USN-4983-1: Linux kernel (OEM) vulnerabilities
3 June 2021
Several security issues were fixed in the Linux kernel.
Releases
Packages
- linux-oem-5.10 - Linux kernel for OEM systems
Details
Piotr Krysiuk discovered that the eBPF implementation in the Linux kernel
did not properly enforce limits for pointer operations. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2021-33200)
Piotr Krysiuk and Benedict Schlueter discovered that the eBPF
implementation in the Linux kernel performed out of bounds speculation on
pointer arithmetic. A local attacker could use this to expose sensitive
information. (CVE-2021-29155)
Piotr Krysiuk discovered that the eBPF implementation in the Linux kernel
did not properly prevent speculative loads in certain situations. A local
attacker could use this to expose sensitive information (kernel memory).
(CVE-2021-31829)
Reiji Watanabe discovered that the KVM VMX implementation in the Linux
kernel did not properly prevent user space from tampering with an array
index value, leading to a potential out-of-bounds write. A local attacker
could use this to cause a denial of service (system crash) or possibly
execute arbitrary code. (CVE-2021-3501)
Update instructions
The problem can be corrected by updating your system to the following package versions:
Ubuntu 20.04
-
linux-image-5.10.0-1029-oem
-
5.10.0-1029.30
-
linux-image-oem-20.04
-
5.10.0.1029.30
-
linux-image-oem-20.04b
-
5.10.0.1029.30
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References
Related notices
- USN-4977-1: linux-image-gcp, linux-image-generic-64k, linux-image-raspi-nolpae, linux-image-lowlatency, linux-image-5.11.0-18-generic-lpae, linux-image-generic, linux-image-azure, linux-aws, linux-image-virtual-hwe-20.04-edge, linux-image-5.11.0-1006-azure, linux-image-generic-hwe-20.04, linux-image-gke, linux-image-oem-20.04, linux-gcp, linux, linux-image-5.11.0-18-lowlatency, linux-image-virtual, linux-oracle, linux-image-5.11.0-1008-kvm, linux-image-aws, linux-image-lowlatency-hwe-20.04-edge, linux-image-generic-64k-hwe-20.04, linux-image-generic-lpae-hwe-20.04, linux-image-5.11.0-18-generic-64k, linux-raspi, linux-image-raspi, linux-image-5.11.0-1008-gcp, linux-image-5.11.0-1009-raspi, linux-image-virtual-hwe-20.04, linux-image-lowlatency-hwe-20.04, linux-image-generic-64k-hwe-20.04-edge, linux-image-generic-lpae-hwe-20.04-edge, linux-image-generic-lpae, linux-image-kvm, linux-image-5.11.0-1007-oracle, linux-image-5.11.0-1009-raspi-nolpae, linux-image-generic-hwe-20.04-edge, linux-azure, linux-kvm, linux-image-5.11.0-1008-aws, linux-image-5.11.0-18-generic, linux-image-oracle
- USN-4999-1: linux-image-gcp, linux-image-generic-64k, linux-image-raspi-nolpae, linux-image-lowlatency, linux-gcp-5.8, linux-image-generic, linux-image-azure, linux-aws, linux-image-gcp-edge, linux-image-virtual-hwe-20.04-edge, linux-image-generic-hwe-20.04, linux-image-gke, linux-image-oem-20.04, linux-image-5.8.0-1030-kvm, linux-gcp, linux, linux-image-virtual, linux-oracle, linux-image-aws, linux-image-lowlatency-hwe-20.04-edge, linux-azure-5.8, linux-image-generic-64k-hwe-20.04, linux-image-generic-lpae-hwe-20.04, linux-image-5.8.0-1029-raspi-nolpae, linux-image-5.8.0-1033-oracle, linux-raspi, linux-image-raspi, linux-image-5.8.0-1035-gcp, linux-image-azure-edge, linux-image-virtual-hwe-20.04, linux-image-lowlatency-hwe-20.04, linux-image-5.8.0-59-generic-64k, linux-image-generic-64k-hwe-20.04-edge, linux-hwe-5.8, linux-image-5.8.0-1038-aws, linux-image-generic-lpae-hwe-20.04-edge, linux-image-5.8.0-59-generic-lpae, linux-image-generic-lpae, linux-image-kvm, linux-image-5.8.0-59-lowlatency, linux-aws-5.8, linux-image-generic-hwe-20.04-edge, linux-image-5.8.0-1029-raspi, linux-azure, linux-kvm, linux-image-5.8.0-1036-azure, linux-oracle-5.8, linux-image-oracle, linux-image-oracle-edge, linux-image-5.8.0-59-generic
