Oval Definition:oval:org.opensuse.security:def:118161
Revision Date:2022-05-10Version:1
Title:Security update for the Linux Kernel (Live Patch 26 for SLE 15 SP2) (Important)
Description:

This update for the Linux Kernel 5.3.18-150200_24_112 fixes several issues.

The following security issues were fixed:

- - CVE-2022-1158: Fixed KVM x86/mmu compare-and-exchange of gPTE via the user address (bsc#1198133) - CVE-2022-1011: A use-after-free flaw was found in the FUSE filesystem in the way a user triggers write(). This flaw allowed a local user to gain unauthorized access to data from the FUSE filesystem, resulting in privilege escalation. (bsc#1197344) - - CVE-2021-39698: In aio_poll_complete_work of aio.c, there was a possible memory corruption due to a use after free. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. (bsc#1196959)
Family:unixClass:patch
Status:Reference(s):1196959
1197344
1198133
CVE-2021-39698
CVE-2022-1011
CVE-2022-1158
SUSE-SU-2022:1634-1
Platform(s):SUSE Linux Enterprise High Performance Computing 15 SP2
SUSE Linux Enterprise Module for Live Patching 15 SP2
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Server for SAP Applications 15 SP2
Product(s):
Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Performance Computing 15 SP2 is installed
  • OR SUSE Linux Enterprise Module for Live Patching 15 SP2 is installed
  • OR SUSE Linux Enterprise Server 15 SP2 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP2 is installed
  • AND kernel-livepatch-5_3_18-150200_24_112-default-2-150200.2.1 is installed
  • BACK