CLSA-2022-1651146021

    Dashboard / Vulnerabilities / CLSA-2022-1651146021

    CLSA-2022-1651146021

    Published: 28 Apr 2022Last Modified: 1 Jun 2026

    Summary: Fix of CVE: CVE-2022-0617, CVE-2021-40490, CVE-2021-29154, CVE-2022-0435, CVE-2021-4154, CVE-2021-3753, CVE-2021-38160, CVE-2021-45485, CVE-2021-3752, CVE-2021-41864, CVE-2021-4083, CVE-2021-26930

    Details: - udf: Restore i_lenAlloc when inode expansion fails (Jan Kara) {CVE-2022-0617} - udf: Fix NULL ptr deref when converting from inline format (Jan Kara) {CVE-2022-0617} - Bluetooth: fix use-after-free error in lock_sock_nested() (Wang ShaoBo) {CVE-2021-3752} - vt_kdsetmode: extend console locking (Linus Torvalds) {CVE-2021-3753} - fget: check that the fd still exists after getting a ref to it (Linus Torvalds) {CVE-2021-4083} - ipv6: use prandom_u32() for ID generation (Willy Tarreau) {CVE-2021-45485} - virtio_console: Assure used length from device is limited (Xie Yongji) {CVE-2021-38160} - bpf: Fix integer overflow in prealloc_elems_and_freelist() (Tatsuhiko Yasumatsu) {CVE-2021-41864} - ext4: fix race writing to an inline_data file while its xattrs are changing (Theodore Ts'o) {CVE-2021-40490} - xen-blkback: fix error handling in xen_blkbk_map() (Jan Beulich) {CVE-2021-26930} - bpf, x86: Validate computation of branch displacements for x86-32 (Piotr Krysiuk) {CVE-2021-29154} - bpf, x86: Validate computation of branch displacements for x86-64 (Piotr Krysiuk) {CVE-2021-29154} - tipc: improve size validations for received domain records (Jon Paul Maloy) {CVE-2022-0435} - cgroup: verify that source is a string (Christian Brauner) {CVE-2021-4154}

    Affected packages

    Package

    Name: bpftool

    Purl: pkg:rpm/tuxcare/bpftool?distro=centos-8.5

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -4.18.0-348.7.1.el8_5.tuxcare.els4

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CLSA-2022-1651146021 | CVE-DB