[Ksplice][Ubuntu-19.04-Updates] New Ksplice updates for Ubuntu 19.04 Disco (USN-4209-1)
Jamie Iles
jamie.iles at oracle.com
Mon Dec 23 03:38:46 PST 2019
Synopsis: USN-4209-1 can now be patched using Ksplice
CVEs: CVE-2019-15794 CVE-2019-16746 CVE-2019-19076 CVE-2019-19081 CVE-2019-19523 CVE-2019-19525 CVE-2019-19528
Systems running Ubuntu 19.04 Disco can now use Ksplice to patch
against the latest Ubuntu Security Notice, USN-4209-1.
INSTALLING THE UPDATES
We recommend that all users of Ksplice Uptrack running Ubuntu 19.04
Disco install these updates.
On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.
Alternatively, you can install these updates by running:
# /usr/sbin/uptrack-upgrade -y
DESCRIPTION
* CVE-2019-19525: Denial-of-service during ATUSB device disconnect.
The ATUSB driver attempts to access a previously freed structure in its
device disconnect path. The flaw could potentially be exploited using
a specially crafted USB device to cause a system to exhibit unexpected
behavior, including a potential denial-of-service.
* NULL pointer dereference when encoding NFS attributes.
A missing check when encoding NFS attributes could lead to a NULL
pointer dereference. A local attacker could use this flaw to cause a
denial-of-service.
* Memory leak in Character Device in Userspace init path.
If certain operations fail when attempting to initialize a CUSE device
small amounts of memory will be leaked. This flaw could be exploited
by a local attacker to waste system resources and degrade performance.
* CVE-2019-19081: Memory leak when initializing virtual NIC in NFP4000/NFP6000 TC Flower offload driver.
A missing check when initializing virtual NIC in NFP4000/NFP6000 TC
Flower offload driver fails could lead to a memory leak. A local
attacker could use this flaw to exhaust kernel memory and cause a
denial-of-service.
* CVE-2019-16746: Buffer overflow when receiving beacon over wireless network.
A missing check a beacon header received over wireless network could
lead to a buffer overflow. A remote attacker could use this flaw to
cause a denial-of-service.
* Race condition when failing to initialize xHCI device causes deadlock.
If any xHCI USB device fails during its initialization process, a race
condition could result in a circular lock dependency on the bandwidth
mutex, resulting in a deadlock. A malicious device might exploit this
flaw to create a denial-of-service.
* CVE-2019-19523: Denial-of-service when disconnecting Ontrak ADU device.
When disconnecting an Ontrak Control Systems ADU family USB relay
device, a race condition between the device disconnection and release
callback could result in a use-after-free, potentially causing memory
corruption or a denial-of-service.
* CVE-2019-19528: Denial-of-service when disconnecting IO Warrior USB device.
Logic errors when disconnecting IO Warrior USB device could lead to a
use-after-free. A local attacker could use this flaw to cause a
denial-of-service.
* NULL pointer dereference when using USB Keyspan USA-xxx Serial driver.
A missing check on endpoints when using USB Keyspan USA-xxx Serial
driver could lead to a NULL pointer dereference. A local attacker could
use a malicious USB device to cause a denial-of-service.
* Information leak when registering Microtek X6USB scanner driver.
A missing check when registering Microtek X6USB scanner driver could
lead to an information leak. A local attacker could use this flaw to
leak information about running kernel and facilitate an attack.
* Information leak when registering USB Lego Infrared Tower driver.
A missing check when registering USB Lego Infrared Tower driver could
lead to an information leak. A local attacker could use this flaw to
leak information about running kernel and facilitate an attack.
* Memory leak when registering VIA Technologies VT6655 driver fails.
A missing free of resources when registering VIA Technologies VT6655
driver fails could lead to a memory leak. A local attacker could use this flaw
to exhaust kernel memory and cause a denial-of-service.
* CVE-2019-19076: Memory leak when setting up traffic control in NFP4000/NFP6000 TC Flower offload driver.
Missing checks when setting up traffic control in NFP4000/NFP6000 TC
Flower offload driver fails could lead to a memory leak. A local
attacker could use this flaw to exhaust kernel memory and cause a
denial-of-service.
* Denial-of-service in EROFS directory reading.
An infinite look in the error handling for directory reading of an EROFS
filesystem could lead to a kernel hang. A maliciously crafted
filesystem could be used to hang the kernel.
* CVE-2019-15794: Denial-of-service in overlayfs and shiftfs mmap().
Incorrect error handling for mmap() on an overlayfs or shiftfs
filesystem could result in a use-after-free and kernel crash.
SUPPORT
Ksplice support is available at ksplice-support_ww at oracle.com.
More information about the Ksplice-Ubuntu-19.04-updates
mailing list