VARIoT IoT vulnerabilities database
| VAR-202406-2134 | CVE-2024-5990 | Rockwell Automation of thinmanager and thinserver Vulnerability in |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation ThinServer™ and cause a denial-of-service condition on the affected device. Rockwell Automation of thinmanager and thinserver Exists in unspecified vulnerabilities.Service operation interruption (DoS) It may be in a state. Rockwell Automation ThinManager is a thin client management software from Rockwell Automation, USA. It allows thin clients to be assigned to multiple remote desktop servers at the same time
| VAR-202406-2530 | CVE-2024-5989 | Rockwell Automation of thinmanager and thinserver Vulnerability in |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™. Rockwell Automation of thinmanager and thinserver Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Rockwell Automation ThinManager is a thin client management software from Rockwell Automation, USA. It allows thin clients to be assigned to multiple remote desktop servers at the same time
| VAR-202406-0976 | CVE-2024-5988 | Rockwell Automation of thinmanager and thinserver Vulnerability in |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™. Rockwell Automation of thinmanager and thinserver Exists in unspecified vulnerabilities.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Rockwell Automation ThinManager is a thin client management software from Rockwell Automation, USA. It allows thin clients to be assigned to multiple remote desktop servers at the same time
| VAR-202406-2167 | CVE-2024-39468 | Linux of Linux Kernel resource locking vulnerability in |
CVSS V2: 7.2 CVSS V3: 5.5 Severity: MEDIUM |
In the Linux kernel, the following vulnerability has been resolved:
smb: client: fix deadlock in smb2_find_smb_tcon()
Unlock cifs_tcp_ses_lock before calling cifs_put_smb_ses() to avoid such
deadlock. Linux of Linux Kernel contains a resource locking vulnerability.Service operation interruption (DoS) It may be in a state. The RUGGEDCOM RST2428P is a Layer 2 Ethernet switch based on SINEC OS with up to 28 non-blocking interfaces. SCALANCE X switches are used to connect industrial components such as programmable logic controllers (PLCs) and human-machine interfaces (HMIs).
Multiple vulnerabilities exist in third-party components prior to SIEMENS SINEC OS V3.2. These vulnerabilities could be exploited to corrupt values, leading to undefined behavior or security issues
| VAR-202406-0858 | CVE-2024-21827 | TP-LINK Technologies of er7206 Active state debug code vulnerability in firmware |
CVSS V2: 8.3 CVSS V3: 7.2 Severity: HIGH |
A leftover debug code vulnerability exists in the cli_server debug functionality of Tp-Link ER7206 Omada Gigabit VPN Router 1.4.1 Build 20240117 Rel.57421. A specially crafted series of network requests can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger this vulnerability. TP-LINK Technologies of er7206 An active debug code vulnerability exists in the firmware.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. TP-LINK ER7206 is a multi-function gigabit router from China's TP-LINK company. The vulnerability is caused by the presence of residual debugging code
| VAR-202406-1771 | CVE-2024-4641 | plural Moxa Inc. Product Format String Vulnerability |
CVSS V2: 6.5 CVSS V3: 6.3 Severity: MEDIUM |
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to accepting a format string from an external source as an argument. An attacker could modify an externally controlled format string to cause a memory leak and denial of service. ONCELLG3470A-LTE-EU-T firmware, ONCELLG3470A-LTE-EU firmware, OnCellG3470A-LTE-US-T firmware etc. Moxa Inc. The product contains a vulnerability in format strings.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. MOXA OnCell G3470A-LTE is a series of cellular gateways/routers from China's MOXA company.
MOXA OnCell G3470A-LTE v1.7.7 and earlier firmware versions have a security vulnerability
| VAR-202406-2348 | CVE-2024-4640 | plural Moxa Inc. Classic buffer overflow vulnerability in the product |
CVSS V2: 7.5 CVSS V3: 7.1 Severity: HIGH |
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to missing bounds checking on buffer operations. An attacker could write past the boundaries of allocated buffer regions in memory, causing a program crash. ONCELLG3470A-LTE-EU-T firmware, ONCELLG3470A-LTE-EU firmware, OnCellG3470A-LTE-US-T firmware etc. Moxa Inc. The product contains a classic buffer overflow vulnerability.Information is tampered with and service operation is interrupted (DoS) It may be in a state. MOXA OnCell G3470A-LTE is a series of cellular gateways/routers from China's MOXA company.
