Описание
Security update for the Linux Kernel (Live Patch 27 for SLE 12 SP4)
This update for the Linux Kernel 4.12.14-95_99 fixes several issues.
The following security issues were fixed:
- CVE-2022-20154: Fixed a use after free due to a race condition in lock_sock_nested of sock.c. This could lead to local escalation of privilege with System execution privileges needed (bsc#1200599).
- CVE-2022-1729: Fixed a sys_perf_event_open() race condition against self (bsc#1199507).
Список пакетов
SUSE Linux Enterprise Live Patching 12 SP4
kgraft-patch-4_12_14-95_99-default-2-2.1
Ссылки
- Link for SUSE-SU-2022:2445-1
- E-Mail link for SUSE-SU-2022:2445-1
- SUSE Security Ratings
- SUSE Bug 1199697
- SUSE Bug 1200608
- SUSE CVE CVE-2022-1729 page
- SUSE CVE CVE-2022-20154 page
Описание
A race condition was found the Linux kernel in perf_event_open() which can be exploited by an unprivileged user to gain root privileges. The bug allows to build several exploit primitives such as kernel address information leak, arbitrary execution, etc.
Затронутые продукты
SUSE Linux Enterprise Live Patching 12 SP4:kgraft-patch-4_12_14-95_99-default-2-2.1
Ссылки
- CVE-2022-1729
- SUSE Bug 1199507
- SUSE Bug 1199697
- SUSE Bug 1201832
Описание
In lock_sock_nested of sock.c, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-174846563References: Upstream kernel
Затронутые продукты
SUSE Linux Enterprise Live Patching 12 SP4:kgraft-patch-4_12_14-95_99-default-2-2.1
Ссылки
- CVE-2022-20154
- SUSE Bug 1200599
- SUSE Bug 1200608
- SUSE Bug 1224298
- SUSE Bug 1224878