OESA-2022-1727
Dashboard / Vulnerabilities / OESA-2022-1727
OESA-2022-1727
Summary: kernel security update
Details: The Linux Kernel, the operating system core itself. Security Fix(es): A use-after-free flaw was found in the Linux kernel’s sound subsystem in the way a user triggers concurrent calls of PCM hw_params. The hw_free ioctls or similar race condition happens inside ALSA PCM for other ioctls. This flaw allows a local user to crash or potentially escalate their privileges on the system.(CVE-2022-1048) The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security and bugfixes.(CVE-2022-1158) KGDB and KDB allow read and write access to kernel memory, and thus should be restricted during lockdown. An attacker with access to a serial port could trigger the debugger so it is important that the debugger respect the lockdown mode when/if it is triggered. CVSS 3.1 Base Score 6.5 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H).(CVE-2022-21499)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1727, https://nvd.nist.gov/vuln/detail/CVE-2022-1048, https://nvd.nist.gov/vuln/detail/CVE-2022-1158, https://nvd.nist.gov/vuln/detail/CVE-2022-21499
Affected packages
Package
Name: kernel
Purl: pkg:rpm/openEuler/kernel&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
