🛡️ USN-6013-1 — linux-aws

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

linux-aws vulnerabilities

Xuewei Feng, Chuanpu Fu, Qi Li, Kun Sun, and Ke Xu discovered that the TCP

implementation in the Linux kernel did not properly handle IPID assignment.

A remote attacker could use this to cause a denial of service (connection

termination) or inject forged data. (CVE-2020-36516)

Ke Sun, Alyssa Milburn, Henrique Kawakami, Emma Benoit, Igor Chervatyuk,

Lisa Aichele, and Thais Moreira Hamasaki discovered that the Spectre

Variant 2 mitigations for AMD processors on Linux were insufficient in some

situations. A local attacker could possibly use this to expose sensitive

information. (CVE-2021-26401)

Jürgen Groß discovered that the Xen subsystem within the Linux kernel did

not adequately limit the number of events driver domains (unprivileged PV

backends) could send to other guest VMs. An attacker in a driver domain

could use this to cause a denial of service in other guest VMs.

(CVE-2021-28712, CVE-2021-28713)

Wolfgang Frisch discovered that the ext4 file system implementation in the

Linux kernel contained an integer overflow when handling metadata inode

extents. An attacker could use this to construct a malicious ext4 file

system image that, when mounted, could cause a denial of service (system

crash). (CVE-2021-3428)

It was discovered that the IEEE 802.15.4 wireless network subsystem in the

Linux kernel did not properly handle certain error conditions, leading to a

null pointer dereference vulnerability. A local attacker could possibly use

this to cause a denial of service (system crash). (CVE-2021-3659)

It was discovered that the System V IPC implementation in the Linux kernel

did not properly handle large shared memory counts. A local attacker could

use this to cause a denial of service (memory exhaustion). (CVE-2021-3669)

Alois Wohlschlager discovered that the overlay file system in the Linux

kernel did not restrict private clones in some situations. An attacker

could use this to expose sensitive information. (CVE-2021-3732)

It was discovered that the SCTP protocol implementation in the Linux kernel

did not properly verify VTAGs in some situations. A remote attacker could

possibly use this to cause a denial of service (connection disassociation).

(CVE-2021-3772)

It was discovered that the btrfs file system implementation in the Linux

kernel did not properly handle locking in certain error conditions. A local

attacker could use this to cause a denial of service (kernel deadlock).

(CVE-2021-4149)

Jann Horn discovered that the socket subsystem in the Linux kernel

contained a race condition when handling listen() and connect() operations,

leading to a read-after-free vulnerability. A local attacker could use this

to cause a denial of service (system crash) or possibly expose sensitive

information. (CVE-2021-4203)

It was discovered that the file system quotas implementation in the Linux

kernel did not properly validate the quota block number. An attacker could

use this to construct a malicious file system image that, when mounted and

operated on, could cause a denial of service (system crash).

(CVE-2021-45868)

Zhihua Yao discovered that the MOXART SD/MMC driver in the Linux kernel did

not properly handle device removal, leading to a use-after-free

vulnerability. A physically proximate attacker could possibly use this to

cause a denial of service (system crash). (CVE-2022-0487)

It was discovered that the block layer subsystem in the Linux kernel did

not properly initialize memory in some situations. A privileged local

attacker could use this to expose sensitive information (kernel memory).

(CVE-2022-0494)

It was discovered that the UDF file system implementation in the Linux

kernel could attempt to dereference a null pointer in some situations. An

attacker could use this to construct a malicious UDF image that, when

mounted and operated on, could cause a denial of service (system crash).

(CVE-2022-0617)

David Bouman discovered that the netfilter subsystem in the Linux kernel

did not initialize memory in some situations. A local attacker could use

this to expose sensitive information (kernel memory). (CVE-2022-1016)

It was discovered that the implementation of the 6pack and mkiss protocols

in the Linux kernel did not handle detach events properly in some

situations, leading to a use-after-free vulnerability. A local attacker

could possibly use this to cause a denial of service (system crash).

(CVE-2022-1195)

Duoming Zhou discovered race conditions in the AX.25 amateur radio protocol

implementation in the Linux kernel, leading to use-after-free

vulnerabilities. A local attacker could possibly use this to cause a denial

of service (system crash). (CVE-2022-1205)

It was discovered that the tty subsystem in the Linux kernel contained a

race condition in certain situations, leading to an out-of-bounds read

vulnerability. A local attacker could possibly use this to cause a denial

of service (system crash) or expose sensitive information. (CVE-2022-1462)

It was discovered that th

Affected software

USN-6013-1 is recorded against 1 package.

  • linux-aws (fixed in 4.4.0-1117.123)

Timeline and source

Published on 12 April 2023 and last revised on 29 June 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

ubuntu.com (Advisory)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)
ubuntu.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2023-04-12
Updated 2026-08-12
Modified 2026-06-29
Fix URL N/A

Affected Packages

Software From version Fixed in
linux-aws 4.4.0-1117.123

References

Similar Threats

Free Vulnerability Check

Is your site affected by USN-6013-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against USN-6013-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.