Advisory: CLSA-2025:1747431461
OS: Ubuntu 16.04 ELS
Public date: 2025-05-16 21:37:43
Project: linux-hwe
Version: 4.15.0-247.258~16.04.1
Errata link: https://errata.tuxcare.com/els_os/ubuntu16.04els/CLSA-2025-1747431461.html
[ Ubuntu: 4.15.0-247.258 ] * CVE-url: https://ubuntu.com/security/CVE-2021-47352 - virtio-net: Add validation for used length * CVE-url: https://ubuntu.com/security/CVE-2024-46745 - Input: uinput - reject requests with unreasonable number of slots * CVE-url: https://ubuntu.com/security/CVE-2024-44952 - driver core: Fix uevent_show() vs driver detach race * CVE-url: https://ubuntu.com/security/CVE-2024-42304 - ext4: make sure the first directory block is not a hole * CVE-url: https://ubuntu.com/security/CVE-2024-42305 - ext4: check dot and dotdot of dx_root before making dir indexed * CVE-url: https://ubuntu.com/security/CVE-2024-53168 - sunrpc: fix one UAF issue caused by sunrpc kernel tcp socket * CVE-url: https://ubuntu.com/security/CVE-2024-49925 - driver core: add dev_groups to all drivers - driver core: Fix error return code in really_probe() - fbdev: efifb: Register sysfs groups through driver core * CVE-url: https://ubuntu.com/security/CVE-2024-56661 - tipc: fix NULL deref in cleanup_bearer() * CVE-url: https://ubuntu.com/security/CVE-2024-56642 - tipc: Fix use-after-free of kernel socket in cleanup_bearer(). * CVE-url: https://ubuntu.com/security/CVE-2021-47163 - tipc: wait and exit until all work queues are done * CVE-url: https://ubuntu.com/security/CVE-2024-26915 - drm/amdgpu: fix IH overflow on Vega10 v2 - drm/amdgpu: Add check to prevent IH overflow - drm/amdgpu: Reset IH OVERFLOW_CLEAR bit * CVE-url: https://ubuntu.com/security/CVE-2024-56770 - net/sched: netem: account for backlog updates from child qdisc - netem: Update sch->q.qlen before qdisc_tree_reduce_backlog() * CVE-url: https://ubuntu.com/security/CVE-2024-50296 - net: hns3: fix kernel crash when uninstalling driver * CVE-url: https://ubuntu.com/security/CVE-2024-53066 - nfs: Fix KMSAN warning in decode_getfattr_attrs() * CVE-url: https://ubuntu.com/security/CVE-2024-49944 - sctp: set sk_state back to CLOSED if autobind fails in sctp_listen_start * CVE-url: https://ubuntu.com/security/CVE-2024-50237 - wifi: mac80211: do not pass a stopped vif to the driver in .get_txpower * CVE-url: https://ubuntu.com/security/CVE-2024-46780 - nilfs2: protect references to superblock parameters exposed in sysfs * CVE-url: https://ubuntu.com/security/CVE-2024-53063 - media: dvbdev: prevent the risk of out of memory access - media: dvbdev: fix the logic when DVB_DYNAMIC_MINORS is not set * CVE-url: https://ubuntu.com/security/CVE-2023-52927 - netfilter: allow exp not to be removed in nf_ct_find_expectation * CVE-url: https://ubuntu.com/security/CVE-2021-47150 - net: fec: fix the potential memory leak in fec_enet_init() * CVE-url: https://ubuntu.com/security/CVE-2024-53140 - netlink: terminate outstanding dump on socket close * CVE-url: https://ubuntu.com/security/CVE-2025-21971 - net_sched: Prevent creation of classes with TC_H_ROOT * CVE-url: https://ubuntu.com/security/CVE-2025-37785 - ext4: fix OOB read when checking dotdot dir * CVE-url: https://ubuntu.com/security/CVE-2023-52572 - cifs: Fix UAF in cifs_demultiplex_thread() * CVE-url: https://ubuntu.com/security/CVE-2022-49738 - f2fs: fix to do sanity check on summary info - f2fs: should put a page when checking the summary info - f2fs: fix to do sanity check on i_extra_isize in is_alive() * CVE-url: https://ubuntu.com/security/CVE-2022-49740 - wifi: brcmfmac: Check the count value of channel spec to prevent out-of- bounds reads * CVE-url: https://ubuntu.com/security/ - ipv6: Define dscp_t and stop taking ECN bits into account in fib6-rules * CVE-url: https://ubuntu.com/security/CVE-2023-53020 - l2tp: close all race conditions in l2tp_tunnel_register() * CVE-url: https://ubuntu.com/security/CVE-2025-21957 - scsi: qla1280: Fix kernel oops when debug level > 2 * CVE-url: