Risk | Low |
Patch available | YES |
Number of vulnerabilities | 3 |
CVE-ID | CVE-2022-1729 CVE-2022-20154 CVE-2022-21499 |
CWE-ID | CWE-362 CWE-264 CWE-284 |
Exploitation vector | Local |
Public exploit | N/A |
Vulnerable software |
SUSE Linux Enterprise Live Patching Operating systems & Components / Operating system kgraft-patch-4_12_14-95_93-default Operating systems & Components / Operating system package or component kgraft-patch-4_12_14-122_98-default Operating systems & Components / Operating system package or component kgraft-patch-4_12_14-122_91-default Operating systems & Components / Operating system package or component kgraft-patch-4_12_14-122_116-default Operating systems & Components / Operating system package or component |
Vendor | SUSE |
Security Bulletin
This security bulletin contains information about 3 vulnerabilities.
EUVDB-ID: #VU64156
Risk: Low
CVSSv4.0: 4.4 [CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-1729
Exploit availability: No
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to a race condition within sys_perf_event_open() in Linux kernel. A local user can exploit the race and gain unauthorized access to sensitive information and escalate privileges on the system.
MitigationUpdate the affected package the Linux Kernel (Live Patch 30 for SLE 12 SP5) to the latest version.
Vulnerable software versionsSUSE Linux Enterprise Live Patching: 12-SP4 - 12-SP5
kgraft-patch-4_12_14-95_93-default: before 6-2.3
kgraft-patch-4_12_14-122_98-default: before 12-2.3
kgraft-patch-4_12_14-122_91-default: before 14-2.3
kgraft-patch-4_12_14-122_116-default: before 5-2.3
CPE2.3https://www.suse.com/support/update/announcement/2022/suse-su-20222438-1/
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU64207
Risk: Low
CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-20154
CWE-ID:
CWE-264 - Permissions, Privileges, and Access Controls
Exploit availability: No
DescriptionThe vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to unspecified error in the Linux Kernel. A local user can bypass security restrictions and escalate privileges on the system.
Update the affected package the Linux Kernel (Live Patch 30 for SLE 12 SP5) to the latest version.
Vulnerable software versionsSUSE Linux Enterprise Live Patching: 12-SP4 - 12-SP5
kgraft-patch-4_12_14-95_93-default: before 6-2.3
kgraft-patch-4_12_14-122_98-default: before 12-2.3
kgraft-patch-4_12_14-122_91-default: before 14-2.3
kgraft-patch-4_12_14-122_116-default: before 5-2.3
CPE2.3https://www.suse.com/support/update/announcement/2022/suse-su-20222438-1/
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.
EUVDB-ID: #VU63961
Risk: Low
CVSSv4.0: 5.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]
CVE-ID: CVE-2022-21499
CWE-ID:
CWE-284 - Improper Access Control
Exploit availability: No
DescriptionThe vulnerability allows a local user to bypass implemented security restrictions.
The vulnerability exists due to improper access restrictions to the kernel debugger when booted in secure boot environments. A local privileged user can bypass UEFI Secure Boot restrictions.
MitigationUpdate the affected package the Linux Kernel (Live Patch 30 for SLE 12 SP5) to the latest version.
Vulnerable software versionsSUSE Linux Enterprise Live Patching: 12-SP4 - 12-SP5
kgraft-patch-4_12_14-95_93-default: before 6-2.3
kgraft-patch-4_12_14-122_98-default: before 12-2.3
kgraft-patch-4_12_14-122_91-default: before 14-2.3
kgraft-patch-4_12_14-122_116-default: before 5-2.3
CPE2.3https://www.suse.com/support/update/announcement/2022/suse-su-20222438-1/
Q & A
Can this vulnerability be exploited remotely?
No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.