Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

SUSE Linux 12-SP2: SUSE-SU-2022:1283-1 Important: Kernel Update

suse
Calendar Grey April 20, 2022
Dist Suse Esm H88
Crucial SUSE Linux Kernel update addresses 13 security flaws. Review the resolved vulnerabilities and follow the installation guidelines.
An update that fixes 13 vulnerabilities is now available

Summary

The SUSE Linux Enterprise 12 SP2 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2022-1016: Fixed a vulnerability in the nf_tables component of the netfilter subsystem. This vulnerability gives an attacker a powerful primitive that can be used to both read from and write to relative stack data, which can lead to arbitrary code execution. (bsc#1197227) - CVE-2022-1048: Fixed a race Condition in snd_pcm_hw_free leading to use-after-free due to the AB/BA lock with buffer_mutex and mmap_lock. (bsc#1197331) - CVE-2022-0850: Fixed a kernel information leak vulnerability in iov_iter.c. (bsc#1196761) - CVE-2021-45868: Fixed a wrong validation check in fs/quota/quota_tree.c which could lead to an use-after-free if there is a corrupted quota

References

#1189562 #1196018 #1196488 #1196761 #1196830

#1196836 #1197227 #1197331 #1197366

Cross- CVE-2021-45868 CVE-2022-0850 CVE-2022-1016

CVE-2022-1048 CVE-2022-23036 CVE-2022-23037

CVE-2022-23038 CVE-2022-23039 CVE-2022-23040

CVE-2022-23041 CVE-2022-23042 CVE-2022-26490

CVE-2022-26966

CVSS scores:

CVE-2021-45868 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2021-45868 (SUSE): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

CVE-2022-0850 (SUSE): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L

CVE-2022-1016 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CVE-2022-1048 (SUSE): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2022-23036 (NVD) : 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:1283-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here