Oval Definition:oval:org.opensuse.security:def:125386
Revision Date:2022-08-09Version:1
Title:Security update for the Linux Kernel (Live Patch 23 for SLE 12 SP4) (Important)
Description:

This update for the Linux Kernel 4.12.14-95_83 fixes several issues.

The following security issues were fixed:

- CVE-2022-28389: Fixed a double free in drivers/net/can/usb/mcba_usb.c vulnerability in the Linux kernel. (bnc#1198033) - CVE-2022-26490: Fixed a buffer overflow in the st21nfca driver. An attacker with adjacent NFC access could crash the system or corrupt the system memory. (bsc#1196830) - CVE-2022-1419: Fixed a concurrency use-after-free in vgem_gem_dumb_create (bsc#1198742). - CVE-2022-28390: Fixed a double free in drivers/net/can/usb/ems_usb.c vulnerability in the Linux kernel (bnc#1198031). - CVE-2022-1679: Fixed a use-after-free in the Atheros wireless driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages (bsc#1199487). - CVE-2022-20141: Fixed a possible use after free due to improper locking in ip_check_mc_rcu() (bsc#1200604).
Family:unixClass:patch
Status:Reference(s):1200605
1201080
1201517
1201655
1201656
1201657
CVE-2022-1419
CVE-2022-1679
CVE-2022-20141
CVE-2022-26490
CVE-2022-28389
CVE-2022-28390
SUSE-SU-2022:2709-1
Platform(s):SUSE Linux Enterprise Live Patching 12 SP4
Product(s):
Definition Synopsis
  • SUSE Linux Enterprise Live Patching 12 SP4 is installed
  • AND kgraft-patch-4_12_14-95_83-default-12-2.2 is installed
  • BACK