OESA-2022-1714
Dashboard / Vulnerabilities / OESA-2022-1714
OESA-2022-1714
Summary: kernel security update
Details: The Linux Kernel, the operating system core itself. Security Fix(es): An out-of-bound write vulnerability was identified within the netfilter subsystem which can be exploited to achieve privilege escalation to root.(CVE-2022-1972) A use-after-free flaw was found in the Linux kernel's NFC core functionality due to a race condition between kobject creation and delete. This vulnerability allows a local attacker with CAP_NET_ADMIN privilege to leak kernel information.(CVE-2022-1974) A use-after-free flaw was found in the Linux kernel’s io_uring subsystem in the way a user sets up a ring with IORING_SETUP_IOPOLL with more than one task completing submissions on this ring. This flaw allows a local user to crash or escalate their privileges on the system.(CVE-2022-1786)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1714, https://nvd.nist.gov/vuln/detail/CVE-2022-1972, https://nvd.nist.gov/vuln/detail/CVE-2022-1974, https://nvd.nist.gov/vuln/detail/CVE-2022-1786
Affected packages
Package
Name: kernel
Purl: pkg:rpm/openEuler/kernel&distro=openEuler-22.03-LTS
Affected ranges
Type: ECOSYSTEM
Events:
