Oval Definition:oval:org.opensuse.security:def:95354
Revision Date:2022-07-05Version:1
Title:Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP4) (Important)
Description:

This update for the Linux Kernel 5.14.21-150400_22 fixes several issues.

The following security issues were fixed:

- CVE-2022-32250: Fixed an use-after-free bug in the netfilter subsystem. This flaw allowed a local attacker with user access to cause a privilege escalation issue. (bnc#1200015) - CVE-2022-1972: Fixed a buffer overflow in nftable that could lead to privilege escalation. (bsc#1200019) - CVE-2022-30594: Fixed restriction bypass on setting the PT_SUSPEND_SECCOMP flag (bnc#1199505). - CVE-2022-1280: Fixed a use-after-free vulnerability in drm_lease_held in drivers/gpu/drm/drm_lease.c (bnc#1197914). - CVE-2022-1280: Fixed a use-after-free vulnerability in drm_lease_held in drivers/gpu/drm/drm_lease.c (bnc#1197914). - CVE-2022-1016: Fixed a vulnerability in the nf_tables component of the netfilter subsystem. This vulnerability gives an attacker a powerful primitive that can be used to both read from and write to relative stack data, which can lead to arbitrary code execution. (bsc#1197227) - CVE-2021-39698: Fixed a possible memory corruption due to a use after free in aio_poll_complete_work. This could lead to local escalation of privilege with no additional execution privileges needed. (bsc#1196956)
Family:unixClass:patch
Status:Reference(s):1100167
1116993
1117954
1188540
1196959
1197335
1198590
1199602
1200266
1200268
CVE-2018-13139
CVE-2018-19432
CVE-2018-19758
CVE-2021-3246
CVE-2021-39698
CVE-2022-1016
CVE-2022-1280
CVE-2022-1966
CVE-2022-1972
CVE-2022-30594
CVE-2022-32250
SUSE-SU-2022:2268-1
Platform(s):SUSE Linux Enterprise High Performance Computing 15 SP4
SUSE Linux Enterprise Module for Live Patching 15 SP4
SUSE Linux Enterprise Module for Open Buildservice Development Tools 15 SP2
SUSE Linux Enterprise Server 15 SP4
SUSE Linux Enterprise Server for SAP Applications 15 SP4
Product(s):
Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise High Performance Computing 15 SP4 is installed
  • OR SUSE Linux Enterprise Module for Live Patching 15 SP4 is installed
  • OR SUSE Linux Enterprise Server 15 SP4 is installed
  • OR SUSE Linux Enterprise Server for SAP Applications 15 SP4 is installed
  • AND kernel-livepatch-5_14_21-150400_22-default-2-150400.4.3.3 is installed
  • BACK