Audit Linux privileges now to limit compromise, escalation, and system-wide damage. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

SUSE: 2022:0761-1 Important: Kernel Denial of Service and Injection Fix

suse
Calendar Grey March 8, 2022
Scroller Suse
SUSE has rolled out a security update that tackles multiple issues within the kernel, focusing on significant branch injection vulnerabilities and potential service denial defects.
An update that solves 7 vulnerabilities, contains one feature and has 47 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP5 RT kernel was updated to receive various security and bugfixes. - CVE-2022-0001: Fixed Branch History Injection vulnerability (bsc#1191580). - CVE-2022-0002: Fixed Intra-Mode Branch Target Injection vulnerability (bsc#1191580). - CVE-2022-0617: Fixed a null pointer dereference in UDF file system functionality. A local user could crash the system by triggering udf_file_write_iter() via a malicious UDF image. (bsc#1196079) - CVE-2022-0644: Fixed a denial of service by a local user. A assertion failure could be triggered in kernel_read_file_from_fd() (bsc#1196155). - CVE-2021-44879: In gc_data_segment() in fs/f2fs/gc.c, special files were not considered, which lead to a move_data_page NULL pointer dereference (bsc#1195987).

References

#1046306 #1050244 #1089644 #1094978 #1097583

#1097584 #1097585 #1097586 #1097587 #1097588

#1101674 #1101816 #1103991 #1109837 #1111981

#1112374 #1114648 #1114685 #1114893 #1117495

#1118661 #1119113 #1136460 #1136461 #1157038

#1157923 #1158533 #1174852 #1185973 #1187716

#1189126 #1191271 #1191580 #1191655 #1193857

#1195080 #1195377 #1195536 #1195543 #1195638

#1195795 #1195823 #1195840 #1195897 #1195908

#1195934 #1195987 #1195995 #1196079 #1196155

#1196400 #1196516 #1196584 #1196612 SLE-20809

Cross- CVE-2021-44879 CVE-2022-0001 CVE-2022-0002

CVE-2022-0492 CVE-2022-0617 CVE-2022-0644

CVE-2022-24959

CVSS scores:

CVE-2021-44879 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:0761-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.