MOXA OnCell G3470A-LTE v1.7.7 and earlier firmware versions have a buffer overflow vulnerability. The vulnerability is caused by the lack of boundary checks on buffer operations
| VAR-202406-2773 | CVE-2024-4639 | plural Moxa Inc. Command injection vulnerabilities in the product |
CVSS V2: 7.5 CVSS V3: 7.1 Severity: HIGH |
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in IPSec configuration. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands. ONCELLG3470A-LTE-EU-T firmware, ONCELLG3470A-LTE-EU firmware, OnCellG3470A-LTE-US-T firmware etc. Moxa Inc. The product contains a command injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. MOXA OnCell G3470A-LTE is a series of cellular gateways/routers from China's MOXA company.
MOXA OnCell G3470A-LTE v1.7.7 and earlier firmware versions have a command injection vulnerability
| VAR-202406-1003 | CVE-2024-4638 | plural Moxa Inc. Command injection vulnerabilities in the product |
CVSS V2: 7.5 CVSS V3: 7.1 Severity: HIGH |
OnCell G3470A-LTE Series firmware versions v1.7.7 and prior have been identified as vulnerable due to a lack of neutralized inputs in the web key upload function. An attacker could modify the intended commands sent to target functions, which could cause malicious users to execute unauthorized commands. ONCELLG3470A-LTE-EU-T firmware, ONCELLG3470A-LTE-EU firmware, OnCellG3470A-LTE-US firmware etc. Moxa Inc. The product contains a command injection vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. MOXA OnCell G3470A-LTE is a series of cellular gateways/routers from China's MOXA company.
MOXA OnCell G3470A-LTE v1.7.7 and earlier firmware versions have a command injection vulnerability
| VAR-202406-1180 | No CVE | Zhejiang Dahua Technology Co., Ltd. Digital Surveillance System has a file upload vulnerability |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
Zhejiang Dahua Technology Co., Ltd. is a global leading video-centric smart IoT solution provider and operation service provider.
Zhejiang Dahua Technology Co., Ltd. Digital Surveillance System has a file upload vulnerability, which can be exploited by attackers to upload malicious files.
| VAR-202406-1413 | CVE-2024-38902 | H3C of Magic R230 Hardcoded password usage vulnerability in firmware |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
H3C Magic R230 V100R002 was discovered to contain a hardcoded password vulnerability in /etc/shadow, which allows attackers to log in as root. H3C of Magic R230 A vulnerability exists in the firmware related to the use of hardcoded passwords.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Magic R230 is a wireless router from H3C, a Chinese company.
H3C Technologies Co., Ltd
| VAR-202406-1019 | CVE-2024-38897 | WAVLINK of wn551k1 Firmware vulnerability regarding disclosure of important information from data queries |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
WAVLINK WN551K1'live_check.shtml enables attackers to obtain sensitive router information. WAVLINK of wn551k1 The firmware contains a vulnerability that could lead to the disclosure of sensitive information through data queries.Information may be obtained. WAVLINK WN551K1 is a wireless router from WAVLINK, a Chinese company.
WAVLINK WN551K1 has an information leakage vulnerability. The vulnerability is caused by improper authorization in the live_check.shtml interface
| VAR-202406-1207 | CVE-2024-38896 | WAVLINK of WL-WN551K1 Command injection vulnerability in firmware |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
WAVLINK WN551K1 found a command injection vulnerability through the start_hour parameter of /cgi-bin/nightled.cgi. WAVLINK WN551K1 is a wireless router from WAVLINK, a Chinese company. No detailed vulnerability details are currently available
| VAR-202406-2575 | CVE-2024-38895 | WAVLINK of WL-WN551K1 Firmware vulnerability regarding disclosure of important information from data queries |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
WAVLINK WN551K1'live_mfg.shtml enables attackers to obtain sensitive router information. WAVLINK of WL-WN551K1 The firmware contains a vulnerability that could lead to the disclosure of sensitive information through data queries.Information may be obtained. WAVLINK WN551K1 is a wireless router from WAVLINK, a Chinese company.
