Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

Mageia 8 MGASA-2023-0166 Critical: Kernel Denial Of Service Threat

mageia
Calendar Grey May 16, 2023
Dist Mageia Esm H88
The latest kernel update from Mageia rectifies various security vulnerabilities, tackling risks such as privilege escalation and denial of service exploits.
This kernel update is based on upstream 5.15.110 and fixes atleast the following security issues: A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/...

Summary

This kernel update is based on upstream 5.15.110 and fixes atleast the following security issues:
A slab-out-of-bound read problem was found in brcmf_get_assoc_ies in drivers/net/wireless/broadcom/brcm80211/brcmfmac/cfg80211.c. This issue could occur when assoc_info->req_len data is bigger than the size of the buffer, defined as WL_EXTRA_BUF_MAX, leading to a denial of service (CVE-2023-1380).
It was discovered that a race condition existed in the Xen transport layer implementation for the 9P file system protocol in the Linux kernel, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service or expose sensitive information (CVE-2023-1859).
An insufficient permission check has been found in the Bluetooth subsystem of the Linux kernel when handling ioctl system calls of HCI sockets. This causes tasks without the proper CAP_NET_ADMIN capability can easily mark HCI sockets as _trusted_. Trusted sockets are intended to enable the sending and r...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=31875

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.107

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.108

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.109

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.110

- https://www.cve.org/CVERecord?id=CVE-2023-1380

- https://www.cve.org/CVERecord?id=CVE-2023-1859

- https://www.cve.org/CVERecord?id=CVE-2023-2002

- https://www.cve.org/CVERecord?id=CVE-2023-2248

- https://www.cve.org/CVERecord?id=CVE-2023-31436

- https://www.cve.org/CVERecord?id=CVE-2023-32233

Resolution

SRPMS

- 8/core/kernel-5.15.110-2.mga8

- 8/core/kmod-virtualbox-7.0.8-1.2.mga8

- 8/core/kmod-xtables-addons-3.23-1.14.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 16 May 2023
URL: https://advisories.mageia.org/MGASA-2023-0166.html
Type: security
CVE: CVE-2023-1380, CVE-2023-1859, CVE-2023-2002, CVE-2023-2248, CVE-2023-31436, CVE-2023-32233

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here