Security update for the Linux Kernel (Live Patch 5 for SLE 15 SP4)
This update for the Linux Kernel 5.14.21-150400_24_33 fixes several issues. The following security issues were fixed: - CVE-2022-43945: Fixed a buffer overflow in the NFSD implementation (bsc#1205128). - CVE-2022-4378: Fixed stack overflow in __do_proc_dointvec (bsc#1206207). - CVE-2022-4139: Fixed an issue with the i915 driver that allowed the GPU to access any physical memory (bsc#1205700). - CVE-2021-39698: Fixed a use-after-free in aio_poll_complete_work of aio.c (bsc#1196956).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for the Linux Kernel 5.14.21-150400_24_33 fixes several issues. The following security issues were fixed: - CVE-2022-43945: Fixed a buffer overflow in the NFSD implementation (bsc#1205128). - CVE-2022-4378: Fixed stack overflow in __do_proc_dointvec (bsc#1206207). - CVE-2022-4139: Fixed an issue with the i915 driver that allowed the GPU to access any physical memory (bsc#1205700). - CVE-2021-39698: Fixed a use-after-free in aio_poll_complete_work of aio.c (bsc#1196956).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1196959
- https://bugzilla.suse.com/1205130
- https://bugzilla.suse.com/1205815
- https://bugzilla.suse.com/1206228
- https://www.suse.com/security/cve/CVE-2021-39698
- https://www.suse.com/security/cve/CVE-2022-4139
- https://www.suse.com/security/cve/CVE-2022-4378
- https://www.suse.com/security/cve/CVE-2022-43945
- https://www.suse.com/support/update/announcement/2022/suse-su-20224542-1/