WAVLINK WN551K1 has an information leakage vulnerability. The vulnerability is caused by improper authorization in the live_mfg.shtml interface
| VAR-202406-1781 | CVE-2024-38894 | WAVLINK of WL-WN551K1 Command injection vulnerability in firmware |
CVSS V2: 5.0 CVSS V3: 5.3 Severity: MEDIUM |
WAVLINK WN551K1 found a command injection vulnerability through the IP parameter of /cgi-bin/touchlist_sync.cgi. WAVLINK WN551K1 is a wireless router from WAVLINK, a Chinese company. No detailed vulnerability details are currently available
| VAR-202406-1782 | CVE-2024-38892 | WAVLINK of WL-WN551K1 Firmware vulnerability regarding disclosure of important information from data queries |
CVSS V2: 6.1 CVSS V3: 6.5 Severity: MEDIUM |
An issue in Wavlink WN551K1 allows a remote attacker to obtain sensitive information via the ExportAllSettings.sh component. WAVLINK of WL-WN551K1 The firmware contains a vulnerability that could lead to the disclosure of sensitive information through data queries.Information may be obtained. WAVLINK WN551K1 is a wireless router from WAVLINK, a Chinese company.
WAVLINK WN551K1 has an information leakage vulnerability
| VAR-202406-2036 | CVE-2024-33278 | ASUS RT-AX88U Buffer Overflow Vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
Buffer Overflow vulnerability in ASUS router RT-AX88U with firmware versions v3.0.0.4.388_24198 allows a remote attacker to execute arbitrary code via the connection_state_machine due to improper length validation for the cookie field. ASUS RT-AX88U is a wireless router from ASUS, a Chinese company.
ASUS RT-AX88U v3.0.0.4.388_24198 has a buffer overflow vulnerability, which is caused by a boundary error when the application processes untrusted input
| VAR-202406-0831 | CVE-2024-38780 | Linux of Linux Kernel resource locking vulnerability in |
CVSS V2: 7.2 CVSS V3: 5.5 Severity: MEDIUM |
In the Linux kernel, the following vulnerability has been resolved:
dma-buf/sw-sync: don't enable IRQ from sync_print_obj()
Since commit a6aa8fca4d79 ("dma-buf/sw-sync: Reduce irqsave/irqrestore from
known context") by error replaced spin_unlock_irqrestore() with
spin_unlock_irq() for both sync_debugfs_show() and sync_print_obj() despite
sync_print_obj() is called from sync_debugfs_show(), lockdep complains
inconsistent lock state warning.
Use plain spin_{lock,unlock}() for sync_print_obj(), for
sync_debugfs_show() is already using spin_{lock,unlock}_irq(). Linux of Linux Kernel contains a resource locking vulnerability.Service operation interruption (DoS) It may be in a state. The RUGGEDCOM RST2428P is a Layer 2 Ethernet switch based on the SINEC operating system with up to 28 non-blocking interfaces.
SCALANCE X switches are used to connect industrial components such as programmable logic controllers (PLCs) or human-machine interfaces (HMIs).
Multiple vulnerabilities in third-party components of Siemens' SINEC OS could allow attackers to gain control of the server
| VAR-202406-0959 | CVE-2024-38662 | Linux of Linux Kernel Vulnerability in |
CVSS V2: 7.2 CVSS V3: 4.7 Severity: MEDIUM |
In the Linux kernel, the following vulnerability has been resolved:
bpf: Allow delete from sockmap/sockhash only if update is allowed
We have seen an influx of syzkaller reports where a BPF program attached to
a tracepoint triggers a locking rule violation by performing a map_delete
on a sockmap/sockhash.
