CLSA-2022-1651146021
Dashboard / Vulnerabilities / CLSA-2022-1651146021
CLSA-2022-1651146021
Summary: Fix of CVE: CVE-2022-0617, CVE-2021-40490, CVE-2021-29154, CVE-2022-0435, CVE-2021-4154, CVE-2021-3753, CVE-2021-38160, CVE-2021-45485, CVE-2021-3752, CVE-2021-41864, CVE-2021-4083, CVE-2021-26930
Details: - udf: Restore i_lenAlloc when inode expansion fails (Jan Kara) {CVE-2022-0617} - udf: Fix NULL ptr deref when converting from inline format (Jan Kara) {CVE-2022-0617} - Bluetooth: fix use-after-free error in lock_sock_nested() (Wang ShaoBo) {CVE-2021-3752} - vt_kdsetmode: extend console locking (Linus Torvalds) {CVE-2021-3753} - fget: check that the fd still exists after getting a ref to it (Linus Torvalds) {CVE-2021-4083} - ipv6: use prandom_u32() for ID generation (Willy Tarreau) {CVE-2021-45485} - virtio_console: Assure used length from device is limited (Xie Yongji) {CVE-2021-38160} - bpf: Fix integer overflow in prealloc_elems_and_freelist() (Tatsuhiko Yasumatsu) {CVE-2021-41864} - ext4: fix race writing to an inline_data file while its xattrs are changing (Theodore Ts'o) {CVE-2021-40490} - xen-blkback: fix error handling in xen_blkbk_map() (Jan Beulich) {CVE-2021-26930} - bpf, x86: Validate computation of branch displacements for x86-32 (Piotr Krysiuk) {CVE-2021-29154} - bpf, x86: Validate computation of branch displacements for x86-64 (Piotr Krysiuk) {CVE-2021-29154} - tipc: improve size validations for received domain records (Jon Paul Maloy) {CVE-2022-0435} - cgroup: verify that source is a string (Christian Brauner) {CVE-2021-4154}
Affected packages
Package
Name: bpftool
Purl: pkg:rpm/tuxcare/bpftool?distro=centos-8.5
Affected ranges
Type: ECOSYSTEM
Events:
