Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

Mageia 8: MGASA-2022-0478 Critical: Kernel-Linus Denial Of Service

mageia
Calendar Grey December 18, 2022
Dist Mageia Esm H88
This Mageia advisory outlines significant kernel-linus enhancements that tackle security vulnerabilities impacting system integrity and user access.
This kernel-linus update is based on upstream 5.15.82 and fixes atleast the following security issues: A flaw was found in the Linux kernel

Summary

This kernel-linus update is based on upstream 5.15.82 and fixes atleast the following security issues:
A flaw was found in the Linux kernel. A denial of service flaw may occur if there is a consecutive request of the NVME_IOCTL_RESET and the NVME_IOCTL_SUBSYS_RESET through the device file of the driver, resulting in a PCIe link disconnect (CVE-2022-3169).
A flaw was found in the KVM's AMD nested virtualization (SVM). A malicious L1 guest could purposely fail to intercept the shutdown of a cooperative nested guest (L2), possibly leading to a page fault and kernel panic in the host (L0) (CVE-2022-3344).
A vulnerability has been found in Linux Kernel function kcm_tx_work of the file net/kcm/kcmsock.c of the component kcm. The manipulation leads to race condition (CVE-2022-3521).
An incorrect TLB flush issue was found in the Linux kernel’s GPU i915 kernel driver, potentially leading to random memory corruption or data leaks. This flaw could allow a local user to crash the system or...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=31261

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.80

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.81

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.82

- https://www.cve.org/CVERecord?id=CVE-2022-3169

- https://www.cve.org/CVERecord?id=CVE-2022-3344

- https://www.cve.org/CVERecord?id=CVE-2022-3521

- https://www.cve.org/CVERecord?id=CVE-2022-3643

- https://www.cve.org/CVERecord?id=CVE-2022-4139

- https://www.cve.org/CVERecord?id=CVE-2022-4378

- https://www.cve.org/CVERecord?id=CVE-2022-45869

Resolution

SRPMS

- 8/core/kernel-linus-5.15.82-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 17 Dec 2022
URL: https://advisories.mageia.org/MGASA-2022-0478.html
Type: security
CVE: CVE-2022-3169, CVE-2022-3344, CVE-2022-3521, CVE-2022-3643, CVE-2022-4139, CVE-2022-4378, CVE-2022-45869

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here