- USN-4997-1: linux-image-gcp, linux-image-generic-64k, linux-image-raspi-nolpae, linux-image-lowlatency, linux-image-5.11.0-1009-azure, linux-image-5.11.0-1012-raspi, linux-image-5.11.0-22-generic, linux-image-generic, linux-image-5.11.0-1010-oracle, linux-aws, linux-image-azure, linux-image-virtual-hwe-20.04-edge, linux-image-generic-hwe-20.04, linux-image-gke, linux-image-oem-20.04, linux-gcp, linux, linux-image-virtual, linux-oracle, linux-image-5.11.0-22-generic-64k, linux-image-aws, linux-image-lowlatency-hwe-20.04-edge, linux-image-generic-64k-hwe-20.04, linux-image-5.11.0-22-generic-lpae, linux-image-generic-lpae-hwe-20.04, linux-raspi, linux-image-raspi, linux-image-virtual-hwe-20.04, linux-image-lowlatency-hwe-20.04, linux-image-5.11.0-22-lowlatency, linux-image-generic-64k-hwe-20.04-edge, linux-image-generic-lpae-hwe-20.04-edge, linux-image-generic-lpae, linux-image-5.11.0-1012-raspi-nolpae, linux-image-generic-hwe-20.04-edge, linux-azure, linux-image-oracle, linux-image-5.11.0-1011-aws, linux-image-5.11.0-1011-gcp
- USN-5000-1: linux-image-gcp, linux-image-lowlatency, linux-image-generic, linux-gke-5.4, linux-image-azure, linux-aws, linux-image-lowlatency-hwe-18.04-edge, linux-image-gcp-edge, linux-image-5.4.0-1046-gcp, linux-image-aws-edge, linux-image-gkeop-5.4, linux-image-oem, linux-image-raspi-hwe-18.04, linux-image-raspi2-hwe-18.04-edge, linux-image-virtual-hwe-18.04, linux-image-gke, linux-image-generic-hwe-18.04, linux-image-azure-lts-20.04, linux-image-snapdragon-hwe-18.04, linux-gcp, linux, linux-gkeop, linux-image-virtual, linux-oracle, linux-image-aws, linux-image-generic-lpae-hwe-18.04-edge, linux-image-raspi-hwe-18.04-edge, linux-image-5.4.0-1051-aws, linux-gke, linux-raspi-5.4, linux-raspi, linux-hwe-5.4, linux-image-gke-5.4, linux-image-generic-lpae-hwe-18.04, linux-image-raspi, linux-image-gcp-lts-20.04, linux-image-azure-edge, linux-aws-5.4, linux-image-lowlatency-hwe-18.04, linux-image-gkeop, linux-gkeop-5.4, linux-image-5.4.0-1038-raspi, linux-image-generic-lpae, linux-image-5.4.0-77-generic-lpae, linux-image-generic-hwe-18.04-edge, linux-image-5.4.0-1018-gkeop, linux-azure-5.4, linux-image-raspi2, linux-image-oracle-lts-20.04, linux-oracle-5.4, linux-image-aws-lts-20.04, linux-gcp-5.4, linux-image-raspi2-hwe-18.04, linux-azure, linux-image-5.4.0-1048-oracle, linux-image-5.4.0-1051-azure, linux-image-5.4.0-77-lowlatency, linux-image-oem-osp1, linux-image-oracle, linux-image-oracle-edge, linux-image-snapdragon-hwe-18.04-edge, linux-image-5.4.0-1046-gke, linux-image-5.4.0-77-generic, linux-image-virtual-hwe-18.04-edge
- USN-5000-2: linux-tools-5.4.0-1041-kvm, linux-modules-5.4.0-1041-kvm, linux-image-unsigned-5.4.0-1041-kvm, linux-kvm-tools-5.4.0-1041, linux-kvm, linux-headers-5.4.0-1041-kvm, linux-image-5.4.0-1041-kvm, linux-tools-kvm, linux-kvm-headers-5.4.0-1041, linux-buildinfo-5.4.0-1041-kvm, linux-image-kvm, linux-headers-kvm
