Synopsis:          Moderate: kernel security and bug fix update
Advisory ID:       SLSA-2022:5937-1
Issue Date:        2022-08-09
CVE Numbers:       CVE-2022-21123
                   CVE-2022-21125
                   CVE-2022-21166
--

Security Fix(es):

* Incomplete cleanup of multi-core shared buffers (aka SBDR)
(CVE-2022-21123)

* Incomplete cleanup of microarchitectural fill buffers (aka SBDS)
(CVE-2022-21125)

* Incomplete cleanup in specific special register write operations (aka
DRPW) (CVE-2022-21166)

For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE

Bug Fix(es):

* SolarFlare sfc spurious TX completion

* Page allocation failure on cryptsetup open

* The kernel-rt crashes where one task is indefinitely looping in
__start_cfs_bandwidth() with the cfs_b->lock spinlock being held

* While using PTimekeeper the qede driver produces excessive log messages

* The kernel crashes due to a GPF happens in mutex_spin_on_owner(). The
known RDMA/cma bug that was introduced with a patch from upstream commit
722c7b2bfead is the possible cause.

* Running LTP testcase creat09 fails showing related  to 'cve-2018-13405'

* Crash when releasing inode which was on unmouted superblock
--

SL7
  x86_64
    bpftool-3.10.0-1160.76.1.el7.x86_64.rpm
    bpftool-debuginfo-3.10.0-1160.76.1.el7.x86_64.rpm
    kernel-3.10.0-1160.76.1.el7.x86_64.rpm
    kernel-debug-3.10.0-1160.76.1.el7.x86_64.rpm
    kernel-debug-debuginfo-3.10.0-1160.76.1.el7.x86_64.rpm
    kernel-debug-devel-3.10.0-1160.76.1.el7.x86_64.rpm
    kernel-debuginfo-3.10.0-1160.76.1.el7.x86_64.rpm
    kernel-debuginfo-common-x86_64-3.10.0-1160.76.1.el7.x86_64.rpm
    kernel-devel-3.10.0-1160.76.1.el7.x86_64.rpm
    kernel-headers-3.10.0-1160.76.1.el7.x86_64.rpm
    kernel-tools-3.10.0-1160.76.1.el7.x86_64.rpm
    kernel-tools-debuginfo-3.10.0-1160.76.1.el7.x86_64.rpm
    kernel-tools-libs-3.10.0-1160.76.1.el7.x86_64.rpm
    perf-3.10.0-1160.76.1.el7.x86_64.rpm
    perf-debuginfo-3.10.0-1160.76.1.el7.x86_64.rpm
    python-perf-3.10.0-1160.76.1.el7.x86_64.rpm
    python-perf-debuginfo-3.10.0-1160.76.1.el7.x86_64.rpm
    kernel-tools-libs-devel-3.10.0-1160.76.1.el7.x86_64.rpm
  noarch
    kernel-abi-whitelists-3.10.0-1160.76.1.el7.noarch.rpm
    kernel-doc-3.10.0-1160.76.1.el7.noarch.rpm

- Scientific Linux Development Team

SciLinux: SLSA-2022-5937-1 Moderate: kernel on SL7.x x86_64

Incomplete cleanup of multi-core shared buffers (aka SBDR) (CVE-2022-21123) * Incomplete cleanup of microarchitectural fill buffers (aka SBDS) (CVE-2022-21125) * Incomplete cleanup...

Summary

Moderate: kernel security and bug fix update



Security Fixes

* Incomplete cleanup of multi-core shared buffers (aka SBDR) (CVE-2022-21123)
* Incomplete cleanup of microarchitectural fill buffers (aka SBDS) (CVE-2022-21125)
* Incomplete cleanup in specific special register write operations (aka DRPW) (CVE-2022-21166)
For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE

Severity
Advisory ID: SLSA-2022:5937-1
Issued Date: : 2022-08-09
CVE Numbers: CVE-2022-21123
CVE-2022-21125
CVE-2022-21166

Related News