MGASA-2022-0229

Source
https://advisories.mageia.org/MGASA-2022-0229.html
Import Source
https://advisories.mageia.org/MGASA-2022-0229.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2022-0229
Related
Published
2022-06-13T20:44:20Z
Modified
2022-06-13T19:54:50Z
Summary
Updated kernel packages fix security vulnerabilities
Details

This kernel update is based on upstream 5.15.46 and fixes at least the following security issues:

KVM: x86: avoid calling x86 emulator without a decoded instruction (CVE-2022-1852).

A use-after-free vulnerability was found in the Linux kernel's Netfilter subsystem in net/netfilter/nftablesapi.c. This flaw allows a local attacker with user access to cause a privilege escalation issue (CVE-2022-1966).

An out-of-bound write vulnerability was identified within the netfilter subsystem which can be exploited to achieve privilege escalation to root. In order to trigger the issue it requires the ability to create user/net namespaces (CVE-2022-1972).

fs/ntfs3: Fix invalid free in log_replay (CVE-2022-1973).

Other fixes in this update: - x86/amdnb: Add AMD Family 17h A0-AF IDs - x86/amdnb: Add Family 19h model 70h-7Fh IDs - x86/amd_nb: Add Family 19h model 60h-6Fh IDs - hwmon: (k10temp): Add support for family 17h models A0h-AFh - hwmon: (k10temp): Add support for family 19h models 70h-7Fh - hwmon: (k10temp): Add support for family 19h models 60h-6Fh

For other upstream fixes, see the referenced changelogs.

References
Credits

Affected packages

Mageia:8 / kernel

Package

Name
kernel
Purl
pkg:rpm/mageia/kernel?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.46-1.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / kmod-virtualbox

Package

Name
kmod-virtualbox
Purl
pkg:rpm/mageia/kmod-virtualbox?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.1.34-1.14.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / kmod-xtables-addons

Package

Name
kmod-xtables-addons
Purl
pkg:rpm/mageia/kmod-xtables-addons?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.20-1.12.mga8

Ecosystem specific

{
    "section": "core"
}