Alerts This Week
Warning Icon 1 646
Alerts This Week
Warning Icon 1 646

SUSE Linux Enterprise 12-SP5: 2022:3930-1 Critical Kernel Update

suse
Calendar Grey November 10, 2022
Dist Suse Esm H88
An upgrade for the SUSE Linux Kernel addresses 16 vulnerabilities, among which are severe buffer overflow exploits. Update immediately!
An update that solves 16 vulnerabilities and has 5 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP5 kernel RT was updated. The following security bugs were fixed: - CVE-2022-3628: Fixed potential buffer overflow in brcmf_fweh_event_worker() in wifi/brcmfmac (bsc#1204868). - CVE-2021-4037: Fixed function logic vulnerability that allowed local users to create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set (bnc#1198702). - CVE-2022-2153: Fixed vulnerability in KVM that could allow an unprivileged local attacker on the host to cause DoS (bnc#1200788). - CVE-2022-2964, CVE-2022-28748: Fixed memory corruption issues in ax88179_178a devices (bnc#1202686 bsc#1196018). - CVE-2022-3521: Fixed race condition in kcm_tx_work() in net/kcm/kcmsock.c (bnc#1204355).

References

#1065729 #1198702 #1200788 #1202686 #1202972

#1203387 #1204241 #1204354 #1204355 #1204402

#1204415 #1204431 #1204439 #1204479 #1204574

#1204635 #1204646 #1204647 #1204653 #1204755

#1204868

Cross- CVE-2021-4037 CVE-2022-2153 CVE-2022-2964

CVE-2022-3521 CVE-2022-3524 CVE-2022-3542

CVE-2022-3545 CVE-2022-3565 CVE-2022-3586

CVE-2022-3594 CVE-2022-3621 CVE-2022-3628

CVE-2022-3629 CVE-2022-3646 CVE-2022-3649

CVE-2022-43750

CVSS scores:

CVE-2021-4037 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2021-4037 (SUSE): 4.4 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

CVE-2022-2153 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVE-2022-2153 (SUSE): 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:N/A:H

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:3930-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here