MGASA-2022-0027

Source
https://advisories.mageia.org/MGASA-2022-0027.html
Import Source
https://advisories.mageia.org/MGASA-2022-0027.json
JSON Data
https://api.osv.dev/v1/vulns/MGASA-2022-0027
Related
Published
2022-01-21T21:41:23Z
Modified
2022-02-17T18:21:47Z
Summary
Updated kernel-linus packages fix security vulnerability
Details

This kernel-linus update is based on upstream 5.15.16 and fixes at least the following security issue:

William Liu and Jamie Hill-Daniel discovered that the file system context functionality in the Linux kernel contained an integer underflow vulnerability, leading to an out-of-bounds write. A local attacker could use this to cause a denial of service (system crash) or execute arbitrary code (CVE-2022-0185).

References
Credits

Affected packages

Mageia:8 / kernel-linus

Package

Name
kernel-linus
Purl
pkg:rpm/mageia/kernel-linus?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.16-1.mga8

Ecosystem specific

{
    "section": "core"
}