2025年6月2日星期一

Ubuntu Linux Kernel Multiple Vulnerabilities

Ubuntu Linux Kernel Multiple Vulnerabilities

Release Date: 2 Jun 2025

RISK: High Risk

TYPE: Operating Systems - Linux

Multiple vulnerabilities were identified in Ubuntu Linux Kernel. An attacker could exploit some of these vulnerabilities to trigger security restriction bypass, denial of service condition, elevation of privilege, remote code execution, sensitive information disclosure and data manipulation on the targeted system.

 

Note:

CVE-2024-50302 is being exploited in the wild. This vulnerability allows an attacker to use a malicious input device to read information from the report buffer. This could be used to leak kernel memory, enabling the exploitation of additional vulnerabilities. Since the exploitation requires physical connection to malicious hardware, the risk level remains Medium.

 

CVE-2024-53150 is being exploited in the wild. This vulnerability allows an attacker to send incorrect information about its clock settings by using a fake USB audio device, which cause out-of-bounds reads.

 

CVE-2024-53197 is being exploited in the wild. This vulnerability allows an attacker to provide a misleading number by using a fake sound device, which cause out-of-bounds accesses.


Impact

  • Denial of Service
  • Elevation of Privilege
  • Remote Code Execution
  • Information Disclosure
  • Data Manipulation
  • Security Restriction Bypass

System / Technologies affected

  • Ubuntu 16.04 LTS
  • Ubuntu 18.04 LTS
  • Ubuntu 20.04 LTS
  • Ubuntu 22.04 LTS
  • Ubuntu 24.04 LTS

Solutions

Before installation of the software, please visit the vendor web-site for more details.

 

Apply fixes issued by the vendor:


Vulnerability Identifier


Source


Related Link

沒有留言:

發佈留言

Microsoft Edge 多個漏洞

Microsoft Edge 多個漏洞 發佈日期: 2025年08月08日 風險: 中度風險 類型: 用戶端 - 瀏覽器 於 Microsoft...