OESA-2022-1517
Dashboard / Vulnerabilities / OESA-2022-1517
OESA-2022-1517
Summary: kernel security update
Details: The Linux Kernel, the operating system core itself. Security Fix(es): A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755(CVE-2021-22600) A use-after-free flaw was found in the Linux kernel’s vmw_execbuf_copy_fence_user function in drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c in vmwgfx. This flaw allows a local attacker with user privileges to cause a privilege escalation problem.(CVE-2022-22942)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1517, https://nvd.nist.gov/vuln/detail/CVE-2021-22600, https://nvd.nist.gov/vuln/detail/CVE-2022-22942
Affected packages
Package
Name: kernel
Purl: pkg:rpm/openEuler/kernel&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
