OESA-2022-1705
Dashboard / Vulnerabilities / OESA-2022-1705
OESA-2022-1705
Summary: kernel security update
Details: The Linux Kernel, the operating system core itself. Security Fix(es): There are use-after-free vulnerabilities in net/ax25/af_ax25.c of linux that allow attacker to crash linux kernel by simulating ax25 device from user space.(CVE-2022-1204) The Linux kernel before 5.17.2 mishandles seccomp permissions. The PTRACE_SEIZE code path allows attackers to bypass intended restrictions on setting the PT_SUSPEND_SECCOMP flag.(CVE-2022-30594) ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2022-33981. Reason: This candidate is a reservation duplicate of CVE-2022-33981. Notes: All CVE users should reference CVE-2022-33981 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage.(CVE-2022-1836) With shadow paging enabled, the INVPCID instruction results in a call to kvm_mmu_invpcid_gva. If INVPCID is executed with CR0.PG=0, the invlpg callback is not set and the result is a NULL pointer dereference.(CVE-2022-1789) Uncontrolled resource consumption in the Linux kernel drivers for Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access.(CVE-2021-33135) perf: Fix sys_perf_event_open() race against self(CVE-2022-1729)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1705, https://nvd.nist.gov/vuln/detail/CVE-2022-1204, https://nvd.nist.gov/vuln/detail/CVE-2022-30594, https://nvd.nist.gov/vuln/detail/CVE-2022-1836, https://nvd.nist.gov/vuln/detail/CVE-2022-1789, https://nvd.nist.gov/vuln/detail/CVE-2021-33135, https://nvd.nist.gov/vuln/detail/CVE-2022-1729
Affected packages
Package
Name: kernel
Purl: pkg:rpm/openEuler/kernel&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
