{"id":"USN-6441-2","summary":"linux-gcp-5.4 vulnerabilities","details":"Ross Lagerwall discovered that the Xen netback backend driver in the Linux\nkernel did not properly handle certain unusual packets from a\nparavirtualized network frontend, leading to a buffer overflow. An attacker\nin a guest VM could use this to cause a denial of service (host system\ncrash) or possibly execute arbitrary code. (CVE-2023-34319)\n\nKyle Zeng discovered that the networking stack implementation in the Linux\nkernel did not properly validate skb object size in certain conditions. An\nattacker could use this cause a denial of service (system crash) or\npossibly execute arbitrary code. (CVE-2023-42752)\n\nKyle Zeng discovered that the netfiler subsystem in the Linux kernel did\nnot properly calculate array offsets, leading to a out-of-bounds write\nvulnerability. A local user could use this to cause a denial of service\n(system crash) or possibly execute arbitrary code. (CVE-2023-42753)\n\nKyle Zeng discovered that the IPv4 Resource Reservation Protocol (RSVP)\nclassifier implementation in the Linux kernel contained an out-of-bounds\nread vulnerability. A local attacker could use this to cause a denial of\nservice (system crash). Please note that kernel packet classifier support\nfor RSVP has been removed to resolve this vulnerability. (CVE-2023-42755)\n\nKyle Zeng discovered that the netfilter subsystem in the Linux kernel\ncontained a race condition in IP set operations in certain situations. A\nlocal attacker could use this to cause a denial of service (system crash).\n(CVE-2023-42756)\n\nBing-Jhong Billy Jheng discovered that the Unix domain socket\nimplementation in the Linux kernel contained a race condition in certain\nsituations, leading to a use-after-free vulnerability. A local attacker\ncould use this to cause a denial of service (system crash) or possibly\nexecute arbitrary code. (CVE-2023-4622)\n\nBudimir Markovic discovered that the qdisc implementation in the Linux\nkernel did not properly validate inner classes, leading to a use-after-free\nvulnerability. A local user could use this to cause a denial of service\n(system crash) or possibly execute arbitrary code. (CVE-2023-4623)\n\nAlex Birnberg discovered that the netfilter subsystem in the Linux kernel\ndid not properly validate register length, leading to an out-of- bounds\nwrite vulnerability. A local attacker could possibly use this to cause a\ndenial of service (system crash). (CVE-2023-4881)\n\nIt was discovered that the Quick Fair Queueing scheduler implementation in\nthe Linux kernel did not properly handle network packets in certain\nconditions, leading to a use after free vulnerability. A local attacker\ncould use this to cause a denial of service (system crash) or possibly\nexecute arbitrary code. (CVE-2023-4921)\n","modified":"2026-02-10T04:43:23Z","published":"2023-10-23T18:07:08Z","related":["UBUNTU-CVE-2023-34319","UBUNTU-CVE-2023-42752","UBUNTU-CVE-2023-42753","UBUNTU-CVE-2023-42755","UBUNTU-CVE-2023-42756","UBUNTU-CVE-2023-4622","UBUNTU-CVE-2023-4623","UBUNTU-CVE-2023-4881","UBUNTU-CVE-2023-4921"],"upstream":["CVE-2023-34319","CVE-2023-42752","CVE-2023-42753","CVE-2023-42755","CVE-2023-42756","CVE-2023-4622","CVE-2023-4623","CVE-2023-4881","CVE-2023-4921","UBUNTU-CVE-2023-34319","UBUNTU-CVE-2023-42752","UBUNTU-CVE-2023-42753","UBUNTU-CVE-2023-42755","UBUNTU-CVE-2023-42756","UBUNTU-CVE-2023-4622","UBUNTU-CVE-2023-4623","UBUNTU-CVE-2023-4881","UBUNTU-CVE-2023-4921"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6441-2"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-4622"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-4623"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-4881"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-4921"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-34319"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-42752"