We don't intend to support this artificial use scenario. Extend the
existing verifier allowed-program-type check for updating sockmap/sockhash
to also cover deleting from a map.
From now on only BPF programs which were previously allowed to update
sockmap/sockhash can delete from these map types. Linux of Linux Kernel Exists in unspecified vulnerabilities.Information may be tampered with. The RUGGEDCOM RST2428P is a Layer 2 Ethernet switch based on the SINEC operating system with up to 28 non-blocking interfaces.
SCALANCE X switches are used to connect industrial components such as programmable logic controllers (PLCs) or human-machine interfaces (HMIs).
Multiple vulnerabilities in third-party components of Siemens' SINEC OS could allow attackers to gain control of the server
| VAR-202406-0906 | CVE-2024-36288 | Linux of Linux Kernel Infinite loop vulnerability in |
CVSS V2: 7.2 CVSS V3: 5.5 Severity: MEDIUM |
In the Linux kernel, the following vulnerability has been resolved:
SUNRPC: Fix loop termination condition in gss_free_in_token_pages()
The in_token->pages[] array is not NULL terminated. This results in
the following KASAN splat:
KASAN: maybe wild-memory-access in range [0x04a2013400000008-0x04a201340000000f]. Linux of Linux Kernel Exists in an infinite loop vulnerability.Service operation interruption (DoS) It may be in a state. The RUGGEDCOM RST2428P is a Layer 2 Ethernet switch based on the SINEC operating system with up to 28 non-blocking interfaces.
SCALANCE X switches are used to connect industrial components such as programmable logic controllers (PLCs) or human-machine interfaces (HMIs).
Multiple vulnerabilities in third-party components of Siemens' SINEC OS could allow attackers to gain control of the server.
==========================================================================
Ubuntu Security Notice USN-6999-1
September 11, 2024
linux, linux-aws, linux-gcp, linux-gke, linux-ibm, linux-lowlatency,
linux-oem-6.8, linux-oracle vulnerabilities
==========================================================================
A security issue affects these releases of Ubuntu and its derivatives:
- Ubuntu 24.04 LTS
Summary:
Several security issues were fixed in the Linux kernel.
Software Description:
- linux: Linux kernel
- linux-aws: Linux kernel for Amazon Web Services (AWS) systems
- linux-gcp: Linux kernel for Google Cloud Platform (GCP) systems
- linux-gke: Linux kernel for Google Container Engine (GKE) systems
- linux-ibm: Linux kernel for IBM cloud systems
- linux-lowlatency: Linux low latency kernel
- linux-oem-6.8: Linux kernel for OEM systems
- linux-oracle: Linux kernel for Oracle Cloud systems
Details:
Chenyuan Yang discovered that the CEC driver driver in the Linux kernel
contained a use-after-free vulnerability. A local attacker could use this
to cause a denial of service (system crash) or possibly execute arbitrary
code. (CVE-2024-23848)
It was discovered that the JFS file system contained an out-of-bounds read
vulnerability when printing xattr debug information. A local attacker could
use this to cause a denial of service (system crash). (CVE-2024-40902)
Several security issues were discovered in the Linux kernel.
An attacker could possibly use these to compromise the system.
