Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The SUSE Linux Enterprise 15 SP4 Azure kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2021-33655: Fixed out of bounds write with ioctl FBIOPUT_VSCREENINFO (bnc#1201635). - CVE-2022-1462: Fixed an out-of-bounds read flaw in the TeleTYpe subsystem (bnc#1198829). - CVE-2022-21505: Fixed kexec lockdown bypass with IMA policy (bsc#1201458). - CVE-2022-29581: Fixed improper update of Reference Count in net/sched that could cause root privilege escalation (bnc#1199665). - CVE-2022-32250: Fixed an use-after-free bug in the netfilter subsystem. This flaw allowed a local attacker with user access to cause a privilege escalation issue (bnc#1200015, bnc#1200494). The following non-security bugs were fixed:
#1190256 #1190497 #1198410 #1198829 #1199086
#1199291 #1199364 #1199665 #1199670 #1200015
#1200465 #1200494 #1200644 #1200651 #1201258
#1201323 #1201381 #1201391 #1201427 #1201458
#1201471 #1201524 #1201592 #1201593 #1201595
#1201596 #1201635 #1201651 #1201675 #1201691
#1201705 #1201725 #1201846 #1201930 #1201954
#1201958 SLE-18130 SLE-20183 SLE-21132 SLE-24569
SLE-24570 SLE-24571 SLE-24578 SLE-24635 SLE-24682
Cross- CVE-2021-33655 CVE-2022-1462 CVE-2022-21505
CVE-2022-29581 CVE-2022-32250
CVSS scores:
CVE-2021-33655 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2021-33655 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2022-1462 (NVD) : 6.3 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:H
Get the latest Linux and open source security news straight to your inbox.