Описание
Security update for the Linux Kernel (Live Patch 5 for SLE 15 SP4)
This update for the Linux Kernel 5.14.21-150400_24_33 fixes several issues.
The following security issues were fixed:
- CVE-2022-43945: Fixed a buffer overflow in the NFSD implementation (bsc#1205128).
- CVE-2022-4378: Fixed stack overflow in __do_proc_dointvec (bsc#1206207).
- CVE-2022-4139: Fixed an issue with the i915 driver that allowed the GPU to access any physical memory (bsc#1205700).
- CVE-2021-39698: Fixed a use-after-free in aio_poll_complete_work of aio.c (bsc#1196956).
Список пакетов
SUSE Linux Enterprise Live Patching 15 SP4
Ссылки
- Link for SUSE-SU-2022:4542-1
- E-Mail link for SUSE-SU-2022:4542-1
- SUSE Security Ratings
- SUSE Bug 1196959
- SUSE Bug 1205130
- SUSE Bug 1205815
- SUSE Bug 1206228
- SUSE CVE CVE-2021-39698 page
- SUSE CVE CVE-2022-4139 page
- SUSE CVE CVE-2022-4378 page
- SUSE CVE CVE-2022-43945 page
Описание
In aio_poll_complete_work of aio.c, there is a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-185125206References: Upstream kernel
Затронутые продукты
Ссылки
- CVE-2021-39698
- SUSE Bug 1196956
- SUSE Bug 1196959
- SUSE Bug 1209225
Описание
An incorrect TLB flush issue was found in the Linux kernel's GPU i915 kernel driver, potentially leading to random memory corruption or data leaks. This flaw could allow a local user to crash the system or escalate their privileges on the system.
Затронутые продукты
Ссылки
- CVE-2022-4139
- SUSE Bug 1205700
- SUSE Bug 1205815
- SUSE Bug 1209225
Описание
A stack overflow flaw was found in the Linux kernel's SYSCTL subsystem in how a user changes certain kernel parameters and variables. This flaw allows a local user to crash or potentially escalate their privileges on the system.
Затронутые продукты
Ссылки
- CVE-2022-4378
- SUSE Bug 1206207
- SUSE Bug 1206228
- SUSE Bug 1208030
- SUSE Bug 1208085
- SUSE Bug 1209225
- SUSE Bug 1211118
- SUSE Bug 1214268
- SUSE Bug 1218483
- SUSE Bug 1218966
Описание
The Linux kernel NFSD implementation prior to versions 5.19.17 and 6.0.2 are vulnerable to buffer overflow. NFSD tracks the number of pages held by each NFSD thread by combining the receive and send buffers of a remote procedure call (RPC) into a single array of pages. A client can force the send buffer to shrink by sending an RPC message over TCP with garbage data added at the end of the message. The RPC message with garbage data is still correctly formed according to the specification and is passed forward to handlers. Vulnerable code in NFSD is not expecting the oversized request and writes beyond the allocated buffer space. CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Затронутые продукты
Ссылки
- CVE-2022-43945
- SUSE Bug 1205128
- SUSE Bug 1205130
- SUSE Bug 1208030
- SUSE Bug 1208085
- SUSE Bug 1209225
- SUSE Bug 1210124