Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×
The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security and bugfixes. Transient execution side-channel attacks attacking the Branch History Buffer (BHB), named "Branch Target Injection" and "Intra-Mode Branch History Injection" are now mitigated. The following security bugs were fixed: - CVE-2022-0001: Fixed Branch History Injection vulnerability (bsc#1191580). - CVE-2022-0002: Fixed Intra-Mode Branch Target Injection vulnerability (bsc#1191580). - CVE-2022-0847: Fixed a vulnerability were a local attackers could overwrite data in arbitrary (read-only) files (bsc#1196584). - CVE-2022-25375: The RNDIS USB gadget lacks validation of the size of the RNDIS_MSG_SET command. Attackers can obtain sensitive information from kernel memory (bnc#1196235 ).
#1089644 #1154353 #1157038 #1157923 #1176447
#1176940 #1178134 #1181147 #1181588 #1183872
#1187716 #1188404 #1189126 #1190812 #1190972
#1191580 #1191655 #1191741 #1192210 #1192483
#1193096 #1193233 #1193243 #1193787 #1194163
#1194967 #1195012 #1195081 #1195286 #1195352
#1195378 #1195506 #1195516 #1195543 #1195668
#1195701 #1195798 #1195799 #1195823 #1195908
#1195928 #1195947 #1195957 #1195995 #1196195
#1196235 #1196339 #1196373 #1196400 #1196403
#1196516 #1196584 #1196585 #1196601 #1196612
#1196776 SLE-20807 SLE-22135 SLE-22494
Cross- CVE-2022-0001 CVE-2022-0002 CVE-2022-0492
CVE-2022-0516 CVE-2022-0847 CVE-2022-25375
CVSS scores:
CVE-2022-0001 (SUSE): 5.6 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N
Get the latest Linux and open source security news straight to your inbox.