🛡️ LSN-0113-1 — linux

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Kernel Live Patch Security Notice

In the Linux kernel, the following vulnerability has been

resolved: smb: client: fix UAF in async decryption Doing an async

decryption (large read) crashes with a slab-use-after-free way down in the

crypto API.

In the Linux kernel, the following vulnerability has been

resolved: ubifs: authentication: Fix use-after-free in ubifs_tnc_end_commit

After an insertion in TNC, the tree might split and cause a node to change

its znode->parent.

In the Linux kernel, the following vulnerability has been

resolved: drm/amdgpu: fix usage slab after free

In the Linux kernel, the following vulnerability has been

resolved: jfs: fix array-index-out-of-bounds in jfs_readdir The stbl might

contain some invalid values.

In the Linux kernel, the following vulnerability has been

resolved: drm/amd/display: Fix out-of-bounds access in

'dcn21_link_encoder_create' An issue was identified in the

dcn21_link_encoder_create function where an out-of-bounds access could

occur when the hpd_source index was used to reference the link_enc_hpd_regs

array.

In the Linux kernel, the following vulnerability has been

resolved: jffs2: Prevent rtime decompress memory corruption The rtime

decompression routine does not fully check bounds during the entirety of

the decompression pass and can corrupt memory outside the decompression

buffer if the compressed data is corrupted.

Affected software

LSN-0113-1 is recorded against 21 packages.

  • linux (fixed in 6.8.0-58.60)
  • linux-aws (fixed in 6.8.0-1027.29)
  • linux-aws-5.15 (fixed in 5.15.0-1087.94~20.04.1)
  • linux-aws-hwe (fixed in 4.15.0-1181.194~16.04.1)
  • linux-azure (fixed in 6.8.0-1027.32)
  • linux-azure-4.15 (fixed in 4.15.0-1189.204)
  • linux-azure-5.15 (fixed in 5.15.0-1094.103~20.04.1)
  • linux-gcp (fixed in 6.8.0-1028.30)
  • linux-gcp-4.15 (fixed in 4.15.0-1174.191)
  • linux-gcp-5.15 (fixed in 5.15.0-1086.95~20.04.1)
  • linux-gke (fixed in 5.15.0-1084.90)
  • linux-gkeop
  • linux-hwe (fixed in 4.15.0-238.250~16.04.1)
  • linux-hwe-5.15 (fixed in 5.15.0-143.153~20.04.1)
  • linux-hwe-5.4 (fixed in 5.4.0-219.239~18.04.1)
  • linux-ibm (fixed in 6.8.0-1024.24)
  • linux-ibm-5.15 (fixed in 5.15.0-1079.82~20.04.1)
  • linux-lowlatency-hwe-5.15 (fixed in 5.15.0-143.153~20.04.1)
  • linux-lts-xenial (fixed in 4.4.0-269.303~14.04.1)
  • linux-oracle (fixed in 6.8.0-1024.25)
  • linux-oracle-5.15 (fixed in 5.15.0-1084.90~20.04.1)

Timeline and source

Published on 10 July 2025 and last revised on 3 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

ubuntu.com (Advisory)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-07-10
Updated 2026-08-12
Modified 2026-06-03
Fix URL N/A

Affected Packages

Software From version Fixed in
linux 6.8.0-58.60
linux-aws 6.8.0-1027.29
linux-aws-5.15 5.15.0-1087.94~20.04.1
linux-aws-hwe 4.15.0-1181.194~16.04.1
linux-azure 6.8.0-1027.32
linux-azure-4.15 4.15.0-1189.204
linux-azure-5.15 5.15.0-1094.103~20.04.1
linux-gcp 6.8.0-1028.30
linux-gcp-4.15 4.15.0-1174.191
linux-gcp-5.15 5.15.0-1086.95~20.04.1
linux-gke 5.15.0-1084.90
linux-gkeop
linux-hwe 4.15.0-238.250~16.04.1
linux-hwe-5.15 5.15.0-143.153~20.04.1
linux-hwe-5.4 5.4.0-219.239~18.04.1
linux-ibm 6.8.0-1024.24
linux-ibm-5.15 5.15.0-1079.82~20.04.1
linux-lowlatency-hwe-5.15 5.15.0-143.153~20.04.1
linux-lts-xenial 4.4.0-269.303~14.04.1
linux-oracle 6.8.0-1024.25
linux-oracle-5.15 5.15.0-1084.90~20.04.1

Similar Threats

Free Vulnerability Check

Is your site affected by LSN-0113-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against LSN-0113-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.