- USN-4997-2: linux-modules-5.11.0-1009-kvm, linux-kvm-headers-5.11.0-1009, linux-tools-5.11.0-1009-kvm, linux-image-unsigned-5.11.0-1009-kvm, linux-kvm, linux-headers-5.11.0-1009-kvm, linux-tools-kvm, linux-buildinfo-5.11.0-1009-kvm, linux-image-kvm, linux-image-5.11.0-1009-kvm, linux-kvm-tools-5.11.0-1009, linux-headers-kvm
- USN-5018-1: linux-buildinfo-4.15.0-151-generic, linux-image-4.15.0-1106-gcp, linux-signed-image-generic-hwe-16.04-edge, linux-headers-gcp, linux-headers-4.15.0-1078-oracle, linux-headers-generic-lpae, linux-image-generic-hwe-16.04-edge, linux-cloud-tools-4.15.0-151, linux-headers-snapdragon, linux-image-azure-edge, linux-image-unsigned-4.15.0-151-lowlatency, nic-pcmcia-modules-4.15.0-151-generic-di, linux-tools-4.15.0-1109-aws, linux-azure-4.15, linux-headers-4.15.0-1121-azure, linux-tools-4.15.0-1097-kvm, linux-cloud-tools-generic-hwe-16.04, linux-aws-edge, linux-azure-headers-4.15.0-1121, linux-aws, linux-snapdragon-headers-4.15.0-1109, linux-image-gcp-lts-18.04, linux-image-gke, scsi-modules-4.15.0-151-generic-di, linux-gcp, linux-image-4.15.0-151-generic-lpae, kernel-image-4.15.0-151-generic-di, linux-snapdragon, dasd-modules-4.15.0-151-generic-di, linux-cloud-tools-common, linux-signed-image-lowlatency-hwe-16.04, nic-shared-modules-4.15.0-151-generic-di, linux-image-unsigned-4.15.0-1078-oracle, linux-tools-azure, linux-tools-4.15.0-1106-gcp, linux-image-extra-virtual, md-modules-4.15.0-151-generic-lpae-di, pcmcia-modules-4.15.0-151-generic-di, linux-signed-image-oracle, linux-kvm, firewire-core-modules-4.15.0-151-generic-di, linux-tools-aws-hwe, linux-image-generic-lpae-hwe-16.04, linux-headers-lowlatency-hwe-16.04, linux-tools-gcp-lts-18.04, linux-azure-edge, linux-modules-4.15.0-151-generic, linux-tools-generic-hwe-16.04, nic-usb-modules-4.15.0-151-generic-lpae-di, linux-cloud-tools-4.15.0-1109-aws, linux-oracle-headers-4.15.0-1078, fs-secondary-modules-4.15.0-151-generic-lpae-di, linux-headers-4.15.0-151-lowlatency, md-modules-4.15.0-151-generic-di, linux-signed-image-generic-hwe-16.04, linux-image-unsigned-4.15.0-1121-azure, linux-tools-4.15.0-1078-oracle, linux-tools-generic, linux-headers-4.15.0-151, linux-generic-hwe-16.04-edge, linux-headers-4.15.0-1106-gcp, linux-azure, linux-source-4.15.0, linux-image-4.15.0-1121-azure, linux-tools-lowlatency, linux-signed-azure-lts-18.04, linux-modules-4.15.0-151-generic-lpae, block-modules-4.15.0-151-generic-lpae-di, linux-tools-generic-hwe-16.04-edge, linux-modules-extra-aws-lts-18.04, linux-signed-image-azure, fs-core-modules-4.15.0-151-generic-di, linux-image-4.15.0-1092-raspi2, scsi-modules-4.15.0-151-generic-lpae-di, linux-gke, kernel-image-4.15.0-151-generic-lpae-di, linux-tools-generic-lpae-hwe-16.04-edge, linux-generic-lpae-hwe-16.04-edge, linux-buildinfo-4.15.0-1109-aws, linux-signed-generic-hwe-16.04, linux-signed-azure-edge, irda-modules-4.15.0-151-generic-lpae-di, linux-modules-extra-4.15.0-1121-azure, usb-modules-4.15.0-151-generic-di, usb-modules-4.15.0-151-generic-lpae-di, linux-modules-extra-azure, ppp-modules-4.15.0-151-generic-lpae-di, linux-azure-lts-18.04, linux-lowlatency-hwe-16.04-edge, linux-headers-generic-hwe-16.04, linux-image-aws-hwe, linux-headers-generic, linux, linux-image-azure-lts-18.04, linux-oracle, linux-source, linux-headers-lowlatency, nic-modules-4.15.0-151-generic-lpae-di, linux-image-4.15.0-1109-aws, linux-tools-4.15.0-1121-azure, plip-modules-4.15.0-151-generic-lpae-di, nic-shared-modules-4.15.0-151-generic-lpae-di, linux-tools-oracle, linux-aws-headers-4.15.0-1109, linux-gcp-4.15, linux-image-gcp, linux-generic, fs-core-modules-4.15.0-151-generic-lpae-di, linux-tools-4.15.0-1109-snapdragon, linux-image-azure, linux-aws-lts-18.04, linux-tools-4.15.0-151-generic-lpae, linux-hwe, linux-tools-lowlatency-hwe-16.04, linux-cloud-tools-generic, linux-oracle-tools-4.15.0-1078, linux-image-lowlatency-hwe-16.04, linux-generic-lpae, linux-oracle-lts-18.04, linux-image-aws-lts-18.04, linux-headers-4.15.0-151-generic-lpae, linux-signed-generic-hwe-16.04-edge, crypto-modules-4.15.0-151-generic-lpae-di, linux-image-4.15.0-1097-kvm, mouse-modules-4.15.0-151-generic-di, linux-headers-4.15.0-1109-snapdragon, linux-cloud-tools-generic-hwe-16.04-edge, linux-doc, linux-hwe-udebs-generic, linux-image-virtual-hwe-16.04-edge, linux-azure-cloud-tools-4.15.0-1121, linux-tools-aws-lts-18.04, linux-headers-4.15.0-1109-aws, linux-image-kvm, linux-buildinfo-4.15.0-1097-kvm, linux-headers-4.15.0-151-generic, linux-gcp-4.15-headers-4.15.0-1106, storage-core-modules-4.15.0-151-generic-lpae-di, linux-signed-lowlatency-hwe-16.04-edge, linux-image-generic, linux-lowlatency-hwe-16.04, linux-cloud-tools-lowlatency-hwe-16.04-edge, linux-virtual-hwe-16.04-edge, linux-tools-azure-lts-18.04, linux-signed-image-oracle-lts-18.04, linux-tools-virtual, linux-image-extra-virtual-hwe-16.04-edge, linux-buildinfo-4.15.0-1092-raspi2, linux-buildinfo-4.15.0-151-lowlatency, linux-image-oracle-lts-18.04, linux-headers-generic-hwe-16.04-edge, linux-modules-extra-gcp, linux-cloud-tools-4.15.0-1121-azure, linux-signed-image-azure-edge, linux-signed-azure, linux-signed-oem, input-modules-4.15.0-151-generic-lpae-di, linux-image-unsigned-4.15.0-1106-gcp, linux-cloud-tools-azure-lts-18.04, linux-headers-oracle-lts-18.04, linux-tools-oracle-lts-18.04, linux-image-oem, linux-cloud-tools-azure-edge, block-modules-4.15.0-151-generic-di, linux-image-virtual, linux-oem, linux-signed-oracle, linux-headers-azure, linux-aws-hwe-cloud-tools-4.15.0-1109, linux-kvm-tools-4.15.0-1097, linux-gcp-lts-18.04, linux-tools-virtual-hwe-16.04, ipmi-modules-4.15.0-151-generic-lpae-di, linux-image-generic-lpae, linux-headers-lowlatency-hwe-16.04-edge, linux-modules-4.15.0-151-lowlatency, linux-image-raspi2, linux-image-virtual-hwe-16.04, linux-generic-lpae-hwe-16.04, linux-signed-oracle-lts-18.04, linux-headers-aws-lts-18.04, linux-tools-host, linux-tools-gke, virtio-modules-4.15.0-151-generic-di, vlan-modules-4.15.0-151-generic-di, linux-raspi2, linux-buildinfo-4.15.0-151-generic-lpae, linux-headers-raspi2, linux-kvm-headers-4.15.0-1097, linux-modules-extra-azure-edge, floppy-modules-4.15.0-151-generic-di, linux-crashdump, linux-raspi2-headers-4.15.0-1092, linux-image-generic-hwe-16.04, linux-modules-4.15.0-1092-raspi2, linux-headers-kvm, linux-headers-azure-edge, linux-azure-4.15-cloud-tools-4.15.0-1121, linux-headers-azure-lts-18.04, linux-aws-cloud-tools-4.15.0-1109, linux-modules-4.15.0-1109-snapdragon, linux-image-oracle, linux-gcp-headers-4.15.0-1106, linux-image-lowlatency, linux-tools-4.15.0-151-generic, linux-aws-hwe, linux-image-4.15.0-151-lowlatency, pcmcia-storage-modules-4.15.0-151-generic-di, multipath-modules-4.15.0-151-generic-lpae-di, linux-buildinfo-4.15.0-1121-azure, linux-signed-lowlatency-hwe-16.04, linux-tools-common, linux-tools-4.15.0-151, linux-modules-4.15.0-1097-kvm, linux-signed-image-azure-lts-18.04, linux-cloud-tools-lowlatency-hwe-16.04, linux-headers