This update corrects flaws in the following subsystems:
- ARM64 architecture;
- MIPS architecture;
- PA-RISC architecture;
- PowerPC architecture;
- RISC-V architecture;
- x86 architecture;
- Block layer subsystem;
- ACPI drivers;
- Drivers core;
- Null block device driver;
- Character device driver;
- TPM device driver;
- Clock framework and drivers;
- CPU frequency scaling framework;
- Hardware crypto device drivers;
- CXL (Compute Express Link) drivers;
- Buffer Sharing and Synchronization framework;
- DMA engine subsystem;
- EFI core;
- FPGA Framework;
- GPU drivers;
- Greybus drivers;
- HID subsystem;
- HW tracing;
- I2C subsystem;
- IIO subsystem;
- InfiniBand drivers;
- Input Device (Mouse) drivers;
- Mailbox framework;
- Media drivers;
- Microchip PCI driver;
- VMware VMCI Driver;
- Network drivers;
- PCI subsystem;
- x86 platform drivers;
- PTP clock framework;
- S/390 drivers;
- SCSI drivers;
- SoundWire subsystem;
- Sonic Silicon Backplane drivers;
- Greybus lights staging drivers;
- Thermal drivers;
- TTY drivers;
- USB subsystem;
- VFIO drivers;
- Framebuffer layer;
- Watchdog drivers;
- 9P distributed file system;
- BTRFS file system;
- File systems infrastructure;
- Ext4 file system;
- F2FS file system;
- JFS file system;
- Network file system server daemon;
- NILFS2 file system;
- NTFS3 file system;
- SMB network file system;
- Tracing file system;
- Tracing infrastructure;
- io_uring subsystem;
- Core kernel;
- BPF subsystem;
- Kernel debugger infrastructure;
- DMA mapping infrastructure;
- IRQ subsystem;
- Memory management;
- 9P file system network protocol;
- Amateur Radio drivers;
- B.A.T.M.A.N. meshing protocol;
- Ethernet bridge;
- Networking core;
- Ethtool driver;
- IPv4 networking;
- IPv6 networking;
- MAC80211 subsystem;
- Multipath TCP;
- Netfilter;
- NET/ROM layer;
- NFC subsystem;
- Network traffic control;
- Sun RPC protocol;
- TIPC protocol;
- TLS protocol;
- Unix domain sockets;
- Wireless networking;
- XFRM subsystem;
- AppArmor security module;
- Integrity Measurement Architecture(IMA) framework;
- Landlock security;
- Linux Security Modules (LSM) Framework;
- SELinux security module;
- Simplified Mandatory Access Control Kernel framework;
- ALSA framework;
- HD-audio driver;
- SOF drivers;
- KVM core;
(CVE-2024-40911, CVE-2024-37356, CVE-2024-40935, CVE-2024-40944,
CVE-2024-41003, CVE-2024-40990, CVE-2024-40952, CVE-2024-40940,
CVE-2024-40930, CVE-2024-40985, CVE-2024-40941, CVE-2024-38630,
CVE-2024-39466, CVE-2024-40933, CVE-2024-38624, CVE-2024-40924,
CVE-2024-40945, CVE-2024-40899, CVE-2024-38622, CVE-2024-40979,
CVE-2024-36484, CVE-2024-41004, CVE-2024-39474, CVE-2022-48772,
CVE-2024-36244, CVE-2024-38664, CVE-2024-40925, CVE-2024-40980,
CVE-2024-39480, CVE-2024-36270, CVE-2024-40936, CVE-2024-40904,
