SUSE update for the Linux Kernel



| Updated: 2022-08-25
Risk Low
Patch available YES
Number of vulnerabilities 5
CVE-ID CVE-2021-33655
CVE-2022-21505
CVE-2022-2585
CVE-2022-26373
CVE-2022-29581
CWE-ID CWE-787
CWE-254
CWE-399
CWE-264
CWE-911
Exploitation vector Local
Public exploit Public exploit code for vulnerability #3 is available.
Vulnerable software
SUSE Linux Enterprise Module for Live Patching
Operating systems & Components / Operating system

SUSE Linux Enterprise Module for Legacy Software
Operating systems & Components / Operating system

SUSE Manager Retail Branch Server
Operating systems & Components / Operating system

SUSE Linux Enterprise Server for SAP Applications
Operating systems & Components / Operating system

SUSE Linux Enterprise High Performance Computing
Operating systems & Components / Operating system

SUSE Linux Enterprise High Availability
Operating systems & Components / Operating system

SUSE Linux Enterprise Server
Operating systems & Components / Operating system

SUSE Linux Enterprise Workstation Extension
Operating systems & Components / Operating system

SUSE Manager Server
Operating systems & Components / Operating system

SUSE Manager Proxy
Operating systems & Components / Operating system

SUSE Linux Enterprise Module for Development Tools
Operating systems & Components / Operating system

SUSE Linux Enterprise Module for Basesystem
Operating systems & Components / Operating system

SUSE Linux Enterprise Desktop
Operating systems & Components / Operating system

openSUSE Leap
Operating systems & Components / Operating system

kernel-livepatch-SLE15-SP4_Update_2-debugsource
Operating systems & Components / Operating system package or component

kernel-livepatch-5_14_21-150400_24_18-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-livepatch-5_14_21-150400_24_18-default
Operating systems & Components / Operating system package or component

kernel-zfcpdump-debugsource
Operating systems & Components / Operating system package or component

kernel-zfcpdump-debuginfo
Operating systems & Components / Operating system package or component

kernel-zfcpdump
Operating systems & Components / Operating system package or component

kernel-source-vanilla
Operating systems & Components / Operating system package or component

kernel-source
Operating systems & Components / Operating system package or component

kernel-macros
Operating systems & Components / Operating system package or component

kernel-docs-html
Operating systems & Components / Operating system package or component

kernel-docs
Operating systems & Components / Operating system package or component

kernel-devel
Operating systems & Components / Operating system package or component

reiserfs-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

reiserfs-kmp-64kb
Operating systems & Components / Operating system package or component

ocfs2-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

ocfs2-kmp-64kb
Operating systems & Components / Operating system package or component

kselftests-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

kselftests-kmp-64kb
Operating systems & Components / Operating system package or component

kernel-64kb-optional-debuginfo
Operating systems & Components / Operating system package or component

kernel-64kb-optional
Operating systems & Components / Operating system package or component

kernel-64kb-livepatch-devel
Operating systems & Components / Operating system package or component

kernel-64kb-extra-debuginfo
Operating systems & Components / Operating system package or component

kernel-64kb-extra
Operating systems & Components / Operating system package or component

kernel-64kb-devel-debuginfo
Operating systems & Components / Operating system package or component

kernel-64kb-devel
Operating systems & Components / Operating system package or component

kernel-64kb-debugsource
Operating systems & Components / Operating system package or component

kernel-64kb-debuginfo
Operating systems & Components / Operating system package or component

kernel-64kb
Operating systems & Components / Operating system package or component

gfs2-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

gfs2-kmp-64kb
Operating systems & Components / Operating system package or component

dtb-xilinx
Operating systems & Components / Operating system package or component

dtb-sprd
Operating systems & Components / Operating system package or component

dtb-socionext
Operating systems & Components / Operating system package or component

dtb-rockchip
Operating systems & Components / Operating system package or component

dtb-renesas
Operating systems & Components / Operating system package or component

dtb-qcom
Operating systems & Components / Operating system package or component

dtb-nvidia
Operating systems & Components / Operating system package or component

dtb-mediatek
Operating systems & Components / Operating system package or component

dtb-marvell
Operating systems & Components / Operating system package or component

dtb-lg
Operating systems & Components / Operating system package or component

dtb-hisilicon
Operating systems & Components / Operating system package or component

dtb-freescale
Operating systems & Components / Operating system package or component

dtb-exynos
Operating systems & Components / Operating system package or component

dtb-cavium
Operating systems & Components / Operating system package or component

dtb-broadcom
Operating systems & Components / Operating system package or component

dtb-arm
Operating systems & Components / Operating system package or component

dtb-apple
Operating systems & Components / Operating system package or component

dtb-apm
Operating systems & Components / Operating system package or component

dtb-amlogic
Operating systems & Components / Operating system package or component

