OESA-2023-1228
Dashboard / Vulnerabilities / OESA-2023-1228
OESA-2023-1228
Summary: kernel security update
Details: The Linux Kernel, the operating system core itself. Security Fix(es): A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c in btrfs in the Linux Kernel.This flaw allows an attacker to crash the system and possibly cause a kernel information lea(CVE-2023-1611) A flaw use after free in the Linux kernel Xircom 16-bit PCMCIA (PC-card) Ethernet driver was found.A local user could use this flaw to crash the system or potentially escalate their privileges on the system.(CVE-2023-1670) A use-after-free flaw was found in xen_9pfs_front_removet in net/9p/trans_xen.c in Xen transport for 9pfs in the Linux Kernel. This flaw could allow a local attacker to crash the system due to a race problem, possibly leading to a kernel information leak.(CVE-2023-1859) A race problem was found in fs/proc/task_mmu.c in the memory management sub-component in the Linux kernel. This issue may allow a local attacker with user privilege to cause a denial of service.(CVE-2023-1582) A double-free flaw was found in the Linux kernel’s TUN/TAP device driver functionality in how a user registers the device when the register_netdevice function fails (NETDEV_REGISTER notifier). This flaw allows a local user to crash or potentially escalate their privileges on the system.(CVE-2022-4744)
References: https://www.openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2023-1228, https://nvd.nist.gov/vuln/detail/CVE-2023-1611, https://nvd.nist.gov/vuln/detail/CVE-2023-1670, https://nvd.nist.gov/vuln/detail/CVE-2023-1859, https://nvd.nist.gov/vuln/detail/CVE-2023-1582, https://nvd.nist.gov/vuln/detail/CVE-2022-4744
Affected packages
Package
Name: kernel
Purl: pkg:rpm/openEuler/kernel&distro=openEuler-22.03-LTS
Affected ranges
Type: ECOSYSTEM
Events:
