ALAS-2022-1876


Amazon Linux 2 Security Advisory: ALAS-2022-1876
Advisory Release Date: 2022-10-31 19:40 Pacific
Advisory Updated Date: 2024-08-14 19:05 Pacific
Severity: Important

Issue Overview:

2024-08-14: CVE-2022-48672 was added to this advisory.

2024-08-01: CVE-2022-48641 was added to this advisory.

2024-08-01: CVE-2022-48659 was added to this advisory.

2024-06-06: CVE-2022-48651 was added to this advisory.

2024-05-23: CVE-2021-47103 was added to this advisory.

In the Linux kernel, the following vulnerability has been resolved:

inet: fully convert sk->sk_rx_dst to RCU rules (CVE-2021-47103)

A flaw use after free in the Linux kernel NILFS file system was found in the way user triggers function security_inode_alloc to fail with following call to function nilfs_mdt_destroy. A local user could use this flaw to crash the system or potentially escalate their privileges on the system. (CVE-2022-2978)

A vulnerability classified as problematic was found in Linux Kernel. This vulnerability affects the function bnx2x_tpa_stop of the file drivers/net/ethernet/broadcom/bnx2x/bnx2x_cmn.c of the component BPF. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. VDB-211042 is the identifier assigned to this vulnerability. (CVE-2022-3542)

A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this issue is the function del_timer of the file drivers/isdn/mISDN/l1oip_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211088. (CVE-2022-3565)

A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function intr_callback of the file drivers/net/usb/r8152.c of the component BPF. The manipulation leads to logging of excessive data. The attack can be launched remotely. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211363. (CVE-2022-3594)

A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_bmap_lookup_at_level of the file fs/nilfs2/inode.c of the component nilfs2. The manipulation leads to null pointer dereference. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211920. (CVE-2022-3621)

A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function nilfs_attach_log_writer of the file fs/nilfs2/segment.c of the component BPF. The manipulation leads to memory leak. The attack may be initiated remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-211961 was assigned to this vulnerability. (CVE-2022-3646)

A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_new_inode of the file fs/nilfs2/inode.c of the component BPF. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211992. (CVE-2022-3649)

An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer overflow and bypassing the size check. After that, because it is used as the third argument to copy_from_user(), a heap overflow may occur. (CVE-2022-39842)

drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case. (CVE-2022-40768)

drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a USB device while calling open(), aka a race condition between ufx_ops_open and ufx_usb_disconnect. (CVE-2022-41849)

roccat_report_event in drivers/hid/hid-roccat.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free in certain situations where a report is received while copying a report->value is in progress. (CVE-2022-41850)

drivers/usb/mon/mon_bin.c in usbmon in the Linux kernel before 5.19.15 and 6.x before 6.0.1 allows a user-space client to corrupt the monitor's internal memory. (CVE-2022-43750)

In the Linux kernel, the following vulnerability has been resolved:

netfilter: ebtables: fix memory leak when blob is malformed (CVE-2022-48641)

In the Linux kernel, the following vulnerability has been resolved: ipvlan: Fix out-of-bound bugs caused by unset skb->mac_header If an AF_PACKET socket is used to send packets through ipvlan and the default xmit function of the AF_PACKET socket is changed from dev_queue_xmit() to packet_direct_xmit() via setsockopt() with the option name of PACKET_QDISC_BYPASS, the skb->mac_header may not be reset and remains as the initial value of 65535, this may trigger slab-out-of-bounds bugs as following: (CVE-2022-48651)

In the Linux kernel, the following vulnerability has been resolved:

mm/slub: fix to return errno if kmalloc() fails (CVE-2022-48659)

In the Linux kernel, the following vulnerability has been resolved:

of: fdt: fix off-by-one error in unflatten_dt_nodes() (CVE-2022-48672)


Affected Packages:

kernel


Note:

This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.


Issue Correction:
Run yum update kernel to update your system.

New Packages:
aarch64:
    kernel-4.14.296-222.539.amzn2.aarch64
    kernel-headers-4.14.296-222.539.amzn2.aarch64
    kernel-debuginfo-common-aarch64-4.14.296-222.539.amzn2.aarch64
    perf-4.14.296-222.539.amzn2.aarch64
    perf-debuginfo-4.14.296-222.539.amzn2.aarch64
    python-perf-4.14.296-222.539.amzn2.aarch64
    python-perf-debuginfo-4.14.296-222.539.amzn2.aarch64
    kernel-tools-4.14.296-222.539.amzn2.aarch64
    kernel-tools-devel-4.14.296-222.539.amzn2.aarch64
    kernel-tools-debuginfo-4.14.296-222.539.amzn2.aarch64
    kernel-devel-4.14.296-222.539.amzn2.aarch64
    kernel-debuginfo-4.14.296-222.539.amzn2.aarch64

i686:
    kernel-headers-4.14.296-222.539.amzn2.i686

src:
    kernel-4.14.296-222.539.amzn2.src

x86_64:
    kernel-4.14.296-222.539.amzn2.x86_64
    kernel-headers-4.14.296-222.539.amzn2.x86_64
    kernel-debuginfo-common-x86_64-4.14.296-222.539.amzn2.x86_64
    perf-4.14.296-222.539.amzn2.x86_64
    perf-debuginfo-4.14.296-222.539.amzn2.x86_64
    python-perf-4.14.296-222.539.amzn2.x86_64
    python-perf-debuginfo-4.14.296-222.539.amzn2.x86_64
    kernel-tools-4.14.296-222.539.amzn2.x86_64
    kernel-tools-devel-4.14.296-222.539.amzn2.x86_64
    kernel-tools-debuginfo-4.14.296-222.539.amzn2.x86_64
    kernel-devel-4.14.296-222.539.amzn2.x86_64
    kernel-debuginfo-4.14.296-222.539.amzn2.x86_64
    kernel-livepatch-4.14.296-222.539-1.0-0.amzn2.x86_64