dtb-amd
Operating systems & Components / Operating system package or component

dtb-amazon
Operating systems & Components / Operating system package or component

dtb-altera
Operating systems & Components / Operating system package or component

dtb-allwinner
Operating systems & Components / Operating system package or component

dlm-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

dlm-kmp-64kb
Operating systems & Components / Operating system package or component

cluster-md-kmp-64kb-debuginfo
Operating systems & Components / Operating system package or component

cluster-md-kmp-64kb
Operating systems & Components / Operating system package or component

kernel-debug-livepatch-devel
Operating systems & Components / Operating system package or component

kernel-debug-devel-debuginfo
Operating systems & Components / Operating system package or component

kernel-debug-devel
Operating systems & Components / Operating system package or component

kernel-debug-debugsource
Operating systems & Components / Operating system package or component

kernel-debug-debuginfo
Operating systems & Components / Operating system package or component

kernel-debug
Operating systems & Components / Operating system package or component

kernel-kvmsmall-livepatch-devel
Operating systems & Components / Operating system package or component

kernel-kvmsmall-devel-debuginfo
Operating systems & Components / Operating system package or component

kernel-kvmsmall-devel
Operating systems & Components / Operating system package or component

kernel-kvmsmall-debugsource
Operating systems & Components / Operating system package or component

kernel-kvmsmall-debuginfo
Operating systems & Components / Operating system package or component

kernel-kvmsmall
Operating systems & Components / Operating system package or component

reiserfs-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

reiserfs-kmp-default
Operating systems & Components / Operating system package or component

ocfs2-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

ocfs2-kmp-default
Operating systems & Components / Operating system package or component

kselftests-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

kselftests-kmp-default
Operating systems & Components / Operating system package or component

kernel-syms
Operating systems & Components / Operating system package or component

kernel-obs-qa
Operating systems & Components / Operating system package or component

kernel-obs-build-debugsource
Operating systems & Components / Operating system package or component

kernel-obs-build
Operating systems & Components / Operating system package or component

kernel-default-optional-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-optional
Operating systems & Components / Operating system package or component

kernel-default-livepatch-devel
Operating systems & Components / Operating system package or component

kernel-default-livepatch
Operating systems & Components / Operating system package or component

kernel-default-extra-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-extra
Operating systems & Components / Operating system package or component

kernel-default-devel-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-devel
Operating systems & Components / Operating system package or component

kernel-default-debugsource
Operating systems & Components / Operating system package or component

kernel-default-debuginfo
Operating systems & Components / Operating system package or component

kernel-default-base-rebuild
Operating systems & Components / Operating system package or component

kernel-default-base
Operating systems & Components / Operating system package or component

kernel-default
Operating systems & Components / Operating system package or component

gfs2-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

gfs2-kmp-default
Operating systems & Components / Operating system package or component

dlm-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

dlm-kmp-default
Operating systems & Components / Operating system package or component

cluster-md-kmp-default-debuginfo
Operating systems & Components / Operating system package or component

cluster-md-kmp-default
Operating systems & Components / Operating system package or component

Vendor SUSE

Security Bulletin

This security bulletin contains information about 5 vulnerabilities.

1) Out-of-bounds write

EUVDB-ID: #VU65833

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2021-33655

CWE-ID: CWE-787 - Out-of-bounds write

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error in FBIOPUT_VSCREENINFO IOCTL. A local user can trigger an out-of-bounds write error and execute arbitrary code with elevated privileges.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Module for Live Patching: 15-SP4

SUSE Linux Enterprise Module for Legacy Software: 15-SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Linux Enterprise Server for SAP Applications: 12-SP4 - 15-SP4

SUSE Linux Enterprise High Performance Computing: 12 - 15-SP4

SUSE Linux Enterprise High Availability: 15-SP4

SUSE Linux Enterprise Server: 11-SP3-CLIENT-TOOLS-BETA - 15-SP4

SUSE Linux Enterprise Workstation Extension: 15-SP4

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

SUSE Linux Enterprise Module for Development Tools: 15-SP4

SUSE Linux Enterprise Module for Basesystem: 15-SP4

SUSE Linux Enterprise Desktop: 15-SP4

openSUSE Leap: 15.4

kernel-livepatch-SLE15-SP4_Update_2-debugsource: before 1-150400.9.5.2

kernel-livepatch-5_14_21-150400_24_18-default-debuginfo: before 1-150400.9.5.2

kernel-livepatch-5_14_21-150400_24_18-default: before 1-150400.9.5.2

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.18.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.18.1

