MGASA-2022-0041 - Updated kernel packages fix security vulnerabilities

Publication date: 01 Feb 2022
URL: https://advisories.mageia.org/MGASA-2022-0041.html
Type: security
Affected Mageia releases: 8
CVE: CVE-2022-0330,
     CVE-2022-22942,
     CVE-2022-24122

This kernel update is based on upstream 5.15.18 and fixes atleast the
following security issues:

A random memory access flaw was found in the Linux kernels GPU i915 kernel
driver functionality in the way a user may run malicious code on the GPU.
This flaw allows a local user to crash the system or escalate their
privileges on the system (CVE-2022-0330).

A use-after-free flaw was found in the Linux kernels
vmw_execbuf_copy_fence_user function in drivers/gpu/drm/vmwgfx/
vmwgfx_execbuf.c in vmwgfx. This flaw allows a local attacker with user
privileges to cause a privilege escalation problem (CVE-2022-22942).

kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged
user namespaces are enabled, allows a use-after-free and privilege
escalation because a ucounts object can outlive its namespace
(CVE-2022-24122).

Other fixes in this update:
- fix broken RTL8814AU support (mga#29952)
- fix cifs failing to load on server kernels (mga#29957)
- fix broken plymouth scaling (mga#29925)
- bpf: Guard against accessing NULL pt_regs in bpf_get_task_stack()
- fs/exec: require argv[0] presence in do_execveat_common()

For other upstream fixes, see the referenced changelogs.

References:
- https://bugs.mageia.org/show_bug.cgi?id=29960
- https://bugs.mageia.org/show_bug.cgi?id=29952
- https://bugs.mageia.org/show_bug.cgi?id=29957
- https://bugs.mageia.org/show_bug.cgi?id=29925
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.17
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.18
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0330
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22942
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24122

SRPMS:
- 8/core/kernel-5.15.18-2.mga8
- 8/core/kmod-virtualbox-6.1.32-1.4.mga8
- 8/core/kmod-xtables-addons-3.18-1.52.mga8

Mageia 8: MGASA-2022-0041 critical: kernel random access flaws

This kernel update is based on upstream 5.15.18 and fixes atleast the following security issues: A random memory access flaw was found in the Linux kernels GPU i915 kernel driver ...

Summary

This kernel update is based on upstream 5.15.18 and fixes atleast the following security issues:
A random memory access flaw was found in the Linux kernels GPU i915 kernel driver functionality in the way a user may run malicious code on the GPU. This flaw allows a local user to crash the system or escalate their privileges on the system (CVE-2022-0330).
A use-after-free flaw was found in the Linux kernels vmw_execbuf_copy_fence_user function in drivers/gpu/drm/vmwgfx/ vmwgfx_execbuf.c in vmwgfx. This flaw allows a local attacker with user privileges to cause a privilege escalation problem (CVE-2022-22942).
kernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged user namespaces are enabled, allows a use-after-free and privilege escalation because a ucounts object can outlive its namespace (CVE-2022-24122).
Other fixes in this update: - fix broken RTL8814AU support (mga#29952) - fix cifs failing to load on server kernels (mga#29957) - fix broken plymouth scaling (mg...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=29960

- https://bugs.mageia.org/show_bug.cgi?id=29952

- https://bugs.mageia.org/show_bug.cgi?id=29957

- https://bugs.mageia.org/show_bug.cgi?id=29925

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.17

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.18

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-0330

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-22942

- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-24122

Resolution

MGASA-2022-0041 - Updated kernel packages fix security vulnerabilities

SRPMS

- 8/core/kernel-5.15.18-2.mga8

- 8/core/kmod-virtualbox-6.1.32-1.4.mga8

- 8/core/kmod-xtables-addons-3.18-1.52.mga8

Severity
Publication date: 01 Feb 2022
URL: https://advisories.mageia.org/MGASA-2022-0041.html
Type: security
CVE: CVE-2022-0330, CVE-2022-22942, CVE-2022-24122

Related News