[Ksplice][Ubuntu-22.04-Updates] New Ksplice updates for Ubuntu 22.04 Jammy (USN-7455-1)
Oracle Ksplice
gregory.herrero at oracle.com
Mon May 19 07:53:47 UTC 2025
Synopsis: USN-7455-1 can now be patched using Ksplice
CVEs: CVE-2022-0995 CVE-2024-46826 CVE-2024-50256 CVE-2025-21700 CVE-2025-21701 CVE-2025-21702 CVE-2025-21703 CVE-2025-21756
Systems running Ubuntu 22.04 Jammy can now use Ksplice to patch
against the latest Ubuntu Security Notice, USN-7455-1.
INSTALLING THE UPDATES
We recommend that all users of Ksplice Uptrack running Ubuntu 22.04
Jammy install these updates.
On systems that have "autoinstall = yes" in /etc/uptrack/uptrack.conf,
these updates will be installed automatically and you do not need to
take any action.
Alternatively, you can install these updates by running:
# /usr/sbin/uptrack-upgrade -y
DESCRIPTION
* CVE-2022-0995: Privilege escalation in General notification queue driver.
A logic error when using the General notification queue driver could
lead to an out-of-bounds memory access. A local attacker could use this
flaw to escalate privileges.
* CVE-2024-46826: Undefined behavior in kernel ELF parsing subsystem.
A logic error when using the kernel ELF parsing subsystem. could lead to
an inconsistently loaded binary. The resulting loaded binary might exhibit
undefined behavior.
* CVE-2024-50256: Denial-of-service in IPv6 packet rejection driver.
A logic error when using the IPv6 packet rejection driver could lead to
a kernel assertion failure. A local attacker could use this flaw to
cause a denial-of-service.
* CVE-2025-21700: Privilege escalation in QoS and/or fair queueing driver.
A logic error when using the QoS and/or fair queueing driver could lead
to a use-after-free. A local attacker could use this flaw to gain root
privileges.
* CVE-2025-21701: Denial-of-service in Networking driver.
A race condition when using the Networking driver could lead to a kernel
assertion failure. A local attacker could use this flaw to cause a
denial-of-service.
* CVE-2025-21702: Privilege escalation in network QoS/scheduling driver.
A missing check when using the network QoS/scheduling driver could lead
to a use-after-free. A local attacker could use this flaw to escalate
privileges.
* CVE-2025-21703: Privilege escalation in network emulator.
A logic error when using the network emulator could lead to a
use-after-free. A local attacker could use this flaw to escalate
privileges.
* CVE-2025-21756: Privilege escalation in Virtual Socket protocol driver.
A logic error when using the Virtual Socket protocol driver could lead
to a use-after-free. A local attacker could use this flaw to escalate
privileges.
SUPPORT
Ksplice support is available at ksplice-support_ww at oracle.com.
More information about the Ksplice-Ubuntu-22.04-updates
mailing list