LSN-0122-1: Kernel Live Patch Security Notice
Ubuntu live patch LSN-0122-1 fixes Linux kernel use-after-free and NULL-dereference bugs in DLM, brcmfmac, and padata.
Ubuntu published kernel live patch notice LSN-0122-1 covering several resolved Linux kernel bugs. Fixes include a use-after-free in the DLM midcomms commit path reported by KASAN, a NULL pointer dereference in brcmfmac's brcmf_sdiod_sglist_rw() when sd_sgentry_align is high and many SKBs are queued, and a use-after-free in padata_reorder. The notice does not list CVE identifiers or report active exploitation.
- Live patch LSN-0122-1 covers multiple Linux kernel fixes.
- DLM midcomms path had a KASAN-reported use-after-free.
- brcmfmac can oops via NULL dereference with high alignment.
- padata_reorder use-after-free is also patched.
- Notice lists no CVE IDs and no active exploitation.
In the Linux kernel, the following vulnerability has been resolved: fs: dlm: fix use after free in midcomms commit While working on processing dlm message in softirq context I experienced the following KASAN use-after-free warning: . In the Linux kernel, the following vulnerability has been resolved: wifi: brcmfmac: Fix oops due to NULL pointer dereference in brcmf_sdiod_sglist_rw() This patch fixes a NULL pointer dereference bug in brcmfmac that occurs when a high 'sd_sgentry_align' value applies (e.g. 512) and a lot of queued SKBs are sent from the pkt queue. In the Linux kernel, the following vulnerability has been resolved: padata: fix UAF in padata_reorder A bug was found when run…
This source does not provide full text. Read it at ubuntu.com.