Anolis OS update for kernel



| Updated: 2025-03-29
Risk High
Patch available YES
Number of vulnerabilities 52
CVE-ID CVE-2020-0404
CVE-2020-13974
CVE-2020-27820
CVE-2020-4788
CVE-2021-0941
CVE-2021-20322
CVE-2021-21781
CVE-2021-26401
CVE-2017-5715
CVE-2021-29154
CVE-2021-3612
CVE-2021-3669
CVE-2021-37159
CVE-2021-3743
CVE-2021-3744
CVE-2019-18808
CVE-2021-3752
CVE-2021-3759
CVE-2021-3764
CVE-2021-3772
CVE-2021-3773
CVE-2021-4002
CVE-2021-4037
CVE-2018-13405
CVE-2021-4083
CVE-2021-4157
CVE-2021-41864
CVE-2021-4197
CVE-2021-4203
CVE-2021-42739
CVE-2021-43056
CVE-2021-43389
CVE-2021-43976
CVE-2021-44733
CVE-2021-45485
CVE-2021-45486
CVE-2022-0001
CVE-2022-0002
CVE-2022-0286
CVE-2022-0322
CVE-2022-1011
CVE-2021-47501
CVE-2021-47544
CVE-2021-47556
CVE-2021-47590
CVE-2021-47614
CVE-2022-48771
CVE-2021-47435
CVE-2021-47076
CVE-2021-47203
CVE-2021-47498
CVE-2022-48904
CWE-ID CWE-269
CWE-190
CWE-416
CWE-200
CWE-125
CWE-330
CWE-77
CWE-787
CWE-400
CWE-415
CWE-401
CWE-345
CWE-284
CWE-264
CWE-119
CWE-252
CWE-129
CWE-20
CWE-476
CWE-704
CWE-667
CWE-399
Exploitation vector Network
Public exploit Public exploit code for vulnerability #9 is available.
Public exploit code for vulnerability #21 is available.
Public exploit code for vulnerability #34 is available.
Public exploit code for vulnerability #41 is available.
Vulnerable software
Anolis OS
Operating systems & Components / Operating system

kernel-doc
Operating systems & Components / Operating system package or component

kernel-abi-stablelists
Operating systems & Components / Operating system package or component

python3-perf
Operating systems & Components / Operating system package or component

perf
Operating systems & Components / Operating system package or component

kernel-tools-libs
Operating systems & Components / Operating system package or component

kernel-tools
Operating systems & Components / Operating system package or component

kernel-modules-extra
Operating systems & Components / Operating system package or component

kernel-modules
Operating systems & Components / Operating system package or component

kernel-headers
Operating systems & Components / Operating system package or component

kernel-devel
Operating systems & Components / Operating system package or component

kernel-debug-modules-extra
Operating systems & Components / Operating system package or component

kernel-debug-modules
Operating systems & Components / Operating system package or component

kernel-debug-devel
Operating systems & Components / Operating system package or component

kernel-debug-core
Operating systems & Components / Operating system package or component

kernel-debug
Operating systems & Components / Operating system package or component

kernel-cross-headers
Operating systems & Components / Operating system package or component

kernel-core
Operating systems & Components / Operating system package or component

kernel
Operating systems & Components / Operating system package or component

bpftool
Operating systems & Components / Operating system package or component

Vendor OpenAnolis

Security Bulletin

This security bulletin contains information about 52 vulnerabilities.

1) Improper Privilege Management

EUVDB-ID: #VU46929

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2020-0404

CWE-ID: CWE-269 - Improper Privilege Management

Exploit availability: No

Description

The vulnerability allows a local authenticated user to execute arbitrary code.

In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-111893654References: Upstream kernel

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Integer overflow

EUVDB-ID: #VU64946

Risk: Low

CVSSv4.0: 4.4 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2020-13974

CWE-ID: CWE-190 - Integer overflow

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to integer overflow within drivers/tty/vt/keyboard.c if k_ascii is called several times in a row. A local user can trigger an integer overflow and execute arbitrary code with elevated privileges.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Use-after-free

EUVDB-ID: #VU63322

Risk: Low

CVSSv4.0: 1.9 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2020-27820

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to execute arbitrary code with elevated privileges.

