🛡️ USN-5343-1 — linux

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

linux, linux-aws, linux-kvm, linux-lts-xenial vulnerabilities

Yiqi Sun and Kevin Wang discovered that the cgroups implementation in the

Linux kernel did not properly restrict access to the cgroups v1

release_agent feature. A local attacker could use this to gain

administrative privileges. (CVE-2022-0492)

It was discovered that the aufs file system in the Linux kernel did not

properly restrict mount namespaces, when mounted with the non-default

allow_userns option set. A local attacker could use this to gain

administrative privileges. (CVE-2016-2853)

It was discovered that the aufs file system in the Linux kernel did not

properly maintain POSIX ACL xattr data, when mounted with the non-default

allow_userns option. A local attacker could possibly use this to gain

elevated privileges. (CVE-2016-2854)

It was discovered that the f2fs file system in the Linux kernel did not

properly validate metadata in some situations. An attacker could use this

to construct a malicious f2fs image that, when mounted and operated on,

could cause a denial of service (system crash) or possibly execute

arbitrary code. (CVE-2019-19449)

It was discovered that the XFS file system implementation in the Linux

kernel did not properly validate meta data in some circumstances. An

attacker could use this to construct a malicious XFS image that, when

mounted, could cause a denial of service. (CVE-2020-12655)

Kiyin (尹亮) discovered that the NFC LLCP protocol implementation in the

Linux kernel contained a reference counting error. A local attacker could

use this to cause a denial of service (system crash). (CVE-2020-25670)

Kiyin (尹亮) discovered that the NFC LLCP protocol implementation in the

Linux kernel did not properly deallocate memory in certain error

situations. A local attacker could use this to cause a denial of service

(memory exhaustion). (CVE-2020-25671, CVE-2020-25672)

Kiyin (尹亮) discovered that the NFC LLCP protocol implementation in the

Linux kernel did not properly handle error conditions in some situations,

leading to an infinite loop. A local attacker could use this to cause a

denial of service. (CVE-2020-25673)

Mathy Vanhoef discovered that the Linux kernel’s WiFi implementation

incorrectly handled EAPOL frames from unauthenticated senders. A physically

proximate attacker could inject malicious packets to cause a denial of

service (system crash). (CVE-2020-26139)

Mathy Vanhoef discovered that the Linux kernel’s WiFi implementation could

reassemble mixed encrypted and plaintext fragments. A physically proximate

attacker could possibly use this issue to inject packets or exfiltrate

selected fragments. (CVE-2020-26147)

It was discovered that the BR/EDR pin-code pairing procedure in the Linux

kernel was vulnerable to an impersonation attack. A physically proximate

attacker could possibly use this to pair to a device without knowledge of

the pin-code. (CVE-2020-26555)

It was discovered that the bluetooth subsystem in the Linux kernel did not

properly perform access control. An authenticated attacker could possibly

use this to expose sensitive information. (CVE-2020-26558, CVE-2021-0129)

It was discovered that the FUSE user space file system implementation in

the Linux kernel did not properly handle bad inodes in some situations. A

local attacker could possibly use this to cause a denial of service.

(CVE-2020-36322)

It was discovered that the Infiniband RDMA userspace connection manager

implementation in the Linux kernel contained a race condition leading to a

use-after-free vulnerability. A local attacker could use this to cause a

denial of service (system crash) or possible execute arbitrary code.

(CVE-2020-36385)

It was discovered that the DRM subsystem in the Linux kernel contained

double-free vulnerabilities. A privileged attacker could possibly use this

to cause a denial of service (system crash) or possibly execute arbitrary

code. (CVE-2021-20292)

It was discovered that a race condition existed in the timer implementation

in the Linux kernel. A privileged attacker could use this to cause a denial

of service. (CVE-2021-20317)

Or Cohen and Nadav Markus discovered a use-after-free vulnerability in the

nfc implementation in the Linux kernel. A privileged local attacker could

use this issue to cause a denial of service (system crash) or possibly

execute arbitrary code. (CVE-2021-23134)

It was discovered that the Xen paravirtualization backend in the Linux

kernel did not properly deallocate memory in some situations. A local

attacker could use this to cause a denial of service (memory exhaustion).

(CVE-2021-28688)

It was discovered that the RPA PCI Hotplug driver implementation in the

Linux kernel did not properly handle device name writes via sysfs, leading

to a buffer overflow. A privileged attacker could use this to cause a

denial of service (system crash) or possibly execute arbitrary code.

(CVE-2021-28972)

It was discovered that a race condition existed in the netfilter subsystem

of the Linux kernel when rep

Affected software

USN-5343-1 is recorded against 4 packages.

  • linux (fixed in 4.4.0-222.255)
  • linux-aws (fixed in 4.4.0-1138.152)
  • linux-kvm (fixed in 4.4.0-1103.112)
  • linux-lts-xenial (fixed in 4.4.0-222.255~14.04.1)

Timeline and source

Published on 22 March 2022 and last revised on 29 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

ubuntu.com (Advisory)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2022-03-22
Updated 2026-08-12
Modified 2026-06-29
Fix URL N/A

Affected Packages

Software From version Fixed in
linux 4.4.0-222.255
linux-aws 4.4.0-1138.152
linux-kvm 4.4.0-1103.112
linux-lts-xenial 4.4.0-222.255~14.04.1

References

Similar Threats

Free Vulnerability Check

Is your site affected by USN-5343-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against USN-5343-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.