https://ubuntu.com/security/CVE-2025-21948 - HID: appleir: Fix potential NULL dereference at raw event handle * CVE-url: https://ubuntu.com/security/CVE-2023-52936 - debugfs: add debugfs_lookup_and_remove() - kernel/irq/irqdomain.c: fix memory leak with using debugfs_lookup() * CVE-url: https://ubuntu.com/security/CVE-2025-21912 - gpio: rcar: Use raw_spinlock to protect register access * CVE-url: https://ubuntu.com/security/CVE-2025-21922 - ppp: Fix KMSAN uninit-value warning with bpf * CVE-url: https://ubuntu.com/security/CVE-2025-21891 - ipvlan: ensure network headers are in skb linear part * CVE-url: https://ubuntu.com/security/CVE-2025-21959 - netfilter: nf_conncount: Fully initialize struct nf_conncount_tuple in insert_tree() * CVE-url: https://ubuntu.com/security/CVE-2025-21996 - drm/radeon: fix uninitialized size issue in radeon_vce_cs_parse() * CVE-url: https://ubuntu.com/security/CVE-2025-21928 - HID: intel-ish-hid: Fix use-after-free issue in ishtp_hid_remove() * CVE-url: https://ubuntu.com/security/CVE-2025-21917 - usb: renesas_usbhs: Flush the notify_hotplug_work * CVE-url: https://ubuntu.com/security/CVE-2023-53001 - drm/drm_vma_manager: Add drm_vma_node_allow_once() * CVE-url: https://ubuntu.com/security/CVE-2025-21969 - Bluetooth: L2CAP: Fix slab-use-after-free Read in l2cap_send_cmd * CVE-url: https://ubuntu.com/security/CVE-2025-21920 - vlan: enforce underlying device type * CVE-url: https://ubuntu.com/security/CVE-2025-21904 - caif_virtio: fix wrong pointer check in cfv_probe() * CVE-url: https://ubuntu.com/security/CVE-2024-56658 - net: defer final 'struct net' free in netns dismantle * CVE-url: https://ubuntu.com/security/CVE-2022-23041 - xen/pvcalls: use alloc/free_pages_exact() * CVE-url: https://ubuntu.com/security/CVE-2024-50265 - ocfs2: remove entry once instead of null-ptr-dereference in ocfs2_xa_remove() * CVE-url: https://ubuntu.com/security/CVE-2024-46826 - ELF: fix kernel.randomize_va_space double read * CVE-url: https://ubuntu.com/security/CVE-2025-21700 - net: sched: Disallow replacing of child qdisc from one parent to another * CVE-url: https://ubuntu.com/security/CVE-2025-21702 - pfifo_tail_enqueue: Drop new packet when sch->limit == 0 * CVE-url: https://ubuntu.com/security/CVE-2024-50167 - be2net: fix potential memory leak in be_xmit() * CVE-url: https://ubuntu.com/security/CVE-2024-49952 - netfilter: nf_tables: prevent nf_skb_duplicated corruption * CVE-url: https://ubuntu.com/security/CVE-2024-49948 - net: add more sanity checks to qdisc_pkt_len_init()
Update command: apt-get update apt-get --only-upgrade install linux-hwe*
linux-buildinfo-4.15.0-247-tuxcare.els45-generic_4.15.0-247.258~16.04.1_amd64.deb linux-buildinfo-4.15.0-247-tuxcare.els45-lowlatency_4.15.0-247.258~16.04.1_amd64.deb linux-cloud-tools-4.15.0-247-tuxcare.els45-generic_4.15.0-247.258~16.04.1_amd64.deb linux-cloud-tools-4.15.0-247-tuxcare.els45-lowlatency_4.15.0-247.258~16.04.1_amd64.deb linux-headers-4.15.0-247-tuxcare.els45_4.15.0-247.258~16.04.1_all.deb linux-headers-4.15.0-247-tuxcare.els45-generic_4.15.0-247.258~16.04.1_amd64.deb linux-headers-4.15.0-247-tuxcare.els45-lowlatency_4.15.0-247.258~16.04.1_amd64.deb linux-hwe-cloud-tools-4.15.0-247-tuxcare.els45_4.15.0-247.258~16.04.1_amd64.deb linux-hwe-tools-4.15.0-247-tuxcare.els45_4.15.0-247.258~16.04.1_amd64.deb linux-image-unsigned-4.15.0-247-tuxcare.els45-generic_4.15.0-247.258~16.04.1_amd64.deb linux-image-unsigned-4.15.0-247-tuxcare.els45-lowlatency_4.15.0-247.258~16.04.1_amd64.deb linux-modules-4.15.0-247-tuxcare.els45-generic_4.15.0-247.258~16.04.1_amd64.deb linux-modules-4.15.0-247-tuxcare.els45-lowlatency_4.15.0-247.258~16.04.1_amd64.deb linux-modules-extra-4.15.0-247-tuxcare.els45-generic_4.15.0-247.258~16.04.1_amd64.deb linux-source-4.15.0_4.15.0-247.258~16.04.1_all.deb linux-tools-4.15.0-247-tuxcare.els45-generic_4.15.0-247.258~16.04.1_amd64.deb linux-tools-4.15.0-247-tuxcare.els45-lowlatency_4.15.0-247.258~16.04.1_amd64.deb