OESA-2022-1927
Dashboard / Vulnerabilities / OESA-2022-1927
OESA-2022-1927
Summary: kernel security update
Details: The Linux Kernel, the operating system core itself. Security Fix(es): An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer overflow and bypassing the size check. After that, because it is used as the third argument to copy_from_user(), a heap overflow may occur.(CVE-2022-39842) An issue was discovered in net/netfilter/nf_tables_api.c in the Linux kernel before 5.19.6. A denial of service can occur upon binding to an already bound chain.(CVE-2022-39190) An issue was discovered the x86 KVM subsystem in the Linux kernel before 5.18.17. Unprivileged guest users can compromise the guest kernel because TLB flush operations are mishandled in certain KVM_VCPU_PREEMPTED situations.(CVE-2022-39189) Found Linux Kernel flaw in the i740 driver. The Userspace program could pass any values to the driver through ioctl() interface. The driver doesn t check the value of pixclock , so it may cause a divide by zero error.(CVE-2022-3061) An issue was found in the Linux kernel in nf_conntrack_irc where the message handling can be confused and incorrectly matches the message. A firewall may be able to be bypassed when users are using unencrypted IRC with nf_conntrack_irc configured.(CVE-2022-2663)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1927, https://nvd.nist.gov/vuln/detail/CVE-2022-39842, https://nvd.nist.gov/vuln/detail/CVE-2022-39190, https://nvd.nist.gov/vuln/detail/CVE-2022-39189, https://nvd.nist.gov/vuln/detail/CVE-2022-3061, https://nvd.nist.gov/vuln/detail/CVE-2022-2663
Affected packages
Package
Name: kernel
Purl: pkg:rpm/openEuler/kernel&distro=openEuler-22.03-LTS
Affected ranges
Type: ECOSYSTEM
Events:
