OESA-2022-1941
Dashboard / Vulnerabilities / OESA-2022-1941
OESA-2022-1941
Summary: kernel security update
Details: The Linux Kernel, the operating system core itself. Security Fix(es): A flaw was found in the sctp_make_strreset_req function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel with a local user privilege access. In this flaw, an attempt to use more buffer than is allocated triggers a BUG_ON issue, leading to a denial of service (DOS).(CVE-2022-0322) A vulnerability was found in the Linux kernel. This flaw allows an unprivileged local user to panic the system, resulting in a denial of service by calling setsockopt(2) with specially crafted arguments. The highest threat from this vulnerability is to system availability.(CVE-2021-3894) A NULL pointer dereference flaw in diFree in fs/jfs/inode.c in Journaled File System (JFS)in the Linux kernel. This could allow a local attacker to crash the system or leak kernel internal information.(CVE-2022-3202)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2022-1941, https://nvd.nist.gov/vuln/detail/CVE-2022-0322, https://nvd.nist.gov/vuln/detail/CVE-2021-3894, https://nvd.nist.gov/vuln/detail/CVE-2022-3202
Affected packages
Package
Name: kernel
Purl: pkg:rpm/openEuler/kernel&distro=openEuler-20.03-LTS-SP3
Affected ranges
Type: ECOSYSTEM
Events:
