vulnerability

Ubuntu: (Multiple Advisories) (CVE-2023-28866): Linux kernel (OEM) vulnerabilities

Severity
5
CVSS
(AV:N/AC:L/Au:N/C:P/I:N/A:N)
Published
Mar 27, 2023
Added
Apr 21, 2023
Modified
Jan 28, 2025

Description

In the Linux kernel through 6.2.8, net/bluetooth/hci_sync.c allows out-of-bounds access because amp_init1[] and amp_init2[] are supposed to have an intentionally invalid element, but do not.

Solution(s)

ubuntu-upgrade-linux-image-6-1-0-1009-oemubuntu-upgrade-linux-image-6-2-0-1003-ibmubuntu-upgrade-linux-image-6-2-0-1005-awsubuntu-upgrade-linux-image-6-2-0-1005-azureubuntu-upgrade-linux-image-6-2-0-1005-lowlatencyubuntu-upgrade-linux-image-6-2-0-1005-lowlatency-64kubuntu-upgrade-linux-image-6-2-0-1005-oracleubuntu-upgrade-linux-image-6-2-0-1006-kvmubuntu-upgrade-linux-image-6-2-0-1006-raspiubuntu-upgrade-linux-image-6-2-0-1006-raspi-nolpaeubuntu-upgrade-linux-image-6-2-0-1007-gcpubuntu-upgrade-linux-image-6-2-0-23-genericubuntu-upgrade-linux-image-6-2-0-23-generic-64kubuntu-upgrade-linux-image-6-2-0-23-generic-lpaeubuntu-upgrade-linux-image-awsubuntu-upgrade-linux-image-azureubuntu-upgrade-linux-image-gcpubuntu-upgrade-linux-image-genericubuntu-upgrade-linux-image-generic-64kubuntu-upgrade-linux-image-generic-lpaeubuntu-upgrade-linux-image-ibmubuntu-upgrade-linux-image-kvmubuntu-upgrade-linux-image-lowlatencyubuntu-upgrade-linux-image-lowlatency-64kubuntu-upgrade-linux-image-oem-22-04cubuntu-upgrade-linux-image-oracleubuntu-upgrade-linux-image-raspiubuntu-upgrade-linux-image-raspi-nolpaeubuntu-upgrade-linux-image-virtual
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.