CVE-2022-0185
Published: 18 January 2022
A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.
From the Ubuntu security team
William Liu and Jamie Hill-Daniel discovered that the file system context functionality in the Linux kernel contained an integer underflow vulnerability, leading to an out-of-bounds write. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code.
Mitigation
Disable unprivileged user namespaces: sysctl -w kernel.unprivileged_userns_clone=0
CVSS 3 base score: 8.4
Status
Package | Release | Status |
---|---|---|
linux-azure-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Released
(5.13.0-1012.14~20.04.1)
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux Launchpad, Ubuntu, Debian |
trusty |
Not vulnerable
(3.11.0-12.19)
|
xenial |
Not vulnerable
(4.4.0-2.16)
|
|
bionic |
Not vulnerable
(4.13.0-16.19)
|
|
upstream |
Released
(5.17~rc1)
|
|
focal |
Released
(5.4.0-96.109)
|
|
hirsute |
Released
(5.11.0-49.55)
|
|
impish |
Released
(5.13.0-27.29)
|
|
jammy |
Not vulnerable
(5.15.0-18.18)
|
|
linux-hwe Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
bionic |
Ignored
(replaced by linux-hwe-5.4)
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
xenial |
Not vulnerable
(4.8.0-39.42~16.04.1)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-hwe-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(5.4.0-96.109~18.04.1)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-hwe-5.8 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Ignored
(was needs-triage now end-of-life)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-hwe-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Ignored
(was needs-triage now end-of-life)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-hwe-edge Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Ignored
(superseded by linux-hwe)
|
|
bionic |
Ignored
(superseded by linux-hwe-5.4)
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-lts-xenial Launchpad, Ubuntu, Debian |
xenial |
Does not exist
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
trusty |
Not vulnerable
(4.4.0-13.29~14.04.1)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-kvm Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
focal |
Released
(5.4.0-1053.55)
|
|
hirsute |
Released
(5.11.0-1024.27)
|
|
impish |
Released
(5.13.0-1010.11)
|
|
bionic |
Not vulnerable
(4.15.0-1002.2)
|
|
xenial |
Not vulnerable
(4.4.0-1004.9)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Not vulnerable
(5.15.0-1002.2)
|
|
linux-aws Launchpad, Ubuntu, Debian |
trusty |
Not vulnerable
(4.4.0-1002.2)
|
xenial |
Not vulnerable
(4.4.0-1001.10)
|
|
bionic |
Not vulnerable
(4.15.0-1001.1)
|
|
upstream |
Released
(5.17~rc1)
|
|
focal |
Released
(5.4.0-1063.66)
|
|
hirsute |
Released
(5.11.0-1027.30)
|
|
impish |
Released
(5.13.0-1011.12)
|
|
jammy |
Not vulnerable
(5.15.0-1002.4)
|
|
linux-aws-5.0 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-aws-5.3)
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-aws-5.3 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-aws-5.4)
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-aws-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(5.4.0-1063.66~18.04.1)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-aws-5.8 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Ignored
(was needs-triage now end-of-life)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-aws-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
focal |
Released
(5.11.0-1027.30~20.04.1)
|
|
jammy |
Does not exist
|
|
linux-aws-hwe Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Not vulnerable
(4.15.0-1030.31~16.04.1)
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-azure Launchpad, Ubuntu, Debian |
trusty |
Not vulnerable
(4.15.0-1023.24~14.04.1)
|
xenial |
Not vulnerable
(4.11.0-1009.9)
|
|
bionic |
Ignored
(superseded by linux-azure-5.3)
|
|
upstream |
Released
(5.17~rc1)
|
|
focal |
Released
(5.4.0-1067.70)
|
|
hirsute |
Released
(5.11.0-1027.30)
|
|
impish |
Released
(5.13.0-1012.14)
|
|
jammy |
Not vulnerable
(5.15.0-1001.2)
|
|
linux-azure-4.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Not vulnerable
(4.15.0-1082.92)
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-azure-5.3 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-azure-5.4)
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-azure-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(5.4.0-1067.70~18.04.1)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-azure-5.8 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Ignored
(was needs-triage now end-of-life)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-azure-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Released
(5.11.0-1027.30~20.04.1)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-bluefield Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Released
(5.4.0-1025.28)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-dell300x Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Not vulnerable
(4.15.0-1005.8)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-azure-edge Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-azure-5.3)
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-gcp Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
bionic |
Ignored
(superseded by linux-gcp-5.3)
|
|
focal |
Released
(5.4.0-1062.66)
|
|
hirsute |
Released
(5.11.0-1028.32)
|
|
impish |
Released
(5.13.0-1012.15)
|
|
xenial |
Not vulnerable
(4.10.0-1004.4)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Not vulnerable
(5.15.0-1001.3)
|
|
linux-gcp-4.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Not vulnerable
(4.15.0-1071.81)
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-gcp-5.3 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-gcp-5.4)
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-gcp-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(5.4.0-1062.66~18.04.1)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-gcp-5.8 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(was needs-triage now end-of-life)
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-gcp-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
focal |
Released
(5.11.0-1028.32~20.04.1)
|
|
jammy |
Does not exist
|
|
linux-gke Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Ignored
(reached end of standard support)
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
focal |
Released
(5.4.0-1059.62)
|
|
jammy |
Needs triage
|
|
linux-gke-4.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(was needs-triage now end-of-life)
