MGASA-2022-0305

Source
https://advisories.mageia.org/MGASA-2022-0305.html
Import Source
https://advisories.mageia.org/MGASA-2022-0305.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2022-0305
Related
Published
2022-08-25T21:21:07Z
Modified
2022-08-25T20:18:02Z
Summary
Updated kernel packages fix security vulnerabilities
Details

This kernel update is based on upstream 5.15.62 and fixes at least the following security issues:

A use-after-free flaw was found in the Linux kernel Atheros wireless adapter driver in the way a user forces the ath9khtcwaitfortarget function to fail with some input messages. This flaw allows a local user to crash or potentially escalate their privileges on the system (CVE-2022-1679).

A use-after-free flaw was found in the Linux kernel’s POSIX CPU timers functionality in the way a user creates and then deletes the timer in the non-leader thread of the program. This flaw allows a local user to crash or potentially escalate their privileges on the system (CVE-2022-2585).

A use-after-free flaw was found in nftables cross-table in the net/netfilter/nftables_api.c function in the Linux kernel. This flaw allows a local, privileged attacker to cause a use-after-free problem at the time of table deletion, possibly leading to local privilege escalation (CVE-2022-2586).

A use-after-free flaw was found in route4change in the net/sched/clsroute.c filter implementation in the Linux kernel. This flaw allows a local, privileged attacker to crash the system, possibly leading to a local privilege escalation issue (CVE-2022-2588).

A flaw was found in hw. In certain processors with Intel's Enhanced Indirect Branch Restricted Speculation (eIBRS) capabilities, soon after VM exit or IBPB command event, the linear address following the most recent near CALL instruction prior to a VM exit may be used as the Return Stack Buffer (RSB) prediction (CVE-2022-26373).

x86/bugs: Enable STIBP for IBPB mitigated RETBleed.

Other fixes in this update: - add support for more tcp congestion control algos (mga #30725) - add fixes for a serious bug that causes TCP connection hangs for users of TCP fast open and nfconntrack - ALSA: info: Fix llseek return value when using callback - ALSA: hda/realtek: Add quirk for Clevo NS50PU, NS70PU - ata: libata-eh: Add missing command name - btrfs: fix lost error handling when looking up extended ref on log repla - btrfs: reset RO counter on block group if we fail to relocate - btrfs: unset reloc control if transaction commit fails in preparetorelocate() - drm/amd/display: Check correct bounds for stream encoder instances for DCN303 - drm/nouveau: recognise GA103 - drm/ttm: Fix dummy res NULL ptr deref bug - locking/atomic: Make testand*bit() ordered on failure - mmc: meson-gx: Fix an error handling path in mesonmmcprobe() - mmc: pxamci: Fix an error handling path in pxamciprobe() - mmc: pxamci: Fix another error handling path in pxamciprobe() - rds: add missing barrier to releaserefill - KVM: Unconditionally get a ref to /dev/kvm module when creating a VM - x86/mm: Use proper mask when setting PUD mapping - x86/entry: Fix entryINT80compat for Xen PV guests - x86/PAT: Have patenabled() properly reflect state when running on Xen - xfs: flush inodegc workqueue tasks before cancel - xfs: reserve quota for dir expansion when linking/unlinking files - xfs: reserve quota for target dir expansion when renaming files - xfs: remove infinite loop when reserving free block pool - xfs: always succeed at setting the reserve pool size - xfs: fix overfilling of reserve pool - xfs: fix soft lockup via spinning in filestream ag selection loop - xfs: revert "xfs: actually bump warning counts when we send warnings" - xfs: reject crazy array sizes being fed to XFSIOCGETBMAP*

xtables-addons have been updated to 3.21.

For other upstream fixes in this update, see the referenced changelogs.

References
Credits

Affected packages

Mageia:8 / kernel

Package

Name
kernel
Purl
pkg:rpm/mageia/kernel?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.62-1.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / kmod-virtualbox

Package

Name
kmod-virtualbox
Purl
pkg:rpm/mageia/kmod-virtualbox?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.1.36-1.10.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / kmod-xtables-addons

Package

Name
kmod-xtables-addons
Purl
pkg:rpm/mageia/kmod-xtables-addons?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.21-1.2.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / xtables-addons

Package

Name
xtables-addons
Purl
pkg:rpm/mageia/xtables-addons?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.21-1.mga8

Ecosystem specific

{
    "section": "core"
}