Alerts This Week
Warning Icon 1 631
Alerts This Week
Warning Icon 1 631

SUSE: 2022:3607-1 Important: Linux Kernel Live Patch Issues Addressed

suse
Calendar Grey October 18, 2022
Dist Suse Esm H88
Crucial SUSE upgrade rolled out for Linux Kernel tackling significant vulnerabilities such as memory leaks and buffer overrun.
An update that fixes 7 vulnerabilities is now available

Summary

This update for the Linux Kernel 5.3.18-150200_24_129 fixes several issues. The following security issues were fixed: - CVE-2022-41674: Fixed buffer overflow that can be triggered by injected WLAN frames (bsc#1203994). - CVE-2022-42719: Fixed use-after-free in the mac80211 stack when parsing a multi-BSSID element (bsc#1204292). - CVE-2022-42720: Fixed refcounting bugs in the multi-BSS handling of the mac80211 stack (bsc#1204291). - CVE-2022-42721: Fixed list management bug in BSS handling of the mac80211 stack (bsc#1204290). - CVE-2022-41222: Fixed a use-after-free via a stale TLB (bsc#1203624). - CVE-2022-39189: Fixed mishandled TLB flush operation in certain KVM_VCPU_PREEMPTED situations (bsc#1203067). - CVE-2021-39698: Fixed memory corruption due to a use after free in

References

#1196959 #1203067 #1203624 #1203994 #1204290

#1204291 #1204292

Cross- CVE-2021-39698 CVE-2022-39189 CVE-2022-41222

CVE-2022-41674 CVE-2022-42719 CVE-2022-42720

CVE-2022-42721

CVSS scores:

CVE-2021-39698 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2021-39698 (SUSE): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2022-39189 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2022-39189 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2022-41222 (NVD) : 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N

CVE-2022-41222 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2022-41674 (SUSE): 8.8 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:3607-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here