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-gke-5.0 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Ignored
(was needs-triage now end-of-life)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-gke-5.3 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Ignored
(was needs-triage now end-of-life)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-gke-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(5.4.0-1059.62~18.04.1)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-gkeop Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Released
(5.4.0-1031.32)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-gkeop-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(5.4.0-1031.32~18.04.1)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-ibm Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Released
(5.4.0-1012.13)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Not vulnerable
(5.15.0-1002.2)
|
|
linux-intel-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Released
(5.13.0-1010.10)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-oracle Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
focal |
Released
(5.4.0-1061.65)
|
|
hirsute |
Released
(5.11.0-1027.30)
|
|
impish |
Released
(5.13.0-1015.19)
|
|
bionic |
Not vulnerable
(4.15.0-1007.9)
|
|
xenial |
Not vulnerable
(4.15.0-1007.9~16.04.1)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Not vulnerable
(5.15.0-1001.3)
|
|
linux-oracle-5.0 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-oracle-5.3)
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-oracle-5.3 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-oracle-5.4)
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-oracle-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(5.4.0-1061.65~18.04.1)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-oracle-5.8 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Ignored
(was needs-triage now end-of-life)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-oracle-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Released
(5.11.0-1027.30~20.04.1)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-oem Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Ignored
(superseded by linux-hwe)
|
|
bionic |
Ignored
(was needs-triage now end-of-life)
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-oem-5.6 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(was needs-triage now end-of-life)
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-oem-5.10 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
focal |
Released
(5.10.0-1057.61)
|
|
jammy |
Does not exist
|
|
linux-oem-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
focal |
Released
(5.13.0-1028.35)
|
|
jammy |
Does not exist
|
|
linux-oem-5.14 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
focal |
Released
(5.14.0-1020.22)
|
|
jammy |
Does not exist
|
|
linux-oem-osp1 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(was needs-triage now end-of-life)
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-raspi Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Released
(5.4.0-1050.56)
|
|
hirsute |
Released
(5.11.0-1027.30)
|
|
impish |
Released
(5.13.0-1015.17)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Not vulnerable
(5.15.0-1002.2)
|
|
linux-raspi2 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Ignored
(was needs-triage now end-of-life)
|
|
bionic |
Not vulnerable
(4.13.0-1005.5)
|
|
focal |
Ignored
(replaced by linux-raspi)
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-raspi2-5.3 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(was needs-triage now end-of-life)
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-raspi-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Released
(5.4.0-1050.56~18.04.1)
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-riscv Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-riscv-5.8)
|
|
hirsute |
Ignored
(reached end-of-life)
|
|
impish |
Released
(5.13.0-1010.11)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Not vulnerable
(5.15.0-1004.4)
|
|
linux-riscv-5.8 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(was needs-triage now end-of-life)
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-riscv-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Released
(5.11.0-1028.31~20.04.1)
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-snapdragon Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Ignored
(was needs-triage now end-of-life)
|
|
bionic |
Not vulnerable
(4.4.0-1077.82)
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-hwe-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
focal |
Released
(5.13.0-27.29~20.04.1)
|
|
jammy |
Does not exist
|
|
linux-aws-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
focal |
Released
(5.13.0-1011.12~20.04.1)
|
|
jammy |
Does not exist
|
|
linux-fips Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
hirsute |
Does not exist
|
|
impish |
Does not exist
|
|
upstream |
Released
(5.17~rc1)
|
|
xenial |
Not vulnerable
(4.4.0-1073.79)
|
|
jammy |
Does not exist
|
|
linux-oracle-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Released
(5.13.0-1015.19~20.04.1)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-gcp-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Released
(5.13.0-1012.15~20.04.1)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-ibm-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
bionic |
Released
(5.4.0-1012.13~18.04.1)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-azure-fde Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
impish |
Does not exist
|
|
focal |
Not vulnerable
(5.4.0-1063.66+cvm2.2)
|
|
upstream |
Released
(5.17~rc1)
|
|
jammy |
Does not exist
|
|
linux-lowlatency Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Not vulnerable
|
|
upstream |
Needs triage
|
|
linux-oem-5.17 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
impish |
Does not exist
|
|
jammy |
Not vulnerable
|
|
upstream |
Needs triage
|
Notes
Author | Note |
---|---|
amurray | Requires CAP_SYS_ADMIN however this can be done within a new user namespace - so can be mitigated by disabling unprivileged user namespaces. |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0185
- https://www.openwall.com/lists/oss-security/2022/01/18/7
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=722d94847de29310e8aa03fcbdb41fc92c521756
- https://ubuntu.com/security/notices/USN-5240-1
- https://ubuntu.com/security/notices/USN-5362-1
- NVD
- Launchpad
- Debian