CVE-2024-38635, CVE-2024-40927, CVE-2024-36481, CVE-2024-40929,
CVE-2024-40958, CVE-2024-36978, CVE-2024-40992, CVE-2024-40908,
CVE-2024-39504, CVE-2024-41001, CVE-2024-40967, CVE-2023-52884,
CVE-2024-40997, CVE-2024-40903, CVE-2024-40913, CVE-2024-34030,
CVE-2024-39473, CVE-2024-40966, CVE-2024-40951, CVE-2024-40902,
CVE-2024-40982, CVE-2024-40923, CVE-2024-39467, CVE-2024-40910,
CVE-2024-40909, CVE-2024-39463, CVE-2024-40974, CVE-2024-41002,
CVE-2024-39464, CVE-2024-39496, CVE-2024-41040, CVE-2024-39469,
CVE-2024-39500, CVE-2024-39510, CVE-2024-38627, CVE-2024-32936,
CVE-2024-40975, CVE-2024-38390, CVE-2024-40959, CVE-2024-41006,
CVE-2024-40986, CVE-2024-40987, CVE-2024-40922, CVE-2024-40983,
CVE-2024-37354, CVE-2024-38637, CVE-2024-39277, CVE-2024-40943,
CVE-2024-39371, CVE-2024-40921, CVE-2024-40953, CVE-2024-38634,
CVE-2024-38659, CVE-2024-39492, CVE-2024-40976, CVE-2024-40906,
CVE-2024-40965, CVE-2024-38667, CVE-2024-39498, CVE-2024-38628,
CVE-2024-38661, CVE-2024-38663, CVE-2024-40998, CVE-2024-40948,
CVE-2024-38306, CVE-2024-40928, CVE-2024-39468, CVE-2024-39494,
CVE-2024-39505, CVE-2024-40963, CVE-2024-39499, CVE-2024-39506,
CVE-2024-40995, CVE-2024-39491, CVE-2024-40900, CVE-2024-39478,
CVE-2024-39490, CVE-2024-39291, CVE-2024-40981, CVE-2024-40926,
CVE-2024-40939, CVE-2024-38385, CVE-2024-39483, CVE-2024-40989,
CVE-2024-40955, CVE-2024-39501, CVE-2024-38381, CVE-2024-33621,
CVE-2024-40964, CVE-2024-42148, CVE-2024-36286, CVE-2024-38629,
CVE-2024-39509, CVE-2024-39298, CVE-2024-36489, CVE-2024-34777,
CVE-2024-40957, CVE-2024-40919, CVE-2024-39462, CVE-2024-39495,
CVE-2024-39497, CVE-2024-38636, CVE-2024-36281, CVE-2024-39479,
CVE-2024-40932, CVE-2024-36288, CVE-2024-38623, CVE-2024-40969,
CVE-2024-40931, CVE-2024-36971, CVE-2024-40934, CVE-2024-36015,
CVE-2024-39485, CVE-2024-40996, CVE-2024-39507, CVE-2024-36973,
CVE-2024-38625, CVE-2024-39301, CVE-2024-34027, CVE-2024-37026,
CVE-2024-40960, CVE-2024-37078, CVE-2024-40912, CVE-2024-40988,
CVE-2024-41005, CVE-2024-39276, CVE-2024-38662, CVE-2024-39502,
CVE-2024-36479, CVE-2024-40947, CVE-2024-38780, CVE-2024-38388,
CVE-2024-40917, CVE-2024-36974, CVE-2024-40970, CVE-2024-40901,
CVE-2024-38384, CVE-2024-39475, CVE-2024-40949, CVE-2024-37021,
CVE-2024-38633, CVE-2024-39503, CVE-2024-41000, CVE-2024-33847,
CVE-2024-35247, CVE-2024-40968, CVE-2024-33619, CVE-2024-38619,
CVE-2024-40984, CVE-2024-36478, CVE-2024-39493, CVE-2024-42078,
CVE-2024-40954, CVE-2024-40978, CVE-2024-39508, CVE-2024-40915,
CVE-2024-39489, CVE-2024-40920, CVE-2024-38618, CVE-2024-40938,
CVE-2024-39296, CVE-2024-40962, CVE-2024-39470, CVE-2024-39481,
CVE-2024-40977, CVE-2024-38621, CVE-2024-40971, CVE-2024-31076,
CVE-2024-36972, CVE-2024-39471, CVE-2024-40994, CVE-2024-40973,