-generic-lpae-hwe-16.04-edge, parport-modules-4.15.0-151-generic-lpae-di, linux-headers-gke, linux-tools-kvm, linux-tools-azure-edge, linux-image-snapdragon, linux-gcp-tools-4.15.0-1106, dasd-extra-modules-4.15.0-151-generic-di, linux-image-4.15.0-151-generic, parport-modules-4.15.0-151-generic-di, linux-headers-virtual-hwe-16.04, linux-signed-image-oem, kernel-signed-image-4.15.0-151-generic-di, linux-virtual, storage-core-modules-4.15.0-151-generic-di, linux-cloud-tools-lowlatency, linux-snapdragon-tools-4.15.0-1109, fs-secondary-modules-4.15.0-151-generic-di, linux-hwe-tools-4.15.0-151, nfs-modules-4.15.0-151-generic-lpae-di, linux-modules-extra-4.15.0-151-generic, crypto-modules-4.15.0-151-generic-di, vlan-modules-4.15.0-151-generic-lpae-di, sata-modules-4.15.0-151-generic-di, serial-modules-4.15.0-151-generic-di, mouse-modules-4.15.0-151-generic-lpae-di, linux-tools-snapdragon, plip-modules-4.15.0-151-generic-di, linux-tools-generic-lpae-hwe-16.04, linux-modules-extra-4.15.0-1106-gcp, linux-udebs-generic, fat-modules-4.15.0-151-generic-di, sata-modules-4.15.0-151-generic-lpae-di, linux-buildinfo-4.15.0-1109-snapdragon, linux-headers-4.15.0-1097-kvm, linux-hwe-cloud-tools-4.15.0-151, linux-tools-oem, linux-modules-extra-aws-hwe, linux-image-lowlatency-hwe-16.04-edge, linux-headers-virtual-hwe-16.04-edge, linux-modules-extra-gke, linux-modules-extra-azure-lts-18.04, linux-modules-4.15.0-1121-azure, linux-tools-4.15.0-1092-raspi2, linux-headers-gcp-lts-18.04, linux-image-4.15.0-1109-snapdragon, linux-signed-image-generic, linux-modules-extra-gcp-lts-18.04, linux-buildinfo-4.15.0-1106-gcp, linux-tools-lowlatency-hwe-16.04-edge, linux-image-generic-lpae-hwe-16.04-edge, linux-headers-oem, linux-lowlatency, linux-signed-image-lowlatency-hwe-16.04-edge, message-modules-4.15.0-151-generic-di, linux-modules-4.15.0-1078-oracle, linux-headers-aws-hwe, linux-cloud-tools-4.15.0-151-lowlatency, linux-tools-4.15.0-151-lowlatency, linux-modules-4.15.0-1106-gcp, linux-cloud-tools-azure, nic-modules-4.15.0-151-generic-di, linux-signed-lowlatency, linux-tools-raspi2, fb-modules-4.15.0-151-generic-di, linux-generic-hwe-16.04, linux-headers-virtual, ppp-modules-4.15.0-151-generic-di, nic-usb-modules-4.15.0-151-generic-di, input-modules-4.15.0-151-generic-di, linux-modules-extra-4.15.0-1078-oracle, linux-signed-image-lowlatency, linux-udebs-generic-lpae, linux-modules-extra-4.15.0-1109-aws, linux-libc-dev, linux-headers-4.15.0-1092-raspi2, linux-azure-4.15-tools-4.15.0-1121, linux-raspi2-tools-4.15.0-1092, linux-gcp-4.15-tools-4.15.0-1106, linux-cloud-tools-virtual, linux-aws-hwe-tools-4.15.0-1109, irda-modules-4.15.0-151-generic-di, linux-headers-generic-lpae-hwe-16.04, linux-headers-oracle, linux-cloud-tools-virtual-hwe-16.04-edge, linux-image-extra-virtual-hwe-16.04, nfs-modules-4.15.0-151-generic-di, linux-cloud-tools-4.15.0-151-generic, ipmi-modules-4.15.0-151-generic-di, linux-tools-virtual-hwe-16.04-edge, linux-aws-tools-4.15.0-1109, linux-image-unsigned-4.15.0-151-generic, fat-modules-4.15.0-151-generic-lpae-di, linux-image-4.15.0-1078-oracle, linux-virtual-hwe-16.04, pata-modules-4.15.0-151-generic-di, linux-signed-generic, linux-buildinfo-4.15.0-1078-oracle, linux-tools-generic-lpae, linux-modules-4.15.0-1109-aws, multipath-modules-4.15.0-151-generic-di, linux-azure-4.15-headers-4.15.0-1121, linux-cloud-tools-virtual-hwe-16.04, linux-tools-gcp, linux-azure-tools-4.15.0-1121