Security update for the Linux Kernel (Live Patch 23 for SLE 12 SP4)
This update for the Linux Kernel 4.12.14-95_83 fixes several issues. The following security issues were fixed: - CVE-2022-20154: Fixed a use after free due to a race condition in lock_sock_nested of sock.c. This could lead to local escalation of privilege with System execution privileges needed (bsc#1200599). - CVE-2022-21499: Reinforced the kernel lockdown feature, until now it's been trivial to break out of it with kgdb or kdb (bsc#1199426). - CVE-2022-1729: Fixed a sys_perf_event_open() race condition against self (bsc#1199507).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for the Linux Kernel 4.12.14-95_83 fixes several issues. The following security issues were fixed: - CVE-2022-20154: Fixed a use after free due to a race condition in lock_sock_nested of sock.c. This could lead to local escalation of privilege with System execution privileges needed (bsc#1200599). - CVE-2022-21499: Reinforced the kernel lockdown feature, until now it's been trivial to break out of it with kgdb or kdb (bsc#1199426). - CVE-2022-1729: Fixed a sys_perf_event_open() race condition against self (bsc#1199507).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1199697
- https://bugzilla.suse.com/1200059
- https://bugzilla.suse.com/1200608
- https://www.suse.com/security/cve/CVE-2022-1729
- https://www.suse.com/security/cve/CVE-2022-20154
- https://www.suse.com/security/cve/CVE-2022-21499
- https://www.suse.com/support/update/announcement/2022/suse-su-20222444-1/