Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

Mageia 8 MGASA-2022-0477 Moderate: Kernel Denial Of Service Issues

mageia
Calendar Grey December 18, 2022
Dist Mageia Esm H88
The kernel patch MGASA-2022-0477 resolves various security vulnerabilities that encompass denial of service threats alongside memory corruption challenges.
This kernel update is based on upstream 5.15.82 and fixes atleast the following security issues: A flaw was found in the Linux kernel

Summary

This kernel update is based on upstream 5.15.82 and fixes atleast the following security issues:
A flaw was found in the Linux kernel. A denial of service flaw may occur if there is a consecutive request of the NVME_IOCTL_RESET and the NVME_IOCTL_SUBSYS_RESET through the device file of the driver, resulting in a PCIe link disconnect (CVE-2022-3169).
A flaw was found in the KVM's AMD nested virtualization (SVM). A malicious L1 guest could purposely fail to intercept the shutdown of a cooperative nested guest (L2), possibly leading to a page fault and kernel panic in the host (L0) (CVE-2022-3344).
A vulnerability has been found in Linux Kernel function kcm_tx_work of the file net/kcm/kcmsock.c of the component kcm. The manipulation leads to race condition (CVE-2022-3521).
Guests can trigger NIC interface reset/abort/crash via netback. It is possible for a guest to trigger a NIC interface reset/abort/crash in a Linux based network backend by sending certain kinds of packets. It appears...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=31260

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.80

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.81

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.82

- https://xenbits.xenproject.org/xsa/advisory-423.txt

- https://xenbits.xenproject.org/xsa/advisory-424.txt

- https://www.cve.org/CVERecord?id=CVE-2022-3169

- https://www.cve.org/CVERecord?id=CVE-2022-3344

- https://www.cve.org/CVERecord?id=CVE-2022-3521

- https://www.cve.org/CVERecord?id=CVE-2022-4139

- https://www.cve.org/CVERecord?id=CVE-2022-4378

- https://www.cve.org/CVERecord?id=CVE-2022-42328

- https://www.cve.org/CVERecord?id=CVE-2022-42329

- https://www.cve.org/CVERecord?id=CVE-2022-45869

Resolution

SRPMS

- 8/core/kernel-5.15.82-1.mga8

- 8/core/kmod-virtualbox-7.0.4-1.2.mga8

- 8/core/kmod-xtables-addons-3.21-1.8.mga8

Severity
important
Lowest
Low
Medium
High
Critical

Publication date: 17 Dec 2022
URL: https://advisories.mageia.org/MGASA-2022-0477.html
Type: security
CVE: CVE-2022-3169, CVE-2022-3344, CVE-2022-3521, CVE-2022-4139, CVE-2022-4378, CVE-2022-42328, CVE-2022-42329, CVE-2022-45869

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here