SUSE-SU-2022:2000-1
Dashboard / Vulnerabilities / SUSE-SU-2022:2000-1
SUSE-SU-2022:2000-1
Summary: Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP3)
Details: This update for the Linux Kernel 5.3.18-57 fixes several issues. The following security issues were fixed: - CVE-2022-1048: Fixed a race Condition in snd_pcm_hw_free leading to use-after-free due to the AB/BA lock with buffer_mutex and mmap_lock (bsc#1197597). - CVE-2022-30594: Fixed restriction bypass on setting the PT_SUSPEND_SECCOMP flag (bnc#1199602). - Add missing module_mutex lock to module notifier for previous live patches (bsc#1199834).
References: https://www.suse.com/support/update/announcement/2022/suse-su-20222000-1/, https://bugzilla.suse.com/1197597, https://bugzilla.suse.com/1199602, https://bugzilla.suse.com/1199834, https://www.suse.com/security/cve/CVE-2022-1048, https://www.suse.com/security/cve/CVE-2022-30594
Affected packages
Package
Name: kernel-livepatch-SLE15-SP3_Update_0
Purl: pkg:rpm/suse/kernel-livepatch-SLE15-SP3_Update_0&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
