Alerts This Week
Warning Icon 1 924
Alerts This Week
Warning Icon 1 924

Mageia 8: MGASA-2022-0308 Critical: Kernel Security Update Overview

mageia
Calendar Grey August 25, 2022
Dist Mageia Esm H88
This kernel update resolves various security issues in Mageia linked to the Atheros driver, CPU timers, and network functions.
This kernel update is based on upstream 5.15.62 and fixes at least the following security issues: A use-after-free flaw was found in the Linux kernel Atheros wireless adapter driv...

Summary

This kernel update is based on upstream 5.15.62 and fixes at least the following security issues:
A use-after-free flaw was found in the Linux kernel Atheros wireless adapter driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privileges on the system (CVE-2022-1679).
A use-after-free flaw was found in the Linux kernel’s POSIX CPU timersfunctionality in the way a user creates and then deletes the timer in the non-leader thread of the program. This flaw allows a local user to crash or potentially escalate their privileges on the system (CVE-2022-2585).
A use-after-free flaw was found in nf_tables cross-table in the net/netfilter/nf_tables_api.c function in the Linux kernel. This flaw allows a local, privileged attacker to cause a use-after-free problem at the time of table deletion, possibly leading to local privilege escalation (CVE-2022-2586).
A use-after-free...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=30762

- https://bugs.mageia.org/show_bug.cgi?id=30725

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.59

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.60

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.61

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.62

- https://www.cve.org/CVERecord?id=CVE-2022-1679

- https://www.cve.org/CVERecord?id=CVE-2022-2585

- https://www.cve.org/CVERecord?id=CVE-2022-2586

- https://www.cve.org/CVERecord?id=CVE-2022-2588

- https://www.cve.org/CVERecord?id=CVE-2022-26373

- https://www.cve.org/CVERecord?id=CVE-2022-36946

Resolution

SRPMS

- 8/core/kernel-linus-5.15.62-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 25 Aug 2022
URL: https://advisories.mageia.org/MGASA-2022-0308.html
Type: security
CVE: CVE-2022-1679, CVE-2022-2585, CVE-2022-2586, CVE-2022-2588, CVE-2022-26373, CVE-2022-36946

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here