Security update for the Linux Kernel (Live Patch 29 for SLE 15 SP2)
This update for the Linux Kernel 5.3.18-150200_24_126 fixes several issues. The following security issues were fixed: - CVE-2020-36516: Fixed an off-path attack via mixed IPID assignment method with the hash-based IPID assignment policy to inject data into a victim's TCP session or terminate that session (bsc#1196867). - CVE-2022-1116: Fixed integer overflow or wraparound vulnerability in io_uring, where a local attacker could have caused memory corruption and escalate privileges to root (bsc#1199648).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for the Linux Kernel 5.3.18-150200_24_126 fixes several issues. The following security issues were fixed: - CVE-2020-36516: Fixed an off-path attack via mixed IPID assignment method with the hash-based IPID assignment policy to inject data into a victim's TCP session or terminate that session (bsc#1196867). - CVE-2022-1116: Fixed integer overflow or wraparound vulnerability in io_uring, where a local attacker could have caused memory corruption and escalate privileges to root (bsc#1199648).
05 / REFERENCES