Mageia 2023-0007: kernel security update
Summary
This kernel update is based on upstream 5.15.88 and fixes atleast the
following security issues:
A use-after-free flaw was found in the Linux kernelâs SGI GRU driver in
the way the first gru_file_unlocked_ioctl function is called by the user,
where a fail pass occurs in the gru_check_chiplet_assignment function.
This flaw allows a local user to crash or potentially escalate their
privileges on the system (CVE-2022-3424).
A vulnerability in the function btf_dump_name_dups of the file
tools/lib/bpf/ btf_dump.c of the component libbpf. This flaw allows a
manipulation that may lea to a use-after-free issue (CVE-2022-3534).
A vulnerability was found in area_cache_get in drivers/net/ethernet/
netronome/nfp/nfpcore/nfp_cppcore.c in the Netronome Flow Processor (NFP)
driver in the Linux kernel. This flaw allows a manipulation that may lead
to a use-after-free issue (CVE-2022-3545).
An out-of-bounds memory write vulnerability was found in the Linux kernel
vmwgfx driver in vmw_kms_curso...
References
- https://bugs.mageia.org/show_bug.cgi?id=31405
- https://bugs.mageia.org/show_bug.cgi?id=31319
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.83
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.84
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.85
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.86
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.87
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.88
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3424
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3534
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-3545
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36280
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-41218
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-45934
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-47929
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0179
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0210
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-0266
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23454
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-23455
Resolution
MGASA-2023-0007 - Updated kernel packages fix security vulnerabilities
SRPMS
- 8/core/kernel-5.15.88-1.mga8
- 8/core/kmod-virtualbox-7.0.4-1.4.mga8
- 8/core/kmod-xtables-addons-3.23-1.2.mga8
- 8/core/xtables-addons-3.23-1.mga8