MGASA-2022-0278

Source
https://advisories.mageia.org/MGASA-2022-0278.html
Import Source
https://advisories.mageia.org/MGASA-2022-0278.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2022-0278
Related
Published
2022-08-06T15:43:47Z
Modified
2022-08-06T14:52:29Z
Summary
Updated kernel packages fix security vulnerabilities
Details

This kernel update is based on upstream 5.15.58 and fixes at least the following security issues:

Kernel lockdown bypass when UEFI secure boot is disabled / unavailable and IMA appraisal is enabled (CVE-2022-21505).

Aliases in the branch predictor may cause some AMD processors to predict the wrong branch type potentially leading to information disclosure (CVE-2022-23825).

Mis-trained branch predictions for return instructions may allow arbitrary speculative code execution under certain microarchitecture-dependent conditions (CVE-2022-29900, RetBleed).

Intel microprocessor generations 6 to 8 are affected by a new Spectre variant that is able to bypass their retpoline mitigation in the kernel to leak arbitrary data. An attacker with unprivileged user access can hijack return instructions to achieve arbitrary speculative code execution under certain microarchitecture-dependent conditions (CVE-2022-29901).

The Linux kernel before 5.18.13 lacks a certain clear operation for the block starting symbol (.bss). This allows Xen PV guest OS users to cause a denial of service or gain privileges (CVE-2022-36123).

An issue was discovered in the Linux kernel through 5.18.14. xfrmexpandpolicies in net/xfrm/xfrm_policy.c can cause a refcount to be dropped twice (CVE-2022-36879).

nfqnlmangle in net/netfilter/nfnetlinkqueue.c in the Linux kernel through 5.18.14 allows remote attackers to cause a denial of service (panic) because, in the case of an nfqueue verdict with a one-byte nftapayload attribute, an skb_pull can encounter a negative skb->len (CVE-2022-36946).

Other fixes in this update: - fs: sendfile handles ONONBLOCK of outfd - hugetlb: fix memoryleak in hugetlbmcopyatomic_pte - mm: fix page leak with multiple threads mapping the same page - x86/bugs: Do not enable IBPB at firmware entry when IBPB is not available - x86/speculation: Make all RETbleed mitigations 64-bit only

For other upstream fixes, see the referenced changelogs.

References
Credits

Affected packages

Mageia:8 / kernel

Package

Name
kernel
Purl
pkg:rpm/mageia/kernel?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.58-2.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / kmod-virtualbox

Package

Name
kmod-virtualbox
Purl
pkg:rpm/mageia/kmod-virtualbox?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.1.36-1.4.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / kmod-xtables-addons

Package

Name
kmod-xtables-addons
Purl
pkg:rpm/mageia/kmod-xtables-addons?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.20-1.30.mga8

Ecosystem specific

{
    "section": "core"
}