CVE-2023-4244
Published: 6 September 2023
A use-after-free vulnerability in the Linux kernel's netfilter: nf_tables component can be exploited to achieve local privilege escalation. Due to a race condition between nf_tables netlink control plane transaction and nft_set element garbage collection, it is possible to underflow the reference counter causing a use-after-free vulnerability. We recommend upgrading past commit 3e91b0ebd994635df2346353322ac51ce84ce6d8.
From the Ubuntu Security Team
Bien Pham discovered that the netfiler subsystem in the Linux kernel contained a race condition, leading to a use-after-free vulnerability. A local user could use this to cause a denial of service (system crash) or possibly execute arbitrary code.
Notes
Author | Note |
---|---|
Priority reason: Allows local code execution / privilege escalation |
|
cascardo | Looks like a duplicate of CVE-2023-4563 |
rodrigo-zaiden | CVE-2023-4563 was marked as duplicated of this. USN-6443-1 was firstly announced fixing this CVE for linux-oem-6.1 in version 6.1.0-1024.24, but one of the fix commits was missing in that version. The complete fix in linux-oem-6.1 is available in version 6.1.0-1025.25. |
Mitigation
If not needed, disable the ability for unprivileged users to create namespaces. To do this temporarily, do: sudo sysctl -w kernel.unprivileged_userns_clone=0 To disable across reboots, do: echo kernel.unprivileged_userns_clone=0 | \ sudo tee /etc/sysctl.d/99-disable-unpriv-userns.conf
Priority
Status
Package | Release | Status |
---|---|---|
linux Launchpad, Ubuntu, Debian |
bionic |
Needed
|
focal |
Needed
|
|
mantic |
Released
(6.5.0-13.13)
|
|
trusty |
Not vulnerable
(3.11.0-12.19)
|
|
upstream |
Released
(6.6~rc1)
|
|
xenial |
Needed
|
|
jammy |
Released
(5.15.0-87.97)
|
|
lunar |
Released
(6.2.0-35.35)
|
|
Patches: Introduced by 3c4287f62044a90e73a561aa05fc46e62da173da Introduced by 8d8540c4f5e03d847c004e71d6a577bf4f8c78cd Introduced by 9d0982927e79049675cb6c6c04a0ebb3dad5a434 Introduced by cfed7e1b1f8ed9b3d81ab12203cfb69c3ef24ac6 Introduced by 3c4287f62044a90e73a561aa05fc46e62da173da Introduced by 8d8540c4f5e03d847c004e71d6a577bf4f8c78cd Introduced by 9d0982927e79049675cb6c6c04a0ebb3dad5a434 Introduced by 9d0982927e79049675cb6c6c04a0ebb3dad5a434 Introduced by d0a8d877da976c244092ce859683b2fa116217db Introduced by 5f68718b34a531a556f2f50300ead2862278da26 Introduced by 5f68718b34a531a556f2f50300ead2862278da26 Introduced by 5f68718b34a531a556f2f50300ead2862278da26 Introduced by 8aeff920dcc9b3f8cf43042a76428582634d9208 Introduced by f6c383b8c31a93752a52697f8430a71dcbc46adf |
||
linux-hwe Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
bionic |
Ignored
(replaced by linux-hwe-5.4)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
xenial |
Needed
|
|
linux-hwe-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
bionic |
Needed
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-hwe-5.8 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-hwe-5.11)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-hwe-5.11)
|
|
mantic |
Does not exist
|
|
linux-hwe-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-hwe-5.13)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-hwe-5.13)
|
|
mantic |
Does not exist
|
|
linux-hwe-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-hwe-5.15)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-hwe-5.15)
|
|
mantic |
Does not exist
|
|
linux-hwe-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
focal |
Released
(5.15.0-87.97~20.04.1)
|
|
linux-hwe-5.19 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
lunar |
Does not exist
|
|
jammy |
Ignored
(end of life, was needs-triage)
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-hwe-6.2 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
jammy |
Released
(6.2.0-35.35~22.04.1)
|
|
linux-hwe-edge Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Ignored
(superseded by linux-hwe)
|
|
bionic |
Ignored
(superseded by linux-hwe-5.4)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(end of life)
|
|
mantic |
Does not exist
|
|
linux-lts-xenial Launchpad, Ubuntu, Debian |
xenial |
Does not exist
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
trusty |
Needed
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-kvm Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
mantic |
Does not exist
|
|
bionic |
Needed
|
|
focal |
Needed
|
|
upstream |
Released
(6.6~rc1)
|
|
xenial |
Needed
|
|
jammy |
Released
(5.15.0-1045.50)
|
|
lunar |
Released
(6.2.0-1015.15)
|
|
linux-allwinner Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Ignored
(end of life)
|
|
upstream |
Ignored
(end of life)
|
|
mantic |
Does not exist
|
|
linux-allwinner-5.19 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
lunar |
Does not exist
|
|
jammy |
Ignored
(end of life, was needs-triage)
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-aws-5.0 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-hwe-5.3)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-hwe-5.3)
|
|
mantic |
Does not exist
|
|
linux-aws-5.3 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-aws-5.4)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-aws-5.4)
|
|
mantic |
Does not exist
|
|
linux-aws-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
bionic |
Needed
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-aws-5.8 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-aws-5.11)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-aws-5.11)
|
|
mantic |
Does not exist
|
|
