Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

SUSE: 2022:0767-1 Important: Kernel Update Addresses Critical Issues

suse
Calendar Grey March 8, 2022
Dist Suse Esm H88
SUSE's recent patch addresses 12 vulnerabilities in the Linux Kernel, improving both safety and reliability.
An update that solves 10 vulnerabilities, contains one feature and has 50 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP5 kernel was updated to receive various security and bugfixes. Transient execution side-channel attacks attacking the Branch History Buffer (BHB), named "Branch Target Injection" and "Intra-Mode Branch History Injection" are now mitigated. The following security bugs were fixed: - CVE-2022-0001: Fixed Branch History Injection vulnerability (bsc#1191580). - CVE-2022-0002: Fixed Intra-Mode Branch Target Injection vulnerability (bsc#1191580). - CVE-2022-0617: Fixed a null pointer dereference in UDF file system functionality. A local user could crash the system by triggering udf_file_write_iter() via a malicious UDF image. (bsc#1196079) - CVE-2022-0644: Fixed a denial of service by a local user. A assertion

References

#1046306 #1050244 #1089644 #1094978 #1097583

#1097584 #1097585 #1097586 #1097587 #1097588

#1101674 #1101816 #1103991 #1109837 #1111981

#1112374 #1114648 #1114685 #1114893 #1117495

#1118661 #1119113 #1136460 #1136461 #1157038

#1157923 #1158533 #1174852 #1185377 #1185973

#1187716 #1189126 #1191271 #1191580 #1191655

#1193857 #1193867 #1194048 #1194516 #1195080

#1195377 #1195536 #1195543 #1195612 #1195638

#1195795 #1195823 #1195840 #1195897 #1195908

#1195934 #1195949 #1195987 #1195995 #1196079

#1196155 #1196400 #1196516 #1196584 #1196612

SLE-20809

Cross- CVE-2021-44879 CVE-2021-45095 CVE-2022-0001

CVE-2022-0002 CVE-2022-0487 CVE-2022-0492

CVE-2022-0617 CVE-2022-0644 CVE-2022-24448

CVE...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:0767-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here