kernel-zfcpdump: before 5.14.21-150400.24.18.1

kernel-source-vanilla: before 5.14.21-150400.24.18.1

kernel-source: before 5.14.21-150400.24.18.1

kernel-macros: before 5.14.21-150400.24.18.1

kernel-docs-html: before 5.14.21-150400.24.18.1

kernel-docs: before 5.14.21-150400.24.18.1

kernel-devel: before 5.14.21-150400.24.18.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.18.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.18.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

kselftests-kmp-64kb: before 5.14.21-150400.24.18.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb-optional: before 5.14.21-150400.24.18.1

kernel-64kb-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb-extra: before 5.14.21-150400.24.18.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb-devel: before 5.14.21-150400.24.18.1

kernel-64kb-debugsource: before 5.14.21-150400.24.18.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb: before 5.14.21-150400.24.18.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

gfs2-kmp-64kb: before 5.14.21-150400.24.18.1

dtb-xilinx: before 5.14.21-150400.24.18.1

dtb-sprd: before 5.14.21-150400.24.18.1

dtb-socionext: before 5.14.21-150400.24.18.1

dtb-rockchip: before 5.14.21-150400.24.18.1

dtb-renesas: before 5.14.21-150400.24.18.1

dtb-qcom: before 5.14.21-150400.24.18.1

dtb-nvidia: before 5.14.21-150400.24.18.1

dtb-mediatek: before 5.14.21-150400.24.18.1

dtb-marvell: before 5.14.21-150400.24.18.1

dtb-lg: before 5.14.21-150400.24.18.1

dtb-hisilicon: before 5.14.21-150400.24.18.1

dtb-freescale: before 5.14.21-150400.24.18.1

dtb-exynos: before 5.14.21-150400.24.18.1

dtb-cavium: before 5.14.21-150400.24.18.1

dtb-broadcom: before 5.14.21-150400.24.18.1

dtb-arm: before 5.14.21-150400.24.18.1

dtb-apple: before 5.14.21-150400.24.18.1

dtb-apm: before 5.14.21-150400.24.18.1

dtb-amlogic: before 5.14.21-150400.24.18.1

dtb-amd: before 5.14.21-150400.24.18.1

dtb-amazon: before 5.14.21-150400.24.18.1

dtb-altera: before 5.14.21-150400.24.18.1

dtb-allwinner: before 5.14.21-150400.24.18.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

dlm-kmp-64kb: before 5.14.21-150400.24.18.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.18.1

kernel-debug-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-debug-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-debug-devel: before 5.14.21-150400.24.18.1

kernel-debug-debugsource: before 5.14.21-150400.24.18.1

kernel-debug-debuginfo: before 5.14.21-150400.24.18.1

kernel-debug: before 5.14.21-150400.24.18.1

kernel-kvmsmall-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.18.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.18.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.18.1

kernel-kvmsmall: before 5.14.21-150400.24.18.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

reiserfs-kmp-default: before 5.14.21-150400.24.18.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

ocfs2-kmp-default: before 5.14.21-150400.24.18.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

kselftests-kmp-default: before 5.14.21-150400.24.18.1

kernel-syms: before 5.14.21-150400.24.18.1

kernel-obs-qa: before 5.14.21-150400.24.18.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.18.1

kernel-obs-build: before 5.14.21-150400.24.18.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-optional: before 5.14.21-150400.24.18.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-default-livepatch: before 5.14.21-150400.24.18.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-extra: before 5.14.21-150400.24.18.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-devel: before 5.14.21-150400.24.18.1

kernel-default-debugsource: before 5.14.21-150400.24.18.1

kernel-default-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-base-rebuild: before 5.14.21-150400.24.18.1.150400.24.5.4

kernel-default-base: before 5.14.21-150400.24.18.1.150400.24.5.4

kernel-default: before 5.14.21-150400.24.18.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

gfs2-kmp-default: before 5.14.21-150400.24.18.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

dlm-kmp-default: before 5.14.21-150400.24.18.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

cluster-md-kmp-default: before 5.14.21-150400.24.18.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2022/suse-su-20222803-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

2) Security features bypass

EUVDB-ID: #VU66592

Risk: Low

CVSSv4.0: 4 [CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-21505

CWE-ID: CWE-254 - Security Features

Exploit availability: No

Description

The vulnerability allows an attacker to bypass implemented security restrictions.