The vulnerability exists due to a use-after-free error in nouveau's postclose() handler. A local user can send specially crafted data to the system and execute arbitrary code with elevated privileges.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

4) Information disclosure

EUVDB-ID: #VU48577

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2020-4788

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists in IBM Power9 processors due to unspecified error. A local user can obtain sensitive information from the data in the L1 cache under extenuating circumstances.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Out-of-bounds read

EUVDB-ID: #VU64702

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-0941

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists in __bpf_skb_max_len() function in net/core/filter.c in the Linux kernel. A local user with special privilege can gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

6) Use of insufficiently random values

EUVDB-ID: #VU63839

Risk: Medium

CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2021-20322

CWE-ID: CWE-330 - Use of Insufficiently Random Values

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to an error when processing received ICMP errors. A remote attacker can effectively bypass the source port UDP randomization to gain access to sensitive information.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

7) Information disclosure

EUVDB-ID: #VU54395

Risk: Low

CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-21781

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in the ARM SIGPAGE functionality. A userland application can read the contents of the sigpage, which can leak kernel memory contents.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

8) Information disclosure

EUVDB-ID: #VU61566

Risk: Low

CVSSv4.0: 1.9 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-26401

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output by the application within LFENCE/JMP. A local user can gain unauthorized access to sensitive information on the system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

9) Information disclosure

EUVDB-ID: #VU9883

Risk: Low

CVSSv4.0: 5.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Clear]

CVE-ID: CVE-2017-5715

CWE-ID: CWE-200 - Information exposure

Exploit availability: Yes

Description

The vulnerability allows a local attacker to obtain potentially sensitive information.

The vulnerability exists in Intel CPU hardware due to improper implementation of the speculative execution of instructions. A local attacker can utilize branch target injection, execute arbitrary code, perform a side-channel attack and read sensitive memory information.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.

10) Command Injection

EUVDB-ID: #VU56241

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-29154

CWE-ID: CWE-77 - Command injection

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to incorrect computation of branch displacements within the BPF JIT compilers in the Linux kernel in arch/x86/net/bpf_jit_comp.c and arch/x86/net/bpf_jit_comp32.c. A local user can inject and execute arbitrary commands with elevated privileges.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

11) Out-of-bounds write

EUVDB-ID: #VU55231

Risk: Low

CVSSv4.0: 4.4 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-3612

CWE-ID: CWE-787 - Out-of-bounds write

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error in joystick devices subsystem in Linux kernel. A local user can make a specially crafted JSIOCSBTNMAP IOCTL call, trigger out-of-bounds write and execute arbitrary code with escalated privileges.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

12) Resource exhaustion

EUVDB-ID: #VU63911

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-3669

CWE-ID: CWE-400 - Resource exhaustion

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to measuring usage of the shared memory does not scale with large shared memory segment counts. A local user can trigger resource exhaustion and perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

13) Double Free

EUVDB-ID: #VU63575

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-37159

CWE-ID: CWE-415 - Double Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to hso_free_net_device() function in drivers/net/usb/hso.c in the Linux kernel calls unregister_netdev without checking for the NETREG_REGISTERED state. A local user can trigger double free and use-after-free errors and execute arbitrary code with elevated privileges.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

14) Out-of-bounds read

EUVDB-ID: #VU63913

Risk: Low

CVSSv4.0: 4.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-3743

CWE-ID: CWE-125 - Out-of-bounds read

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service attack.

The vulnerability exists due to a boundary condition in the Qualcomm IPC router protocol in the Linux kernel. A local user can gain access to out-of-bounds memory to leak internal kernel information or perform a denial of service attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

15) Memory leak

EUVDB-ID: #VU63813

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-3744

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

Exploit availability: No

Description

The vulnerability allows a local user to perform DoS attack on the target system.

The vulnerability exists due memory leak in the ccp_run_aes_gcm_cmd() function in drivers/crypto/ccp/ccp-ops.c. A local user can force the application to leak memory and perform denial of service attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

16) Memory leak

EUVDB-ID: #VU24433

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2019-18808

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the "ccp_run_sha_cmd()" function in drivers/crypto/ccp/ccp-ops.c in the Linux kernel through 5.3.9 allows a local user to cause a denial of service (memory consumption).

