Nov. 21, 2023, 2:55 p.m. |

Ubuntu security notices ubuntu.com

Yu Hao discovered that the UBI driver in the Linux kernel did not properly
check for MTD with zero erasesize during device attachment. A local
privileged attacker could use this to cause a denial of service (system
crash). (CVE-2023-31085)

Lucas Leong discovered that the netfilter subsystem in the Linux kernel did
not properly validate some attributes passed from userspace. A local
attacker could use this to cause a denial of service (system crash) or
possibly expose sensitive information (kernel memory). …

attachment attacker attributes check crash cve denial of service device driver kernel linux linux kernel local netfilter privileged service subsystem system usn vulnerabilities

Security Specialist

@ Protect Democracy | Remote, US

Information And Security Controller - Tram (UAE National)

@ Keolis | Dubaï, AE

Cybersecurity Engineer

@ Alstom Transport | Cairo, EG

IT Security Specialist (m/w/d) - Data Center & Cloud

@ CLAAS | Harsewinkel, NW, DE, 33428

Security Architect - Central Government sector

@ BAE Systems | London, GB

Project Cyber Security Manager

@ Alstom | Bangkok, TH