The vulnerability exists due to incorrect implementation of the IMA lockdown feature. If IMA appraisal is used with the "ima_appraise=log" boot param, lockdown can be defeated with kexec on any machine with Secure Boot. An attacker with physical access to device can bypass Secure Boot mechanism.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Module for Live Patching: 15-SP4

SUSE Linux Enterprise Module for Legacy Software: 15-SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Linux Enterprise Server for SAP Applications: 12-SP4 - 15-SP4

SUSE Linux Enterprise High Performance Computing: 12 - 15-SP4

SUSE Linux Enterprise High Availability: 15-SP4

SUSE Linux Enterprise Server: 11-SP3-CLIENT-TOOLS-BETA - 15-SP4

SUSE Linux Enterprise Workstation Extension: 15-SP4

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

SUSE Linux Enterprise Module for Development Tools: 15-SP4

SUSE Linux Enterprise Module for Basesystem: 15-SP4

SUSE Linux Enterprise Desktop: 15-SP4

openSUSE Leap: 15.4

kernel-livepatch-SLE15-SP4_Update_2-debugsource: before 1-150400.9.5.2

kernel-livepatch-5_14_21-150400_24_18-default-debuginfo: before 1-150400.9.5.2

kernel-livepatch-5_14_21-150400_24_18-default: before 1-150400.9.5.2

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.18.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.18.1

kernel-zfcpdump: before 5.14.21-150400.24.18.1

kernel-source-vanilla: before 5.14.21-150400.24.18.1

kernel-source: before 5.14.21-150400.24.18.1

kernel-macros: before 5.14.21-150400.24.18.1

kernel-docs-html: before 5.14.21-150400.24.18.1

kernel-docs: before 5.14.21-150400.24.18.1

kernel-devel: before 5.14.21-150400.24.18.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.18.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.18.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

kselftests-kmp-64kb: before 5.14.21-150400.24.18.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb-optional: before 5.14.21-150400.24.18.1

kernel-64kb-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb-extra: before 5.14.21-150400.24.18.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb-devel: before 5.14.21-150400.24.18.1

kernel-64kb-debugsource: before 5.14.21-150400.24.18.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb: before 5.14.21-150400.24.18.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

gfs2-kmp-64kb: before 5.14.21-150400.24.18.1

dtb-xilinx: before 5.14.21-150400.24.18.1

dtb-sprd: before 5.14.21-150400.24.18.1

dtb-socionext: before 5.14.21-150400.24.18.1

dtb-rockchip: before 5.14.21-150400.24.18.1

dtb-renesas: before 5.14.21-150400.24.18.1

dtb-qcom: before 5.14.21-150400.24.18.1

dtb-nvidia: before 5.14.21-150400.24.18.1

dtb-mediatek: before 5.14.21-150400.24.18.1

dtb-marvell: before 5.14.21-150400.24.18.1

dtb-lg: before 5.14.21-150400.24.18.1

dtb-hisilicon: before 5.14.21-150400.24.18.1

dtb-freescale: before 5.14.21-150400.24.18.1

dtb-exynos: before 5.14.21-150400.24.18.1

dtb-cavium: before 5.14.21-150400.24.18.1

dtb-broadcom: before 5.14.21-150400.24.18.1

dtb-arm: before 5.14.21-150400.24.18.1

dtb-apple: before 5.14.21-150400.24.18.1

dtb-apm: before 5.14.21-150400.24.18.1

dtb-amlogic: before 5.14.21-150400.24.18.1

dtb-amd: before 5.14.21-150400.24.18.1

dtb-amazon: before 5.14.21-150400.24.18.1

dtb-altera: before 5.14.21-150400.24.18.1

dtb-allwinner: before 5.14.21-150400.24.18.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

dlm-kmp-64kb: before 5.14.21-150400.24.18.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.18.1

kernel-debug-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-debug-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-debug-devel: before 5.14.21-150400.24.18.1

kernel-debug-debugsource: before 5.14.21-150400.24.18.1

kernel-debug-debuginfo: before 5.14.21-150400.24.18.1

kernel-debug: before 5.14.21-150400.24.18.1

kernel-kvmsmall-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.18.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.18.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.18.1

kernel-kvmsmall: before 5.14.21-150400.24.18.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

reiserfs-kmp-default: before 5.14.21-150400.24.18.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

ocfs2-kmp-default: before 5.14.21-150400.24.18.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

kselftests-kmp-default: before 5.14.21-150400.24.18.1

kernel-syms: before 5.14.21-150400.24.18.1

kernel-obs-qa: before 5.14.21-150400.24.18.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.18.1

kernel-obs-build: before 5.14.21-150400.24.18.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-optional: before 5.14.21-150400.24.18.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-default-livepatch: before 5.14.21-150400.24.18.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-extra: before 5.14.21-150400.24.18.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-devel: before 5.14.21-150400.24.18.1

kernel-default-debugsource: before 5.14.21-150400.24.18.1

kernel-default-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-base-rebuild: before 5.14.21-150400.24.18.1.150400.24.5.4

kernel-default-base: before 5.14.21-150400.24.18.1.150400.24.5.4

kernel-default: before 5.14.21-150400.24.18.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

gfs2-kmp-default: before 5.14.21-150400.24.18.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

dlm-kmp-default: before 5.14.21-150400.24.18.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

cluster-md-kmp-default: before 5.14.21-150400.24.18.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2022/suse-su-20222803-1/


Q & A

Can this vulnerability be exploited remotely?