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

17) Use-after-free

EUVDB-ID: #VU63767

Risk: Low

CVSSv4.0: 4.8 [CVSS:4.0/AV:A/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-3752

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a remote attacker to escalate privileges on the system.

The vulnerability exists due to a use-after-free error in the Linux kernel’s Bluetooth subsystem when a user calls connect to the socket and disconnect simultaneously. A local user can escalate privileges on the system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

18) Resource exhaustion

EUVDB-ID: #VU63914

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-3759

CWE-ID: CWE-400 - Resource exhaustion

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists in the Linux kernel’s ipc functionality of the memcg subsystem when user calls the semget function multiple times, creating semaphores. A local user can trigger resource exhaustion and perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

19) Memory leak

EUVDB-ID: #VU63817

Risk: Medium

CVSSv4.0: 4.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2021-3764

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak error in the ccp_run_aes_gcm_cmd() function in Linux kernel. A local user can trigger a memory leak error and perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

20) Insufficient verification of data authenticity

EUVDB-ID: #VU63835

Risk: Medium

CVSSv4.0: 6.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2021-3772

CWE-ID: CWE-345 - Insufficient Verification of Data Authenticity

Exploit availability: No

Description

The vulnerability allows a remote attacker to perform a denial of service attack (DoS) on the target system.

The vulnerability exists due to insufficient verification of data authenticity in the Linux SCTP stack. A remote attacker can exploit this vulnerability to perform a denial of service attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

21) Information disclosure

EUVDB-ID: #VU63920

Risk: Medium

CVSSv4.0: 7.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:P/U:Green]

CVE-ID: CVE-2021-3773

CWE-ID: CWE-200 - Information exposure

Exploit availability: Yes

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to excessive data output in the netfilter. A remote attacker can infer openvpn connection endpoint informationand gain unauthorized access to sensitive information on the system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.

22) Memory leak

EUVDB-ID: #VU63836

Risk: Low

CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-4002

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

Exploit availability: No

Description

The vulnerability allows a local user to gain access to sensitive information.

The vulnerability exists due memory leak in the Linux kernel's hugetlbfs memory usage. A local user can force the application to leak memory and gain access to sensitive information.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

23) Improper access control

EUVDB-ID: #VU63923

Risk: Low

CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-4037

CWE-ID: CWE-284 - Improper Access Control

Exploit availability: No

Description

The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.

The vulnerability exists due to improper access restrictions in the fs/inode.c:inode_init_owner() function logic of the Linux kernel. A local user can create files for the XFS file-system with an unintended group ownership and with group execution and SGID permission bits set to bypass implemented security restrictions and gain unauthorized access to the application.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

24) Security restrictions bypass

EUVDB-ID: #VU13631

Risk: Low

CVSSv4.0: 1.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2018-13405

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a local attacker to create arbitrary files on the target system.

The vulnerability exists due to the inode_init_owner function, as defined in the fs/inode.c source code file, allows the creation of arbitrary files in set-group identification (SGID) directories. A local attacker can create arbitrary files with unintended group ownership.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

25) Use-after-free

EUVDB-ID: #VU61246

Risk: Low

CVSSv4.0: 4.4 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-4083

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the Linux kernel's garbage collection for Unix domain socket file handlers. A local user can call close() and fget() simultaneously and can potentially trigger a race condition, which in turn leads to a use-after-free error and allows privilege escalation.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

26) Buffer overflow

EUVDB-ID: #VU63323

Risk: High

CVSSv4.0: 6.1 [CVSS:4.0/AV:A/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]

CVE-ID: CVE-2021-4157

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a remote attacker to execute arbitrary code on the target system.

