0-1124.130"},{"binary_name":"linux-tools-4.4.0-1124-aws","binary_version":"4.4.0-1124.130"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6439-2.json","cves_map":{"ecosystem":"Ubuntu:Pro:14.04:LTS","cves":[{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2023-1206"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2023-3772"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"high"}],"id":"CVE-2023-4622"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"high"}],"id":"CVE-2023-4623"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H"},{"type":"Ubuntu","score":"high"}],"id":"CVE-2023-4881"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"high"}],"id":"CVE-2023-4921"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"low"}],"id":"CVE-2023-31083"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"medium"}],"id":"CVE-2023-34319"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"high"}],"id":"CVE-2023-42752"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"},{"type":"Ubuntu","score":"high"}],"id":"CVE-2023-42753"},{"severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H"},{"type":"CVSS_V3","score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"high"}],"id":"CVE-2023-42755"}]}}}],"schema_version":"1.7.3"}