No. The attacker should have physical access to the system in order to successfully exploit this vulnerability.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

3) Resource management error

EUVDB-ID: #VU66394

Risk: Low

CVSSv4.0: 7.1 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/U:Clear]

CVE-ID: CVE-2022-2585

CWE-ID: CWE-399 - Resource Management Errors

Exploit availability: Yes

Description

The vulnerability allows a local user to perform a denial of service (DoS) attack or escalate privileges on the system.

The vulnerability exists due to improper management of internal resources in POSIX CPU timers when handling death of a process. A local user can crash the kernel or execute arbitrary code.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Module for Live Patching: 15-SP4

SUSE Linux Enterprise Module for Legacy Software: 15-SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Linux Enterprise Server for SAP Applications: 12-SP4 - 15-SP4

SUSE Linux Enterprise High Performance Computing: 12 - 15-SP4

SUSE Linux Enterprise High Availability: 15-SP4

SUSE Linux Enterprise Server: 11-SP3-CLIENT-TOOLS-BETA - 15-SP4

SUSE Linux Enterprise Workstation Extension: 15-SP4

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

SUSE Linux Enterprise Module for Development Tools: 15-SP4

SUSE Linux Enterprise Module for Basesystem: 15-SP4

SUSE Linux Enterprise Desktop: 15-SP4

openSUSE Leap: 15.4

kernel-livepatch-SLE15-SP4_Update_2-debugsource: before 1-150400.9.5.2

kernel-livepatch-5_14_21-150400_24_18-default-debuginfo: before 1-150400.9.5.2

kernel-livepatch-5_14_21-150400_24_18-default: before 1-150400.9.5.2

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.18.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.18.1

kernel-zfcpdump: before 5.14.21-150400.24.18.1

kernel-source-vanilla: before 5.14.21-150400.24.18.1

kernel-source: before 5.14.21-150400.24.18.1

kernel-macros: before 5.14.21-150400.24.18.1

kernel-docs-html: before 5.14.21-150400.24.18.1

kernel-docs: before 5.14.21-150400.24.18.1

kernel-devel: before 5.14.21-150400.24.18.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.18.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.18.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

kselftests-kmp-64kb: before 5.14.21-150400.24.18.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb-optional: before 5.14.21-150400.24.18.1

kernel-64kb-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb-extra: before 5.14.21-150400.24.18.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb-devel: before 5.14.21-150400.24.18.1

kernel-64kb-debugsource: before 5.14.21-150400.24.18.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb: before 5.14.21-150400.24.18.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

gfs2-kmp-64kb: before 5.14.21-150400.24.18.1

dtb-xilinx: before 5.14.21-150400.24.18.1

dtb-sprd: before 5.14.21-150400.24.18.1

dtb-socionext: before 5.14.21-150400.24.18.1

dtb-rockchip: before 5.14.21-150400.24.18.1

dtb-renesas: before 5.14.21-150400.24.18.1

dtb-qcom: before 5.14.21-150400.24.18.1

dtb-nvidia: before 5.14.21-150400.24.18.1

dtb-mediatek: before 5.14.21-150400.24.18.1

dtb-marvell: before 5.14.21-150400.24.18.1

dtb-lg: before 5.14.21-150400.24.18.1

dtb-hisilicon: before 5.14.21-150400.24.18.1

dtb-freescale: before 5.14.21-150400.24.18.1

dtb-exynos: before 5.14.21-150400.24.18.1

dtb-cavium: before 5.14.21-150400.24.18.1

dtb-broadcom: before 5.14.21-150400.24.18.1

dtb-arm: before 5.14.21-150400.24.18.1

dtb-apple: before 5.14.21-150400.24.18.1

dtb-apm: before 5.14.21-150400.24.18.1

dtb-amlogic: before 5.14.21-150400.24.18.1

dtb-amd: before 5.14.21-150400.24.18.1

dtb-amazon: before 5.14.21-150400.24.18.1

dtb-altera: before 5.14.21-150400.24.18.1

dtb-allwinner: before 5.14.21-150400.24.18.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

dlm-kmp-64kb: before 5.14.21-150400.24.18.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.18.1

kernel-debug-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-debug-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-debug-devel: before 5.14.21-150400.24.18.1

kernel-debug-debugsource: before 5.14.21-150400.24.18.1

kernel-debug-debuginfo: before 5.14.21-150400.24.18.1

kernel-debug: before 5.14.21-150400.24.18.1

kernel-kvmsmall-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.18.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.18.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.18.1

kernel-kvmsmall: before 5.14.21-150400.24.18.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

reiserfs-kmp-default: before 5.14.21-150400.24.18.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