The vulnerability exists due to a boundary error in the Linux kernel NFS subsystem. A remote attacker can create a specially crafted data and crash the system or escalate privileges on the system

Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated user via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

27) Out-of-bounds write

EUVDB-ID: #VU63855

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-41864

CWE-ID: CWE-787 - Out-of-bounds write

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error when processing untrusted input. A local user can gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel information.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

28) Security restrictions bypass

EUVDB-ID: #VU61258

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-4197

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to missing permissions checks within the cgroups (control groups) functionality of Linux Kernel when writing into a file descriptor. A local low privileged process can trick a higher privileged parent process into writing arbitrary data into files, which can result in denial of service or privileges escalation.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

29) Use-after-free

EUVDB-ID: #VU63838

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-4203

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error in sock_getsockopt() function in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() function (and connect() function) in the Linux kernel. A local user can exploit the use-after-free error and crash the system or escalate privileges on the system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

30) Buffer overflow

EUVDB-ID: #VU59474

Risk: Low

CVSSv4.0: 5.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-42739

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary within the firewire subsystem in the Linux kernel in drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c files. A local privileged user can run a specially crafted program tat calls avc_ca_pmt() function to trigger memory corruption and execute arbitrary code with elevated privileges.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

31) Unchecked Return Value

EUVDB-ID: #VU63921

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-43056

CWE-ID: CWE-252 - Unchecked Return Value

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service attack.

The vulnerability exists due to an arch/powerpc/kvm/book3s_hv_rmhandlers.S implementation error when handling SRR1 register values. A local user can perform a denial of service attack, when the host is running on Power8.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

32) Improper Validation of Array Index

EUVDB-ID: #VU63385

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-43389

CWE-ID: CWE-129 - Improper Validation of Array Index

Exploit availability: No

Description

The vulnerability allows a local user to execute arbitrary code with elevated privileges.

The vulnerability exists due to improper validation of array index in the ISDN CAPI implementation within detach_capi_ctr() function in drivers/isdn/capi/kcapi.c. local user can send specially crafted data to the system and execute arbitrary code with elevated privileges.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

33) Input validation error

EUVDB-ID: #VU61215

Risk: Low

CVSSv4.0: 1.7 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-43976

CWE-ID: CWE-20 - Improper input validation

Exploit availability: No

Description

The vulnerability allows an attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to insufficient validation of user-supplied input within the mwifiex_usb_recv() function in drivers/net/wireless/marvell/mwifiex/usb.c in Linux kernel. An attacker with physical access to the system can insert a specially crafted USB device and perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

34) Use-after-free

EUVDB-ID: #VU59100

Risk: Low

CVSSv4.0: 7.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Clear]

CVE-ID: CVE-2021-44733

CWE-ID: CWE-416 - Use After Free

Exploit availability: Yes

Description

The vulnerability allows a local user to elevate privileges on the system.

The vulnerability exists due to a use-after-free error in the drivers/tee/tee_shm.c file within the TEE subsystem in the Linux kernel. A local user can trigger a race condition in tee_shm_get_from_id during an attempt to free a shared memory object and execute arbitrary code with elevated privileges.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.

35) Information disclosure

EUVDB-ID: #VU63668

Risk: Medium

CVSSv4.0: 2.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2021-45485

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to sensitive information.

The vulnerability exists due to an error in the IPv6 implementation in the Linux kernel. A remote attacker can gain access to sensitive information.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

36) Information disclosure

EUVDB-ID: #VU63577

Risk: Medium

CVSSv4.0: 4.9 [CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green]

CVE-ID: CVE-2021-45486

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to incorrect implementation of the IPv4 protocol in the Linux kernel. A remote attacker can disclose internal state in some situations.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

37) Information disclosure

EUVDB-ID: #VU61198

Risk: Low

CVSSv4.0: 1.9 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-0001

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to non-transparent sharing of branch predictor selectors between contexts. A local user can gain unauthorized access to sensitive information on the system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

38) Information disclosure

EUVDB-ID: #VU61199

Risk: Low

CVSSv4.0: 1.9 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-0002

CWE-ID: CWE-200 - Information exposure

Exploit availability: No

Description

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to non-transparent sharing of branch predictor within a context. A local user can gain unauthorized access to sensitive information on the system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

39) NULL pointer dereference

EUVDB-ID: #VU63925

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-0286

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error in the Linux kernel’s bonding driver when user bonds non existing or fake device. A local user can perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

40) Type conversion

EUVDB-ID: #VU63856

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-0322

CWE-ID: CWE-704 - Type conversion

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service attack.

