Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

oracle-oval логотип

ELSA-2022-9025

Опубликовано: 18 янв. 2022
Источник: oracle-oval
Платформа: Oracle Linux 7
Платформа: Oracle Linux 8

Описание

ELSA-2022-9025: Unbreakable Enterprise kernel-container security update (IMPORTANT)

[5.4.17-2136.302.7.3.el7]

  • vfs: fs_context: fix up param length parsing in legacy_parse_param (Dan Carpenter) [Orabug: 33761451] {CVE-2022-0185}

Обновленные пакеты

Oracle Linux 7

Oracle Linux x86_64

kernel-uek-container

5.4.17-2136.302.7.3.el7

kernel-uek-container-debug

5.4.17-2136.302.7.3.el7

Oracle Linux 8

Oracle Linux x86_64

kernel-uek-container

5.4.17-2136.302.7.3.el8

kernel-uek-container-debug

5.4.17-2136.302.7.3.el8

Связанные CVE

Связанные уязвимости

CVSS3: 8.4
ubuntu
больше 3 лет назад

A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.

CVSS3: 7.8
redhat
больше 3 лет назад

A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.

CVSS3: 8.4
nvd
больше 3 лет назад

A heap-based buffer overflow flaw was found in the way the legacy_parse_param function in the Filesystem Context functionality of the Linux kernel verified the supplied parameters length. An unprivileged (in case of unprivileged user namespaces enabled, otherwise needs namespaced CAP_SYS_ADMIN privilege) local user able to open a filesystem that does not support the Filesystem Context API (and thus fallbacks to legacy handling) could use this flaw to escalate their privileges on the system.

CVSS3: 8.4
msrc
больше 3 лет назад

Описание отсутствует

CVSS3: 8.4
debian
больше 3 лет назад

A heap-based buffer overflow flaw was found in the way the legacy_pars ...