ocfs2-kmp-default: before 5.14.21-150400.24.18.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

kselftests-kmp-default: before 5.14.21-150400.24.18.1

kernel-syms: before 5.14.21-150400.24.18.1

kernel-obs-qa: before 5.14.21-150400.24.18.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.18.1

kernel-obs-build: before 5.14.21-150400.24.18.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-optional: before 5.14.21-150400.24.18.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-default-livepatch: before 5.14.21-150400.24.18.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-extra: before 5.14.21-150400.24.18.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-devel: before 5.14.21-150400.24.18.1

kernel-default-debugsource: before 5.14.21-150400.24.18.1

kernel-default-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-base-rebuild: before 5.14.21-150400.24.18.1.150400.24.5.4

kernel-default-base: before 5.14.21-150400.24.18.1.150400.24.5.4

kernel-default: before 5.14.21-150400.24.18.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

gfs2-kmp-default: before 5.14.21-150400.24.18.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

dlm-kmp-default: before 5.14.21-150400.24.18.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

cluster-md-kmp-default: before 5.14.21-150400.24.18.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2022/suse-su-20222803-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.

4) Security restrictions bypass

EUVDB-ID: #VU66549

Risk: Low

CVSSv4.0: 4.3 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-26373

CWE-ID: CWE-264 - Permissions, Privileges, and Access Controls

Exploit availability: No

Description

The vulnerability allows a local user to gain access to potentially sensitive information.

The vulnerability exists due to non-transparent sharing of return predictor targets between contexts in Intel CPU processors. A local user can bypass the expected architecture isolation between contexts and gain access to sensitive information on the system.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Module for Live Patching: 15-SP4

SUSE Linux Enterprise Module for Legacy Software: 15-SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Linux Enterprise Server for SAP Applications: 12-SP4 - 15-SP4

SUSE Linux Enterprise High Performance Computing: 12 - 15-SP4

SUSE Linux Enterprise High Availability: 15-SP4

SUSE Linux Enterprise Server: 11-SP3-CLIENT-TOOLS-BETA - 15-SP4

SUSE Linux Enterprise Workstation Extension: 15-SP4

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

SUSE Linux Enterprise Module for Development Tools: 15-SP4

SUSE Linux Enterprise Module for Basesystem: 15-SP4

SUSE Linux Enterprise Desktop: 15-SP4

openSUSE Leap: 15.4

kernel-livepatch-SLE15-SP4_Update_2-debugsource: before 1-150400.9.5.2

kernel-livepatch-5_14_21-150400_24_18-default-debuginfo: before 1-150400.9.5.2

kernel-livepatch-5_14_21-150400_24_18-default: before 1-150400.9.5.2

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.18.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.18.1

kernel-zfcpdump: before 5.14.21-150400.24.18.1

kernel-source-vanilla: before 5.14.21-150400.24.18.1

kernel-source: before 5.14.21-150400.24.18.1

kernel-macros: before 5.14.21-150400.24.18.1

kernel-docs-html: before 5.14.21-150400.24.18.1

kernel-docs: before 5.14.21-150400.24.18.1

kernel-devel: before 5.14.21-150400.24.18.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.18.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.18.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

kselftests-kmp-64kb: before 5.14.21-150400.24.18.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb-optional: before 5.14.21-150400.24.18.1

kernel-64kb-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb-extra: before 5.14.21-150400.24.18.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb-devel: before 5.14.21-150400.24.18.1

kernel-64kb-debugsource: before 5.14.21-150400.24.18.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb: before 5.14.21-150400.24.18.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

gfs2-kmp-64kb: before 5.14.21-150400.24.18.1

dtb-xilinx: before 5.14.21-150400.24.18.1

dtb-sprd: before 5.14.21-150400.24.18.1

dtb-socionext: before 5.14.21-150400.24.18.1

dtb-rockchip: before 5.14.21-150400.24.18.1

dtb-renesas: before 5.14.21-150400.24.18.1

dtb-qcom: before 5.14.21-150400.24.18.1

dtb-nvidia: before 5.14.21-150400.24.18.1

dtb-mediatek: before 5.14.21-150400.24.18.1

dtb-marvell: before 5.14.21-150400.24.18.1

dtb-lg: before 5.14.21-150400.24.18.1

dtb-hisilicon: before 5.14.21-150400.24.18.1

dtb-freescale: before 5.14.21-150400.24.18.1

dtb-exynos: before 5.14.21-150400.24.18.1

dtb-cavium: before 5.14.21-150400.24.18.1

dtb-broadcom: before 5.14.21-150400.24.18.1

dtb-arm: before 5.14.21-150400.24.18.1

dtb-apple: before 5.14.21-150400.24.18.1

dtb-apm: before 5.14.21-150400.24.18.1

dtb-amlogic: before 5.14.21-150400.24.18.1

dtb-amd: before 5.14.21-150400.24.18.1

dtb-amazon: before 5.14.21-150400.24.18.1

dtb-altera: before 5.14.21-150400.24.18.1

dtb-allwinner: before 5.14.21-150400.24.18.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

