OESA-2022-1871
Dashboard / Vulnerabilities / OESA-2022-1871
Summary: kernel security update
Details: The Linux Kernel, the operating system core itself. Security Fix(es): Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.(CVE-2022-26373) A use-after-free flaw was found in route4_change in the net/sched/cls_route.c filter implementation in the Linux kernel. This flaw allows a local, privileged attacker to crash the system, possibly leading to a local privilege escalation issue.(CVE-2022-2588)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1871, https://nvd.nist.gov/vuln/detail/CVE-2022-26373, https://nvd.nist.gov/vuln/detail/CVE-2022-2588
Affected packages
Package
Name: kernel
Purl: pkg:rpm/openEuler/kernel&distro=openEuler-20.03-LTS-SP3
Affected ranges
Type: ECOSYSTEM
Events:
