{"id":"USN-6765-1","summary":"linux-oem-6.5 vulnerabilities","details":"Alon Zahavi discovered that the NVMe-oF/TCP subsystem in the Linux kernel\ndid not properly validate H2C PDU data, leading to a null pointer\ndereference vulnerability. A remote attacker could use this to cause a\ndenial of service (system crash). (CVE-2023-6356, CVE-2023-6535,\nCVE-2023-6536)\n\nSander Wiebing, Alvise de Faveri Tron, Herbert Bos, and Cristiano Giuffrida\ndiscovered that the Linux kernel mitigations for the initial Branch History\nInjection vulnerability (CVE-2022-0001) were insufficient for Intel\nprocessors. A local attacker could potentially use this to expose sensitive\ninformation. (CVE-2024-2201)\n\nChenyuan Yang discovered that the RDS Protocol implementation in the Linux\nkernel contained an out-of-bounds read vulnerability. An attacker could use\nthis to possibly cause a denial of service (system crash). (CVE-2024-23849)\n\nIt was discovered that a race condition existed in the Bluetooth subsystem\nin the Linux kernel, leading to a null pointer dereference vulnerability. A\nprivileged local attacker could use this to possibly cause a denial of\nservice (system crash). (CVE-2024-24860)\n\nSeveral security issues were discovered in the Linux kernel.\nAn attacker could possibly use these to compromise the system.\nThis update corrects flaws in the following subsystems:\n  - ARM64 architecture;\n  - PowerPC architecture;\n  - S390 architecture;\n  - Core kernel;\n  - x86 architecture;\n  - Block layer subsystem;\n  - Cryptographic API;\n  - Android drivers;\n  - Drivers core;\n  - Power management core;\n  - Bus devices;\n  - Hardware random number generator core;\n  - Device frequency;\n  - DMA engine subsystem;\n  - EDAC drivers;\n  - ARM SCMI message protocol;\n  - GPU drivers;\n  - IIO ADC drivers;\n  - InfiniBand drivers;\n  - IOMMU subsystem;\n  - Media drivers;\n  - Multifunction device drivers;\n  - MTD block device drivers;\n  - Network drivers;\n  - NVME drivers;\n  - PCI driver for MicroSemi Switchtec;\n  - x86 platform drivers;\n  - Power supply drivers;\n  - SCSI drivers;\n  - QCOM SoC drivers;\n  - SPMI drivers;\n  - Thermal drivers;\n  - TTY drivers;\n  - VFIO drivers;\n  - BTRFS file system;\n  - Ceph distributed file system;\n  - EFI Variable file system;\n  - EROFS file system;\n  - Ext4 file system;\n  - F2FS file system;\n  - GFS2 file system;\n  - JFS file system;\n  - Network file systems library;\n  - Network file system server daemon;\n  - Pstore file system;\n  - ReiserFS file system;\n  - SMB network file system;\n  - BPF subsystem;\n  - Memory management;\n  - TLS protocol;\n  - Networking core;\n  - IPv4 networking;\n  - IPv6 networking;\n  - Logical Link layer;\n  - Netfilter;\n  - Network traffic control;\n  - SMC sockets;\n  - Sun RPC protocol;\n  - AppArmor security module;\n(CVE-2023-52635, CVE-2024-26632, CVE-2023-52468, CVE-2023-52472,\nCVE-2023-52589, CVE-2024-26671, CVE-2024-26640, CVE-2024-26631,\nCVE-2023-52489, CVE-2023-52616, CVE-2023-52445, CVE-2023-52463,\nCVE-2024-26610, CVE-2023-52497, CVE-2023-52453, CVE-2023-52470,\nCVE-2024-26649, CVE-2023-52583, CVE-2024-26644, CVE-2023-52607,\nCVE-2023-52587, CVE-2024-26594, CVE-2023-52618, CVE-2023-52495,\nCVE-2023-52632, CVE-2024-26583, CVE-2023-52633, CVE-2023-52591,\nCVE-2024-26633, CVE-2023-52627, CVE-2024-26670, CVE-2024-26598,\nCVE-2024-26592, CVE-2023-52473, CVE-2023-52623, CVE-2023-52446,\nCVE-2023-52443, CVE-2023-52451, CVE-2024-26629, CVE-2023-52462,\nCVE-2024-26808, CVE-2023-52598, CVE-2023-52611, CVE-2023-52492,\nCVE-2023-52456, CVE-2023-52626, CVE-2023-52455, CVE-2024-26641,\nCVE-2023-52588, CVE-2023-52608, CVE-2024-26618, CVE-2024-26582,\nCVE-2023-52609, CVE-2023-52604, CVE-2024-26646, CVE-2024-26634,\nCVE-2023-52469, CVE-2023-52467, CVE-2023-52447, CVE-2024-26623,\nCVE-2023-52621, CVE-2024-26647, CVE-2024-26615, CVE-2023-52450,\nCVE-2023-52619, CVE-2023-52610, CVE-2023-52606, CVE-2023-52464,\nCVE-2023-52465, CVE-2024-26638, CVE-2023-52498, CVE-2024-26625,\nCVE-2023-52449, CVE-2023-52584, CVE-2023-52454, CVE-2023-52458,\nCVE-2024-26585, CVE-2024-26669, CVE-2023-52493, CVE-2024-26645,\nCVE-2024-26607, CVE-2023-52615, CVE-2023-52617, CVE-2024-26612,\nCVE-2024-26668, CVE-2023-52594, CVE-2023-52612, CVE-2024-26584,\nCVE-2024-26586, CVE-2024-26616, CVE-2024-26673, CVE-2023-52448,\nCVE-2024-26620, CVE-2023-52614, CVE-2024-26636, CVE-2023-52602,\nCVE-2023-52452, CVE-2023-52601, CVE-2024-26635, CVE-2024-26627,\nCVE-2023-52488, CVE-2023-52487, CVE-2023-52597, CVE-2023-52494,\nCVE-2023-52444, CVE-2024-26608, CVE-2023-52593, CVE-2023-52491,\nCVE-2023-52595, CVE-2023-52599, CVE-2024-26595, CVE-2023-52622,\nCVE-2024-26650, CVE-2024-26614, CVE-2023-52490, CVE-2023-52486,\nCVE-2023-52457)\n","modified":"2026-02-04T04:30:27.794019Z","published":"2024-05-07T15:22:10.940719Z","withdrawn":"2024-05-07T16:22:10.940719Z","related":["CVE-2023-52443","CVE-2023-52444","CVE-2023-52445","CVE-2023-52446","CVE-2023-52447","CVE-2023-52448","CVE-2023-52449","CVE-2023-52450","CVE-2023-52451","CVE-2023-52452","CVE-2023-52453","CVE-2023-52454","CVE-2023-52455","CVE-2023-52456","CVE-2023-52457","CVE-2023-52458","CVE-2023-52462","CVE-2023-52463","CVE-2023-52464","CVE-2023-52465","CVE-2023-52467","CVE-2023-52468","CVE-2023-52469","CVE-2023-52470","CVE-2023-52472","CVE-2023-52473","CVE-2023-52486","CVE-2023-52487","CVE-2023-52488","CVE-2023-52489","CVE-2023-52490","CVE-2023-52491","CVE-2023-52492","CVE-2023-52493","CVE-2023-52494","CVE-2023-52495","CVE-2023-52497","CVE-2023-52498","CVE-2023-52583","CVE-2023-52584","CVE-2023-52587","CVE-2023-52588","CVE-2023-52589","CVE-2023-52591","CVE-2023-52593","CVE-2023-52594","CVE-2023-52595","CVE-2023-52597","CVE-2023-52598","CVE-2023-52599","CVE-2023-52601","CVE-2023-52602","CVE-2023-52604","CVE-2023-52606","CVE-2023-52607","CVE-2023-52608","CVE-2023-52609","CVE-2023-52610","CVE-2023-52611","CVE-2023-52612","CVE-2023-52614","CVE-2023-52615","CVE-2023-52616","CVE-2023-52617","CVE-2023-52618","CVE-2023-52619","CVE-2023-52621","CVE-2023-52622","CVE-2023-52623","CVE-2023-52626","CVE-2023-52627","CVE-2023-52632","CVE-2023-52633","CVE-2023-52635","CVE-2023-6356","CVE-2023-6535","CVE-2023-6536","CVE-2024-2201","CVE-2024-23849","CVE-2024-24860","CVE-2024-26582","CVE-2024-26583","CVE-2024-26584","CVE-2024-26585","CVE-2024-26586","CVE-2024-26592","CVE-2024-26594","CVE-2024-26595","CVE-2024-26598","CVE-2024-26607","CVE-2024-26608","CVE-2024-26610","CVE-2024-26612","CVE-2024-26614","CVE-2024-26615","CVE-2024-26616","CVE-2024-26618","CVE-2024-26620","CVE-2024-26623","CVE-2024-26625","CVE-2024-26627","CVE-2024-26629","CVE-2024-26631","CVE-2024-26632","CVE-2024-26633","CVE-2024-26634","CVE-2024-26635","CVE-2024-26636","CVE-2024-26638","CVE-2024-26640","CVE-2024-26641","CVE-2024-26644","CVE-2024-26645","CVE-2024-26646","CVE-2024-26647","CVE-2024-26649","CVE-2024-26650","CVE-2024-26668","CVE-2024-26669","CVE-2024-26670","CVE-2024-26671","CVE-2024-26673","CVE-2024-26808"],"references":[{"type":"ADVISORY","url":"https://ubuntu.com/security/notices/USN-6765-1"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52443"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52444"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52445"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52446"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52447"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52448"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52449"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52450"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52451"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52452"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52453"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52454"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52455"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52456"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52457"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52458"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52462"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52463"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52464"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52465"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52467"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52468"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52469"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52470"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52472"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52473"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52486"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52487"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52488"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52489"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52490"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52491"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52492"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52493"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52494"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52495"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52497"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52498"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52583"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52584"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52587"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52588"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52589"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52591"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52593"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52594"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52595"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52597"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52598"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52599"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52601"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52602"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52604"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52606"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52607"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52608"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52609"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52610"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52611"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52612"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52614"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52615"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52616"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52617"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52618"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52619"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52621"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52622"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52623"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52626"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52627"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52632"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