dlm-kmp-64kb: before 5.14.21-150400.24.18.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.18.1

kernel-debug-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-debug-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-debug-devel: before 5.14.21-150400.24.18.1

kernel-debug-debugsource: before 5.14.21-150400.24.18.1

kernel-debug-debuginfo: before 5.14.21-150400.24.18.1

kernel-debug: before 5.14.21-150400.24.18.1

kernel-kvmsmall-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.18.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.18.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.18.1

kernel-kvmsmall: before 5.14.21-150400.24.18.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

reiserfs-kmp-default: before 5.14.21-150400.24.18.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

ocfs2-kmp-default: before 5.14.21-150400.24.18.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

kselftests-kmp-default: before 5.14.21-150400.24.18.1

kernel-syms: before 5.14.21-150400.24.18.1

kernel-obs-qa: before 5.14.21-150400.24.18.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.18.1

kernel-obs-build: before 5.14.21-150400.24.18.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-optional: before 5.14.21-150400.24.18.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-default-livepatch: before 5.14.21-150400.24.18.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-extra: before 5.14.21-150400.24.18.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-devel: before 5.14.21-150400.24.18.1

kernel-default-debugsource: before 5.14.21-150400.24.18.1

kernel-default-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-base-rebuild: before 5.14.21-150400.24.18.1.150400.24.5.4

kernel-default-base: before 5.14.21-150400.24.18.1.150400.24.5.4

kernel-default: before 5.14.21-150400.24.18.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

gfs2-kmp-default: before 5.14.21-150400.24.18.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

dlm-kmp-default: before 5.14.21-150400.24.18.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

cluster-md-kmp-default: before 5.14.21-150400.24.18.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2022/suse-su-20222803-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.

5) Improper update of reference count

EUVDB-ID: #VU63496

Risk: Low

CVSSv4.0: 5.9 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear]

CVE-ID: CVE-2022-29581

CWE-ID: CWE-911 - Improper Update of Reference Count

Exploit availability: No

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to improper update of reference count in net/sched in Linux kernel. A local user can execute arbitrary code with root privileges.

Mitigation

Update the affected package the Linux Kernel to the latest version.

Vulnerable software versions

SUSE Linux Enterprise Module for Live Patching: 15-SP4

SUSE Linux Enterprise Module for Legacy Software: 15-SP4

SUSE Manager Retail Branch Server: 4.3

SUSE Linux Enterprise Server for SAP Applications: 12-SP4 - 15-SP4

SUSE Linux Enterprise High Performance Computing: 12 - 15-SP4

SUSE Linux Enterprise High Availability: 15-SP4

SUSE Linux Enterprise Server: 11-SP3-CLIENT-TOOLS-BETA - 15-SP4

SUSE Linux Enterprise Workstation Extension: 15-SP4

SUSE Manager Server: 4.3

SUSE Manager Proxy: 4.3

SUSE Linux Enterprise Module for Development Tools: 15-SP4

SUSE Linux Enterprise Module for Basesystem: 15-SP4

SUSE Linux Enterprise Desktop: 15-SP4

openSUSE Leap: 15.4

kernel-livepatch-SLE15-SP4_Update_2-debugsource: before 1-150400.9.5.2

kernel-livepatch-5_14_21-150400_24_18-default-debuginfo: before 1-150400.9.5.2

kernel-livepatch-5_14_21-150400_24_18-default: before 1-150400.9.5.2

kernel-zfcpdump-debugsource: before 5.14.21-150400.24.18.1

kernel-zfcpdump-debuginfo: before 5.14.21-150400.24.18.1

kernel-zfcpdump: before 5.14.21-150400.24.18.1

kernel-source-vanilla: before 5.14.21-150400.24.18.1

kernel-source: before 5.14.21-150400.24.18.1

kernel-macros: before 5.14.21-150400.24.18.1

kernel-docs-html: before 5.14.21-150400.24.18.1

kernel-docs: before 5.14.21-150400.24.18.1

kernel-devel: before 5.14.21-150400.24.18.1

reiserfs-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

reiserfs-kmp-64kb: before 5.14.21-150400.24.18.1

ocfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

ocfs2-kmp-64kb: before 5.14.21-150400.24.18.1

kselftests-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

kselftests-kmp-64kb: before 5.14.21-150400.24.18.1

kernel-64kb-optional-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb-optional: before 5.14.21-150400.24.18.1