The vulnerability exists due to a type conversion error in the sctp_make_strreset_req() function in net/sctp/sm_make_chunk.c in the SCTP network protocol in the Linux kernel. A local user can perform a denial of service attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

41) Use-after-free

EUVDB-ID: #VU63386

Risk: Low

CVSSv4.0: 7.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Clear]

CVE-ID: CVE-2022-1011

CWE-ID: CWE-416 - Use After Free

Exploit availability: Yes

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error in the write() function of FUSE filesystem. A local user can retireve (partial) /etc/shadow hashes and execute arbitrary code with elevated privileges.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.

42) NULL pointer dereference

EUVDB-ID: #VU90392

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-47501

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the i40e_dbg_dump_desc() function in drivers/net/ethernet/intel/i40e/i40e_debugfs.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

43) Buffer overflow

EUVDB-ID: #VU93138

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-47544

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory corruption within the include/net/sock.h. A local user can perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

44) NULL pointer dereference

EUVDB-ID: #VU90530

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-47556

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the ethtool_set_coalesce() function in net/ethtool/ioctl.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

45) Improper locking

EUVDB-ID: #VU92354

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-47590

CWE-ID: CWE-667 - Improper Locking

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the __mptcp_push_pending() function in net/mptcp/protocol.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

46) Use-after-free

EUVDB-ID: #VU92993

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-47614

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the add_pble_prm() function in drivers/infiniband/hw/irdma/pble.c. A local user can escalate privileges on the system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

47) Use-after-free

EUVDB-ID: #VU92899

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-48771

CWE-ID: CWE-416 - Use After Free

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a use-after-free error within the vmw_kms_helper_buffer_finish() function in drivers/gpu/drm/vmwgfx/vmwgfx_kms.c, within the vmw_fence_event_ioctl() function in drivers/gpu/drm/vmwgfx/vmwgfx_fence.c, within the vmw_execbuf_fence_commands(), vmw_execbuf_copy_fence_user() and vmw_execbuf_process() functions in drivers/gpu/drm/vmwgfx/vmwgfx_execbuf.c. A local user can escalate privileges on the system.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

48) NULL pointer dereference

EUVDB-ID: #VU90405

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-47435

CWE-ID: CWE-476 - NULL Pointer Dereference

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the start_io_acct() and dec_pending() functions in drivers/md/dm.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

49) Resource exhaustion

EUVDB-ID: #VU92193

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-47076

CWE-ID: CWE-400 - Resource exhaustion

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to application does not properly control consumption of internal resources. A local user can trigger resource exhaustion and perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

50) Buffer overflow

EUVDB-ID: #VU93156

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-47203

CWE-ID: CWE-119 - Memory corruption

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory corruption within the lpfc_drain_txq() function in drivers/scsi/lpfc/lpfc_sli.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

51) Resource management error

EUVDB-ID: #VU92964

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-47498

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the dm_mq_queue_rq() function in drivers/md/dm-rq.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

52) Memory leak

EUVDB-ID: #VU96403

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-48904

CWE-ID: CWE-401 - Missing release of memory after effective lifetime

Exploit availability: No

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the v1_free_pgtable() function in drivers/iommu/amd/io_pgtable.c. A local user can perform a denial of service (DoS) attack.

Mitigation

Install updates from vendor's repository.

Vulnerable software versions

Anolis OS: 8

kernel-doc: before 4.18.0-372.9.1

kernel-abi-stablelists: before 4.18.0-372.9.1

python3-perf: before 4.18.0-372.9.1

perf: before 4.18.0-372.9.1

kernel-tools-libs: before 4.18.0-372.9.1

kernel-tools: before 4.18.0-372.9.1

kernel-modules-extra: before 4.18.0-372.9.1

kernel-modules: before 4.18.0-372.9.1

kernel-headers: before 4.18.0-372.9.1

kernel-devel: before 4.18.0-372.9.1

kernel-debug-modules-extra: before 4.18.0-372.9.1

kernel-debug-modules: before 4.18.0-372.9.1

kernel-debug-devel: before 4.18.0-372.9.1

kernel-debug-core: before 4.18.0-372.9.1

kernel-debug: before 4.18.0-372.9.1

kernel-cross-headers: before 4.18.0-372.9.1

kernel-core: before 4.18.0-372.9.1

kernel: before 4.18.0-372.9.1

bpftool: before 4.18.0-372.9.1

CPE2.3 External links

https://anas.openanolis.cn/errata/detail/ANSA-2022:0430


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###