52633"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-52635"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-6356"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-6535"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2023-6536"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-2201"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-23849"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-24860"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26582"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26583"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26584"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26585"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26586"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26592"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26594"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26595"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26598"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26607"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26608"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26610"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26612"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26614"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26615"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26616"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26618"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26620"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26623"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26625"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26627"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26629"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26631"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26632"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26633"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26634"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26635"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26636"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26638"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26640"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26641"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26644"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26645"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26646"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26647"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26649"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26650"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26668"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26669"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26670"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26671"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26673"},{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2024-26808"}],"affected":[{"package":{"name":"linux-oem-6.5","ecosystem":"Ubuntu:22.04:LTS","purl":"pkg:deb/ubuntu/linux-oem-6.5"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.5.0-1022.23"}]}],"ecosystem_specific":{"availability":"No subscription needed","binaries":[{"linux-modules-ipu6-oem-22.04b":"6.5.0.1022.24","linux-modules-usbio-oem-22.04":"6.5.0.1022.24","linux-image-oem-22.04a":"6.5.0.1022.24","linux-modules-iwlwifi-oem-22.04d":"6.5.0.1022.24","linux-oem-22.04d":"6.5.0.1022.24","linux-oem-6.5-headers-6.5.0-1022":"6.5.0-1022.23","linux-oem-6.5-lib-rust-6.5.0-1022-oem":"6.5.0-1022.23","linux-tools-6.5.0-1022-oem":"6.5.0-1022.23","linux-tools-oem-22.04c":"6.5.0.1022.24","linux-buildinfo-6.5.0-1022-oem":"6.5.0-1022.23","linux-modules-ipu6-oem-22.04":"6.5.0.1022.24","linux-modules-ivsc-oem-22.04b":"6.5.0.1022.24","linux-modules-ivsc-oem-22.04d":"6.5.0.1022.24","linux-modules-iwlwifi-oem-22.04b":"6.5.0.1022.24","linux-oem-22.04b":"6.5.0.1022.24","linux-oem-22.04":"6.5.0.1022.24","linux-oem-6.5-tools-6.5.0-1022":"6.5.0-1022.23","linux-image-uc-6.5.0-1022-oem":"6.5.0-1022.23","linux-modules-ivsc-6.5.0-1022-oem":"6.5.0-1022.23","linux-modules-iwlwifi-oem-22.04":"6.5.0.1022.24","linux-oem-22.04c":"6.5.0.1022.24","linux-oem-6.5-tools-host":"6.5.0-1022.23","linux-tools-oem-22.04":"6.5.0.1022.24","linux-modules-ivsc-oem-22.04":"6.5.0.1022.24","linux-headers-oem-22.04b":"6.5.0.1022.24","linux-modules-ipu6-6.5.0-1022-oem":"6.5.0-1022.23","linux-modules-usbio-6.5.0-1022-oem":"6.5.0-1022.23","linux-oem-22.04a":"6.5.0.1022.24","linux-headers-oem-22.04a":"6.5.0.1022.24","linux-headers-oem-22.04d":"6.5.0.1022.24","linux-image-6.5.0-1022-oem":"6.5.0-1022.23","linux-image-oem-22.04d":"6.5.0.1022.24","linux-modules-6.5.0-1022-oem":"6.5.0-1022.23","linux-modules-ipu6-oem-22.04c":"6.5.0.1022.24","linux-modules-ivsc-oem-22.04c":"6.5.0.1022.24","linux-modules-iwlwifi-6.5.0-1022-oem":"6.5.0-1022.23","linux-headers-6.5.0-1022-oem":"6.5.0-1022.23","linux-image-oem-22.04c":"6.5.0.1022.24","linux-modules-iwlwifi-oem-22.04c":"6.5.0.1022.24","linux-tools-oem-22.04a":"6.5.0.1022.24","linux-tools-oem-22.04b":"6.5.0.1022.24","linux-headers-oem-22.04c":"6.5.0.1022.24","linux-headers-oem-22.04":"6.5.0.1022.24","linux-modules-usbio-oem-22.04d":"6.5.0.1022.24","linux-tools-oem-22.04d":"6.5.0.1022.24","linux-modules-ipu6-oem-22.04d":"6.5.0.1022.24","linux-image-oem-22.04b":"6.5.0.1022.24","linux-image-oem-22.04":"6.5.0.1022.24","linux-image-uc-oem-22.04d":"6.5.0.1022.24","linux-image-uc-oem-22.04":"6.5.0.1022.24","linux-image-unsigned-6.5.0-1022-oem":"6.5.0-1022.23"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/usn/USN-6765-1.json"}}],"schema_version":"1.7.3"}