kernel-64kb-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-64kb-extra-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb-extra: before 5.14.21-150400.24.18.1

kernel-64kb-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb-devel: before 5.14.21-150400.24.18.1

kernel-64kb-debugsource: before 5.14.21-150400.24.18.1

kernel-64kb-debuginfo: before 5.14.21-150400.24.18.1

kernel-64kb: before 5.14.21-150400.24.18.1

gfs2-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

gfs2-kmp-64kb: before 5.14.21-150400.24.18.1

dtb-xilinx: before 5.14.21-150400.24.18.1

dtb-sprd: before 5.14.21-150400.24.18.1

dtb-socionext: before 5.14.21-150400.24.18.1

dtb-rockchip: before 5.14.21-150400.24.18.1

dtb-renesas: before 5.14.21-150400.24.18.1

dtb-qcom: before 5.14.21-150400.24.18.1

dtb-nvidia: before 5.14.21-150400.24.18.1

dtb-mediatek: before 5.14.21-150400.24.18.1

dtb-marvell: before 5.14.21-150400.24.18.1

dtb-lg: before 5.14.21-150400.24.18.1

dtb-hisilicon: before 5.14.21-150400.24.18.1

dtb-freescale: before 5.14.21-150400.24.18.1

dtb-exynos: before 5.14.21-150400.24.18.1

dtb-cavium: before 5.14.21-150400.24.18.1

dtb-broadcom: before 5.14.21-150400.24.18.1

dtb-arm: before 5.14.21-150400.24.18.1

dtb-apple: before 5.14.21-150400.24.18.1

dtb-apm: before 5.14.21-150400.24.18.1

dtb-amlogic: before 5.14.21-150400.24.18.1

dtb-amd: before 5.14.21-150400.24.18.1

dtb-amazon: before 5.14.21-150400.24.18.1

dtb-altera: before 5.14.21-150400.24.18.1

dtb-allwinner: before 5.14.21-150400.24.18.1

dlm-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

dlm-kmp-64kb: before 5.14.21-150400.24.18.1

cluster-md-kmp-64kb-debuginfo: before 5.14.21-150400.24.18.1

cluster-md-kmp-64kb: before 5.14.21-150400.24.18.1

kernel-debug-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-debug-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-debug-devel: before 5.14.21-150400.24.18.1

kernel-debug-debugsource: before 5.14.21-150400.24.18.1

kernel-debug-debuginfo: before 5.14.21-150400.24.18.1

kernel-debug: before 5.14.21-150400.24.18.1

kernel-kvmsmall-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-kvmsmall-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-kvmsmall-devel: before 5.14.21-150400.24.18.1

kernel-kvmsmall-debugsource: before 5.14.21-150400.24.18.1

kernel-kvmsmall-debuginfo: before 5.14.21-150400.24.18.1

kernel-kvmsmall: before 5.14.21-150400.24.18.1

reiserfs-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

reiserfs-kmp-default: before 5.14.21-150400.24.18.1

ocfs2-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

ocfs2-kmp-default: before 5.14.21-150400.24.18.1

kselftests-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

kselftests-kmp-default: before 5.14.21-150400.24.18.1

kernel-syms: before 5.14.21-150400.24.18.1

kernel-obs-qa: before 5.14.21-150400.24.18.1

kernel-obs-build-debugsource: before 5.14.21-150400.24.18.1

kernel-obs-build: before 5.14.21-150400.24.18.1

kernel-default-optional-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-optional: before 5.14.21-150400.24.18.1

kernel-default-livepatch-devel: before 5.14.21-150400.24.18.1

kernel-default-livepatch: before 5.14.21-150400.24.18.1

kernel-default-extra-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-extra: before 5.14.21-150400.24.18.1

kernel-default-devel-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-devel: before 5.14.21-150400.24.18.1

kernel-default-debugsource: before 5.14.21-150400.24.18.1

kernel-default-debuginfo: before 5.14.21-150400.24.18.1

kernel-default-base-rebuild: before 5.14.21-150400.24.18.1.150400.24.5.4

kernel-default-base: before 5.14.21-150400.24.18.1.150400.24.5.4

kernel-default: before 5.14.21-150400.24.18.1

gfs2-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

gfs2-kmp-default: before 5.14.21-150400.24.18.1

dlm-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

dlm-kmp-default: before 5.14.21-150400.24.18.1

cluster-md-kmp-default-debuginfo: before 5.14.21-150400.24.18.1

cluster-md-kmp-default: before 5.14.21-150400.24.18.1

CPE2.3 External links

https://www.suse.com/support/update/announcement/2022/suse-su-20222803-1/


Q & A

Can this vulnerability be exploited remotely?

No. This vulnerability can be exploited locally. The attacker should have authentication credentials and successfully authenticate on the system.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability.



###SIDEBAR###