Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

Mageia 8: MGASA-2022-0045 Moderate: Connman Memory Reference Issues

mageia
Calendar Grey February 2, 2022
Dist Mageia Esm H88
Mageia has released updates for connman packages addressing security vulnerabilities concerning DNS and memory references, as outlined in the documentation.
TCP Receive Path does not Check for Presence of Sufficient Header Data

Summary

TCP Receive Path does not Check for Presence of Sufficient Header Data. (CVE-2022-23096)
Possibly invalid memory reference in 'strnlen()' call in 'forward_dns_reply()'. (CVE-2022-23097)
TCP Receive Path Triggers 100 % CPU loop if DNS server does not Send Back Data. (CVE-2022-23098)

References

- https://bugs.mageia.org/show_bug.cgi?id=29945

- https://www.openwall.com/lists/oss-security/2022/01/25/1

- https://www.cve.org/CVERecord?id=CVE-2022-23096

- https://www.cve.org/CVERecord?id=CVE-2022-23097

- https://www.cve.org/CVERecord?id=CVE-2022-23098

Resolution

SRPMS

- 8/core/connman-1.38-2.2.mga8

Publication date: 02 Feb 2022
URL: https://advisories.mageia.org/MGASA-2022-0045.html
Type: security
CVE: CVE-2022-23096, CVE-2022-23097, CVE-2022-23098

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here