linux-aws-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-aws-5.13)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-aws-5.13)
|
|
mantic |
Does not exist
|
|
linux-aws-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-aws-5.15)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-aws-5.15)
|
|
mantic |
Does not exist
|
|
linux-aws-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
focal |
Released
(5.15.0-1048.53~20.04.1)
|
|
linux-aws-5.19 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Ignored
(superseded by linux-aws-6.2)
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-aws-6.2)
|
|
mantic |
Does not exist
|
|
linux-aws-6.2 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
jammy |
Released
(6.2.0-1014.14~22.04.1)
|
|
linux-aws-hwe Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
xenial |
Needed
|
|
linux-azure Launchpad, Ubuntu, Debian |
bionic |
Ignored
(superseded by linux-azure-5.3)
|
focal |
Needed
|
|
mantic |
Pending
(6.5.0-1010.10)
|
|
trusty |
Needed
|
|
upstream |
Released
(6.6~rc1)
|
|
xenial |
Needed
|
|
jammy |
Released
(5.15.0-1050.57)
|
|
lunar |
Released
(6.2.0-1015.15)
|
|
linux-azure-4.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
bionic |
Needed
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-azure-5.3 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-azure-5.4)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-azure-5.4)
|
|
mantic |
Does not exist
|
|
linux-azure-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
bionic |
Needed
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-azure-5.8 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-azure-5.11)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-azure-5.11)
|
|
mantic |
Does not exist
|
|
linux-azure-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-azure-5.13)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-azure-5.13)
|
|
mantic |
Does not exist
|
|
linux-azure-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-azure-5.15)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-azure-5.15)
|
|
mantic |
Does not exist
|
|
linux-azure-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
focal |
Released
(5.15.0-1050.57~20.04.1)
|
|
linux-azure-5.19 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
lunar |
Does not exist
|
|
jammy |
Ignored
(end of life, was needs-triage)
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-azure-fde Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-azure-fde-5.15)
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
jammy |
Released
(5.15.0-1050.57)
|
|
linux-azure-fde-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
focal |
Released
(5.15.0-1050.57~20.04.1)
|
|
linux-azure-fde-5.19 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
lunar |
Does not exist
|
|
jammy |
Ignored
(end of life, was needs-triage)
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-bluefield Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
focal |
Needed
|
|
jammy |
Pending
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-dell300x Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(end of standard support)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(end of life)
|
|
mantic |
Does not exist
|
|
linux-azure-edge Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-azure-5.3)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-azure-5.3)
|
|
mantic |
Does not exist
|
|
linux-fips Launchpad, Ubuntu, Debian |
trusty |
Ignored
(end of standard support)
|
xenial |
Ignored
(end of standard support)
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-gcp Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
bionic |
Ignored
(superseded by linux-gcp-5.3)
|
|
focal |
Needed
|
|
mantic |
Released
(6.5.0-1010.10)
|
|
upstream |
Released
(6.6~rc1)
|
|
xenial |
Needed
|
|
jammy |
Released
(5.15.0-1045.53)
|
|
lunar |
Released
(6.2.0-1017.19)
|
|
linux-gcp-4.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
mantic |
Does not exist
|
|
bionic |
Needed
|
|
linux-gcp-5.3 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-gcp-5.4)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-gcp-5.4)
|
|
mantic |
Does not exist
|
|
linux-gcp-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
bionic |
Needed
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-gcp-5.8 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-gcp-5.11)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-gcp-5.11)
|
|
mantic |
Does not exist
|
|
linux-gcp-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-gcp-5.13)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-gcp-5.13)
|
|
mantic |
Does not exist
|
|
linux-gcp-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-gcp-5.15)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-gcp-5.15)
|
|
mantic |
Does not exist
|
|
linux-gcp-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
focal |
Released
(5.15.0-1045.53~20.04.2)
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-gcp-5.19 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Ignored
(superseded by linux-gcp-6.2)
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-gcp-6.2 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
jammy |
Released
(6.2.0-1017.19~22.04.1)
|
|
linux-gke Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Ignored
(end of standard support)
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(end of life)
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
jammy |
Released
(5.15.0-1045.50)
|
|
linux-gke-4.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-gke-5.0)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-gke-5.0)
|
|
mantic |