CVE-2024-40916, CVE-2024-40942, CVE-2024-40956, CVE-2024-39465,
CVE-2024-40914, CVE-2024-40937, CVE-2024-40918, CVE-2024-40905,
CVE-2024-39488, CVE-2024-38632, CVE-2024-39461, CVE-2024-40999,
CVE-2024-40972, CVE-2024-36477, CVE-2024-40961)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 24.04 LTS
linux-image-6.8.0-1010-gke 6.8.0-1010.13
linux-image-6.8.0-1012-ibm 6.8.0-1012.12
linux-image-6.8.0-1012-oem 6.8.0-1012.12
linux-image-6.8.0-1012-oracle 6.8.0-1012.12
linux-image-6.8.0-1012-oracle-64k 6.8.0-1012.12
linux-image-6.8.0-1014-gcp 6.8.0-1014.16
linux-image-6.8.0-1015-aws 6.8.0-1015.16
linux-image-6.8.0-44-generic 6.8.0-44.44
linux-image-6.8.0-44-generic-64k 6.8.0-44.44
linux-image-6.8.0-44-lowlatency 6.8.0-44.44.1
linux-image-6.8.0-44-lowlatency-64k 6.8.0-44.44.1
linux-image-aws 6.8.0-1015.16
linux-image-gcp 6.8.0-1014.16
linux-image-generic 6.8.0-44.44
linux-image-generic-64k 6.8.0-44.44
linux-image-generic-64k-hwe-24.04 6.8.0-44.44
linux-image-generic-hwe-24.04 6.8.0-44.44
linux-image-generic-lpae 6.8.0-44.44
linux-image-gke 6.8.0-1010.13
linux-image-ibm 6.8.0-1012.12
linux-image-ibm-classic 6.8.0-1012.12
linux-image-ibm-lts-24.04 6.8.0-1012.12
linux-image-kvm 6.8.0-44.44
linux-image-lowlatency 6.8.0-44.44.1
linux-image-lowlatency-64k 6.8.0-44.44.1
linux-image-oracle 6.8.0-1012.12
linux-image-oracle-64k 6.8.0-1012.12
linux-image-virtual 6.8.0-44.44
linux-image-virtual-hwe-24.04 6.8.0-44.44
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well.
References:
https://ubuntu.com/security/notices/USN-6999-1
CVE-2022-48772, CVE-2023-52884, CVE-2024-23848, CVE-2024-31076,
CVE-2024-32936, CVE-2024-33619, CVE-2024-33621, CVE-2024-33847,
CVE-2024-34027, CVE-2024-34030, CVE-2024-34777, CVE-2024-35247,
CVE-2024-36015, CVE-2024-36244, CVE-2024-36270, CVE-2024-36281,
CVE-2024-36286, CVE-2024-36288, CVE-2024-36477, CVE-2024-36478,
CVE-2024-36479, CVE-2024-36481, CVE-2024-36484, CVE-2024-36489,
CVE-2024-36971, CVE-2024-36972, CVE-2024-36973, CVE-2024-36974,
CVE-2024-36978, CVE-2024-37021, CVE-2024-37026, CVE-2024-37078,
CVE-2024-37354, CVE-2024-37356, CVE-2024-38306, CVE-2024-38381,
CVE-2024-38384, CVE-2024-38385, CVE-2024-38388, CVE-2024-38390,
CVE-2024-38618, CVE-2024-38619, CVE-2024-38621, CVE-2024-38622,
CVE-2024-38623, CVE-2024-38624, CVE-2024-38625, CVE-2024-38627,
CVE-2024-38628, CVE-2024-38629, CVE-2024-38630, CVE-2024-38632,
CVE-2024-38633, CVE-2024-38634, CVE-2024-38635, CVE-2024-38636,
CVE-2024-38637, CVE-2024-38659, CVE-2024-38661, CVE-2024-38662,
CVE-2024-38663, CVE-2024-38664, CVE-2024-38667, CVE-2024-38780,
CVE-2024-39276, CVE-2024-39277, CVE-2024-39291, CVE-2024-39296,
CVE-2024-39298, CVE-2024-39301, CVE-2024-39371, CVE-2024-39461,
CVE-2024-39462, CVE-2024-39463, CVE-2024-39464, CVE-2024-39465,
CVE-2024-39466, CVE-2024-39467, CVE-2024-39468, CVE-2024-39469,
