OESA-2023-1216
Dashboard / Vulnerabilities / OESA-2023-1216
OESA-2023-1216
Summary: kernel security update
Details: The Linux Kernel, the operating system core itself. Security Fix(es): A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux Kernel.This flaw allows an attacker to crash the system and possibly cause a kernel information lea(CVE-2023-1611) A flaw use after free in the Linux kernel Xircom 16-bit PCMCIA (PC-card) Ethernet driver was found.A local user could use this flaw to crash the system or potentially escalate their privileges on the system.(CVE-2023-1670) A use-after-free flaw was found in xen_9pfs_front_removet in net/9p/trans_xen.c in Xen transport for 9pfs in the Linux Kernel. This flaw could allow a local attacker to crash the system due to a race problem, possibly leading to a kernel information leak.(CVE-2023-1859)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1216, https://nvd.nist.gov/vuln/detail/CVE-2023-1611, https://nvd.nist.gov/vuln/detail/CVE-2023-1670, https://nvd.nist.gov/vuln/detail/CVE-2023-1859
Affected packages
Package
Name: kernel
Purl: pkg:rpm/openEuler/kernel&distro=openEuler-22.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