Does not exist
|
|
linux-gke-5.0 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-gke-5.3)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-gke-5.3)
|
|
mantic |
Does not exist
|
|
linux-gke-5.3 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-gke-5.4)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-gke-5.4)
|
|
mantic |
Does not exist
|
|
linux-gke-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(end of life)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(end of life)
|
|
mantic |
Does not exist
|
|
linux-gke-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(end of life)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(end of life)
|
|
mantic |
Does not exist
|
|
linux-gkeop Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
focal |
Needed
|
|
upstream |
Released
(6.6~rc1)
|
|
jammy |
Released
(5.15.0-1031.37)
|
|
linux-gkeop-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(end of life)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(end of life)
|
|
mantic |
Does not exist
|
|
linux-gkeop-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
focal |
Released
(5.15.0-1031.37~20.04.1)
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-ibm Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
lunar |
Ignored
(end of life, was needs-triage)
|
|
focal |
Needed
|
|
mantic |
Ignored
(end of life, was needs-triage)
|
|
upstream |
Released
(6.6~rc1)
|
|
jammy |
Released
(5.15.0-1041.44)
|
|
linux-ibm-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
bionic |
Needed
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-ibm-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
focal |
Released
(5.15.0-1041.44~20.04.1)
|
|
linux-intel-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(end of life)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(end of life)
|
|
mantic |
Does not exist
|
|
linux-intel-iotg Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
jammy |
Released
(5.15.0-1043.49)
|
|
linux-intel-iotg-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
focal |
Released
(5.15.0-1043.49~20.04.1)
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-iot Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
focal |
Needed
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-lowlatency Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
mantic |
Released
(6.5.0-13.13.1)
|
|
upstream |
Released
(6.6~rc1)
|
|
jammy |
Released
(5.15.0-87.96)
|
|
lunar |
Released
(6.2.0-1015.15)
|
|
linux-lowlatency-hwe-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
focal |
Released
(5.15.0-87.96~20.04.1)
|
|
linux-lowlatency-hwe-5.19 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
lunar |
Does not exist
|
|
jammy |
Ignored
(end of life, was needs-triage)
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-lowlatency-hwe-6.2 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
jammy |
Released
(6.2.0-1015.15~22.04.1)
|
|
linux-nvidia Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
jammy |
Released
(5.15.0-1039.39)
|
|
linux-oracle Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
bionic |
Needed
|
|
focal |
Needed
|
|
mantic |
Released
(6.5.0-1012.12)
|
|
upstream |
Released
(6.6~rc1)
|
|
xenial |
Needed
|
|
jammy |
Released
(5.15.0-1046.52)
|
|
lunar |
Released
(6.2.0-1014.14)
|
|
linux-oracle-5.0 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-oracle-5.3)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-oracle-5.3)
|
|
mantic |
Does not exist
|
|
linux-oracle-5.3 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(superseded by linux-oracle-5.4)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-oracle-5.4)
|
|
mantic |
Does not exist
|
|
linux-oracle-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
bionic |
Needed
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-oracle-5.8 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-oracle-5.11)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-oracle-5.11)
|
|
mantic |
Does not exist
|
|
linux-oracle-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-oracle-5.13)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-oracle-5.13)
|
|
mantic |
Does not exist
|
|
linux-oracle-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-oracle-5.15)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-oracle-5.15)
|
|
mantic |
Does not exist
|
|
linux-oracle-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
focal |
Released
(5.15.0-1046.52~20.04.1)
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-oem Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Ignored
(end of standard support)
|
|
bionic |
Ignored
(end of life)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(end of life)
|
|
mantic |
Does not exist
|
|
linux-oem-5.6 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-oem-5.10)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-oem-5.10)
|
|
mantic |
Does not exist
|
|
linux-oem-5.10 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-oem-5.13)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-oem-5.13)
|
|
mantic |
Does not exist
|
|
linux-oem-5.13 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-oem-5.14)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-oem-5.14)
|
|
mantic |
Does not exist
|
|
linux-oem-5.14 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(end of life)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(end of life)
|
|
mantic |
Does not exist
|
|
linux-oem-5.17 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
lunar |
Does not exist
|
|
jammy |
Ignored
(end of life, was needs-triage)
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-oem-6.0 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
lunar |
Does not exist
|
|
jammy |
Ignored
(end of life, was needs-triage)
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-oem-6.1 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
jammy |
Released
(6.1.0-1025.25)
|
|
linux-oem-osp1 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(end of standard support)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(end of life)
|
|
mantic |
Does not exist
|
|
linux-raspi Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Needed
|
|
mantic |
Released
(6.5.0-1007.9)
|
|
upstream |
Released
(6.6~rc1)
|
|
jammy |
Released
(5.15.0-1041.44)
|
|
lunar |
Released
(6.2.0-1015.17)
|
|
linux-raspi2 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Ignored
(end of standard support)
|
|
bionic |
Ignored
(end of standard support)
|
|
focal |
Ignored
(replaced by linux-raspi)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(end of life)
|
|
mantic |
Does not exist
|
|
linux-raspi2-5.3 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Ignored
(end of standard support)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-raspi2-5.4)
|
|
mantic |
Does not exist
|
|
linux-raspi-5.4 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
bionic |
Needed
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-riscv Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-riscv-5.8)
|
|
jammy |
Ignored
(end of life)
|
|
lunar |
Released
(6.2.0-35.35.1)
|
|
mantic |
Released
(6.5.0-13.13.1)
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-riscv-5.8 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-riscv-5.11)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-riscv-5.11)
|
|
mantic |
Does not exist
|
|
linux-riscv-5.11 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Ignored
(superseded by linux-riscv-5.13)
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(superseded by linux-riscv-5.13)
|
|
mantic |
Does not exist
|
|
linux-riscv-5.15 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
focal |
Released
(5.15.0-1044.48~20.04.1)
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-riscv-5.19 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Ignored
(end of life)
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(end of life)
|
|
mantic |
Does not exist
|
|
linux-snapdragon Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Ignored
(end of standard support)
|
|
bionic |
Ignored
(end of standard support)
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(end of life)
|
|
mantic |
Does not exist
|
|
linux-starfive Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
mantic |
Released
(6.5.0-1004.5)
|
|
upstream |
Released
(6.6~rc1)
|
|
lunar |
Released
(6.2.0-1007.8)
|
|
linux-starfive-5.19 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Ignored
(end of life)
|
|
lunar |
Does not exist
|
|
upstream |
Ignored
(end of life)
|
|
mantic |
Does not exist
|
|
linux-xilinx-zynqmp Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
lunar |
Does not exist
|
|
jammy |
Released
(5.15.0-1025.29)
|
|
mantic |
Does not exist
|
|
focal |
Needed
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-azure-6.2 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
jammy |
Released
(6.2.0-1015.15~22.04.1)
|
|
linux-azure-fde-6.2 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
jammy |
Released
(6.2.0-1015.15~22.04.1)
|
|
linux-nvidia-6.2 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
jammy |
Released
(6.2.0-1011.11)
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-starfive-6.2 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
jammy |
Released
(6.2.0-1007.8~22.04.1)
|
|
upstream |
Released
(6.6~rc1)
|
|
linux-aws Launchpad, Ubuntu, Debian |
bionic |
Needed
|
focal |
Needed
|
|
mantic |
Released
(6.5.0-1010.10)
|
|
trusty |
Needed
|
|
upstream |
Released
(6.6~rc1)
|
|
xenial |
Needed
|
|
jammy |
Released
(5.15.0-1048.53)
|
|
lunar |
Released
(6.2.0-1014.14)
|
|
linux-laptop Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
jammy |
Does not exist
|
|
lunar |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
mantic |
Released
(6.5.0-1006.9)
|
|
linux-oem-6.5 Launchpad, Ubuntu, Debian |
trusty |
Does not exist
|
xenial |
Does not exist
|
|
bionic |
Does not exist
|
|
focal |
Does not exist
|
|
lunar |
Does not exist
|
|
mantic |
Does not exist
|
|
upstream |
Released
(6.6~rc1)
|
|
jammy |
Released
(6.5.0-1008.8)
|
Severity score breakdown
Parameter | Value |
---|---|
Base score | 7.0 |
Attack vector | Local |
Attack complexity | High |
Privileges required | Low |
User interaction | None |
Scope | Unchanged |
Confidentiality | High |
Integrity impact | High |
Availability impact | High |
Vector | CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-4244
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=3e91b0ebd994635df2346353322ac51ce84ce6d8
- https://kernel.dance/3e91b0ebd994635df2346353322ac51ce84ce6d8
- https://ubuntu.com/security/notices/USN-6443-1
- https://ubuntu.com/security/notices/USN-6444-1
- https://ubuntu.com/security/notices/USN-6445-1
- https://ubuntu.com/security/notices/USN-6446-1
- https://ubuntu.com/security/notices/USN-6444-2
- https://ubuntu.com/security/notices/USN-6445-2
- https://ubuntu.com/security/notices/USN-6446-2
- https://ubuntu.com/security/notices/USN-6446-3
- https://ubuntu.com/security/notices/USN-6461-1
- https://ubuntu.com/security/notices/USN-6466-1
- https://ubuntu.com/security/notices/USN-6503-1
- https://ubuntu.com/security/notices/USN-6537-1
- NVD
- Launchpad
- Debian