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-42753"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-42755"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-42756"}],"affected":[{"package":{"name":"linux-gcp-5.4","ecosystem":"Ubuntu:Pro:18.04:LTS","purl":"pkg:deb/ubuntu/linux-gcp-5.4@5.4.0-1116.125~18.04.1?arch=source&distro=esm-infra/bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.4.0-1116.125~18.04.1"}]}],"versions":["5.4.0-1019.19~18.04.2","5.4.0-1021.21~18.04.1","5.4.0-1022.22~18.04.1","5.4.0-1024.24~18.04.1","5.4.0-1025.25~18.04.1","5.4.0-1028.29~18.04.1","5.4.0-1029.31~18.04.1","5.4.0-1030.32~18.04.1","5.4.0-1032.34~18.04.1","5.4.0-1033.35~18.04.1","5.4.0-1034.37~18.04.1","5.4.0-1036.39~18.04.1","5.4.0-1037.40~18.04.1","5.4.0-1038.41~18.04.1","5.4.0-1040.43~18.04.1","5.4.0-1041.44~18.04.1","5.4.0-1042.45~18.04.1","5.4.0-1043.46~18.04.1","5.4.0-1044.47~18.04.2","5.4.0-1046.49~18.04.1","5.4.0-1049.53~18.04.1","5.4.0-1051.55~18.04.1","5.4.0-1052.56~18.04.1","5.4.0-1053.57~18.04.1","5.4.0-1055.59~18.04.1","5.4.0-1056.60~18.04.1","5.4.0-1057.61~18.04.1","5.4.0-1058.62~18.04.1","5.4.0-1059.63~18.04.1","5.4.0-1060.64~18.04.1","5.4.0-1062.66~18.04.1","5.4.0-1063.67~18.04.1","5.4.0-1064.68~18.04.1","5.4.0-1065.69~18.04.1","5.4.0-1067.71~18.04.1","5.4.0-1068.72~18.04.1","5.4.0-1069.73~18.04.1","5.4.0-1072.77~18.04.1","5.4.0-1073.78~18.04.1","5.4.0-1075.80~18.04.1","5.4.0-1078.84~18.04.1","5.4.0-1080.87~18.04.1","5.4.0-1083.91~18.04.1","5.4.0-1084.92~18.04.1","5.4.0-1086.94~18.04.1","5.4.0-1087.95~18.04.1","5.4.0-1089.97~18.04.1","5.4.0-1092.101~18.04.1","5.4.0-1093.102~18.04.1","5.4.0-1096.105~18.04.2","5.4.0-1097.106~18.04.1","5.4.0-1098.107~18.04.1","5.4.0-1100.109~18.04.1","5.4.0-1101.110~18.04.1","5.4.0-1102.111~18.04.2","5.4.0-1103.112~18.04.1","5.4.0-1104.113~18.04.1","5.4.0-1105.114~18.04.1","5.4.0-1106.115~18.04.1","5.4.0-1107.116~18.04.1","5.4.0-1108.117~18.04.1","5.4.0-1109.118~18.04.1","5.4.0-1110.119~18.04.1","5.4.0-1111.120~18.04.1","5.4.0-1112.121~18.04.1","5.4.0-1113.122~18.04.1","5.4.0-1115.124~18.04.1"],"ecosystem_specific":{"binaries":[{"binary_version":"5.4.0-1116.125~18.04.1","binary_name":"linux-buildinfo-5.4.0-1116-gcp"},{"binary_version":"5.4.0-1116.125~18.04.1","binary_name":"linux-gcp-5.4-headers-5.4.0-1116"},{"binary_version":"5.4.0-1116.125~18.04.1","binary_name":"linux-gcp-5.4-tools-5.4.0-1116"},{"binary_version":"5.4.0-1116.125~18.04.1","binary_name":"linux-headers-5.4.0-1116-gcp"},{"binary_version":"5.4.0-1116.125~18.04.1","binary_name":"linux-image-unsigned-5.4.0-1116-gcp"},{"binary_version":"5.4.0-1116.125~18.04.1","binary_name":"linux-modules-5.4.0-1116-gcp"},{"binary_version":"5.4.0-1116.125~18.04.1","binary_name":"linux-modules-extra-5.4.0-1116-gcp"},{"binary_version":"5.4.0-1116.125~18.04.1","binary_name":"linux-tools-5.4.0-1116-gcp"}],"availability":"Available with Ubuntu Pro (Infra-only): https://ubuntu.com/pro"},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6441-2.json","cves_map":{"cves":[{"id":"CVE-2023-4622","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]},{"id":"CVE-2023-4623","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]},{"id":"CVE-2023-4881","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]},{"id":"CVE-2023-4921","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]},{"id":"CVE-2023-34319","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"medium","type":"Ubuntu"}]},{"id":"CVE-2023-42752","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]},{"id":"CVE-2023-42753","severity":[{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]},{"id":"CVE-2023-42755","severity":[{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]},{"id":"CVE-2023-42756","severity":[{"score":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H","type":"CVSS_V3"},{"score":"high","type":"Ubuntu"}]}],"ecosystem":"Ubuntu:Pro:18.04:LTS"}}}],"schema_version":"1.7.3"}