Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 8 MGASA-2022-0279 Critical: Kernel-Linus Speculative Execution

mageia
Calendar Grey August 6, 2022
Dist Mageia Esm H88
Kernel-linus enhancement MGASA-2022-0280 tackles vulnerabilities linked to various CVEs, bolstering overall system integrity.
This kernel-linus update is based on upstream 5.15.58 and fixes at least the following security issues: Kernel lockdown bypass when UEFI secure boot is disabled / unavailable and ...

Summary

This kernel-linus update is based on upstream 5.15.58 and fixes at least the following security issues:
Kernel lockdown bypass when UEFI secure boot is disabled / unavailable and IMA appraisal is enabled (CVE-2022-21505).
Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure (CVE-2022-23825).
Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions (CVE-2022-29900, RetBleed).
Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions (CVE-2022-29901).
The Linux kernel before 5.18.13 lacks a certain clear operation for the blo...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=30688

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.56

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.57

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.58

- - https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00702.html

- https://www.cve.org/CVERecord?id=CVE-2022-21505

- https://www.cve.org/CVERecord?id=CVE-2022-23825

- https://www.cve.org/CVERecord?id=CVE-2022-29900

- https://www.cve.org/CVERecord?id=CVE-2022-29901

- https://www.cve.org/CVERecord?id=CVE-2022-36123

- https://www.cve.org/CVERecord?id=CVE-2022-36879

Resolution

SRPMS

- 8/core/kernel-linus-5.15.58-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 06 Aug 2022
URL: https://advisories.mageia.org/MGASA-2022-0279.html
Type: security
CVE: CVE-2022-21505, CVE-2022-23825, CVE-2022-29900, CVE-2022-29901, CVE-2022-36123, CVE-2022-36879

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here