[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248392

 
 

909

 
 

195452

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

ALAS-2022-1604 --- kernel

ID: oval:org.secpod.oval:def:1601559Date: (C)2022-07-14   (M)2024-04-17
Class: PATCHFamily: unix




A kernel information leak flaw was identified in the scsi_ioctl function in drivers/scsi/scsi_ioctl.c in the Linux kernel. This flaw allows a local attacker with a special user privilege to create issues with confidentiality. An information leak flaw was found in NFS over RDMA in the net/sunrpc/xprtrdma/rpc_rdma.c function in RPCRDMA_HDRLEN_MIN . This flaw allows an attacker with normal user privileges to leak kernel information. Due to the small table perturb size, a memory leak flaw was found in the Linux kernel's TCP source port generation algorithm in the net/ipv4/tcp.c function. This flaw allows an attacker to leak information and may cause a denial of service. A use-after-free flaw was found in fs/ext4/namei.c:dx_insert_block in the Linux kernel's filesystem sub-component. This flaw allows a local attacker with a user privilege to cause a denial of service. A use-after-free vulnerability was found in the Linux kernel's Netfilter subsystem in net/netfilter/nf_tables_api.c. This flaw allows a local attacker with user access to cause a privilege escalation issue. net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free. The Linux kernel before 5.17.9 allows TCP servers to identify clients by observing what source ports are used. An issue was discovered in the Linux kernel through 5.18.3 on powerpc 32-bit platforms. There is a buffer overflow in ptrace PEEKUSER and POKEUSER when accessing floating point registers

Platform:
Amazon Linux AMI
Product:
kernel
perf
Reference:
ALAS-2022-1604
CVE-2022-0494
CVE-2022-0812
CVE-2022-1012
CVE-2022-1184
CVE-2022-1966
CVE-2022-32250
CVE-2022-32296
CVE-2022-32981
CVE    8
CVE-2022-1184
CVE-2022-0812
CVE-2022-1012
CVE-2022-0494
...

© SecPod Technologies