CVE-2024-39470, CVE-2024-39471, CVE-2024-39473, CVE-2024-39474,
CVE-2024-39475, CVE-2024-39478, CVE-2024-39479, CVE-2024-39480,
CVE-2024-39481, CVE-2024-39483, CVE-2024-39485, CVE-2024-39488,
CVE-2024-39489, CVE-2024-39490, CVE-2024-39491, CVE-2024-39492,
CVE-2024-39493, CVE-2024-39494, CVE-2024-39495, CVE-2024-39496,
CVE-2024-39497, CVE-2024-39498, CVE-2024-39499, CVE-2024-39500,
CVE-2024-39501, CVE-2024-39502, CVE-2024-39503, CVE-2024-39504,
CVE-2024-39505, CVE-2024-39506, CVE-2024-39507, CVE-2024-39508,
CVE-2024-39509, CVE-2024-39510, CVE-2024-40899, CVE-2024-40900,
CVE-2024-40901, CVE-2024-40902, CVE-2024-40903, CVE-2024-40904,
CVE-2024-40905, CVE-2024-40906, CVE-2024-40908, CVE-2024-40909,
CVE-2024-40910, CVE-2024-40911, CVE-2024-40912, CVE-2024-40913,
CVE-2024-40914, CVE-2024-40915, CVE-2024-40916, CVE-2024-40917,
CVE-2024-40918, CVE-2024-40919, CVE-2024-40920, CVE-2024-40921,
CVE-2024-40922, CVE-2024-40923, CVE-2024-40924, CVE-2024-40925,
CVE-2024-40926, CVE-2024-40927, CVE-2024-40928, CVE-2024-40929,
CVE-2024-40930, CVE-2024-40931, CVE-2024-40932, CVE-2024-40933,
CVE-2024-40934, CVE-2024-40935, CVE-2024-40936, CVE-2024-40937,
CVE-2024-40938, CVE-2024-40939, CVE-2024-40940, CVE-2024-40941,
CVE-2024-40942, CVE-2024-40943, CVE-2024-40944, CVE-2024-40945,
CVE-2024-40947, CVE-2024-40948, CVE-2024-40949, CVE-2024-40951,
CVE-2024-40952, CVE-2024-40953, CVE-2024-40954, CVE-2024-40955,
CVE-2024-40956, CVE-2024-40957, CVE-2024-40958, CVE-2024-40959,
CVE-2024-40960, CVE-2024-40961, CVE-2024-40962, CVE-2024-40963,
CVE-2024-40964, CVE-2024-40965, CVE-2024-40966, CVE-2024-40967,
CVE-2024-40968, CVE-2024-40969, CVE-2024-40970, CVE-2024-40971,
CVE-2024-40972, CVE-2024-40973, CVE-2024-40974, CVE-2024-40975,
CVE-2024-40976, CVE-2024-40977, CVE-2024-40978, CVE-2024-40979,
CVE-2024-40980, CVE-2024-40981, CVE-2024-40982, CVE-2024-40983,
CVE-2024-40984, CVE-2024-40985, CVE-2024-40986, CVE-2024-40987,
CVE-2024-40988, CVE-2024-40989, CVE-2024-40990, CVE-2024-40992,
CVE-2024-40994, CVE-2024-40995, CVE-2024-40996, CVE-2024-40997,
CVE-2024-40998, CVE-2024-40999, CVE-2024-41000, CVE-2024-41001,
CVE-2024-41002, CVE-2024-41003, CVE-2024-41004, CVE-2024-41005,
CVE-2024-41006, CVE-2024-41040, CVE-2024-42078, CVE-2024-42148
Package Information:
https://launchpad.net/ubuntu/+source/linux/6.8.0-44.44
https://launchpad.net/ubuntu/+source/linux-aws/6.8.0-1015.16
https://launchpad.net/ubuntu/+source/linux-gcp/6.8.0-1014.16
https://launchpad.net/ubuntu/+source/linux-gke/6.8.0-1010.13
https://launchpad.net/ubuntu/+source/linux-ibm/6.8.0-1012.12
https://launchpad.net/ubuntu/+source/linux-lowlatency/6.8.0-44.44.1
https://launchpad.net/ubuntu/+source/linux-oem-6.8/6.8.0-1012.12
https://launchpad.net/ubuntu/+source/linux-oracle/6.8.0-1012.12