Amazon Linux 2 Security Advisory: ALAS-2022-1876
Advisory Release Date: 2022-10-31 19:40 Pacific
Advisory Updated Date: 2024-08-14 19:05 Pacific
FAQs regarding Amazon Linux ALAS/CVE Severity
2024-08-14: CVE-2022-48672 was added to this advisory.
2024-08-01: CVE-2022-48641 was added to this advisory.
2024-08-01: CVE-2022-48659 was added to this advisory.
2024-06-06: CVE-2022-48651 was added to this advisory.
2024-05-23: CVE-2021-47103 was added to this advisory.
In the Linux kernel, the following vulnerability has been resolved:
inet: fully convert sk->sk_rx_dst to RCU rules (CVE-2021-47103)
A flaw use after free in the Linux kernel NILFS file system was found in the way user triggers function security_inode_alloc to fail with following call to function nilfs_mdt_destroy. A local user could use this flaw to crash the system or potentially escalate their privileges on the system. (CVE-2022-2978)
A vulnerability classified as problematic was found in Linux Kernel. This vulnerability affects the function bnx2x_tpa_stop of the file drivers/net/ethernet/broadcom/bnx2x/bnx2x_cmn.c of the component BPF. The manipulation leads to memory leak. It is recommended to apply a patch to fix this issue. VDB-211042 is the identifier assigned to this vulnerability. (CVE-2022-3542)
A vulnerability, which was classified as critical, has been found in Linux Kernel. Affected by this issue is the function del_timer of the file drivers/isdn/mISDN/l1oip_core.c of the component Bluetooth. The manipulation leads to use after free. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211088. (CVE-2022-3565)
A vulnerability was found in Linux Kernel. It has been declared as problematic. Affected by this vulnerability is the function intr_callback of the file drivers/net/usb/r8152.c of the component BPF. The manipulation leads to logging of excessive data. The attack can be launched remotely. It is recommended to apply a patch to fix this issue. The associated identifier of this vulnerability is VDB-211363. (CVE-2022-3594)
A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_bmap_lookup_at_level of the file fs/nilfs2/inode.c of the component nilfs2. The manipulation leads to null pointer dereference. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211920. (CVE-2022-3621)
A vulnerability, which was classified as problematic, has been found in Linux Kernel. This issue affects the function nilfs_attach_log_writer of the file fs/nilfs2/segment.c of the component BPF. The manipulation leads to memory leak. The attack may be initiated remotely. It is recommended to apply a patch to fix this issue. The identifier VDB-211961 was assigned to this vulnerability. (CVE-2022-3646)
A vulnerability was found in Linux Kernel. It has been classified as problematic. Affected is the function nilfs_new_inode of the file fs/nilfs2/inode.c of the component BPF. The manipulation leads to use after free. It is possible to launch the attack remotely. It is recommended to apply a patch to fix this issue. The identifier of this vulnerability is VDB-211992. (CVE-2022-3649)
An issue was discovered in the Linux kernel before 5.19. In pxa3xx_gcu_write in drivers/video/fbdev/pxa3xx-gcu.c, the count parameter has a type conflict of size_t versus int, causing an integer overflow and bypassing the size check. After that, because it is used as the third argument to copy_from_user(), a heap overflow may occur. (CVE-2022-39842)
drivers/scsi/stex.c in the Linux kernel through 5.19.9 allows local users to obtain sensitive information from kernel memory because stex_queuecommand_lck lacks a memset for the PASSTHRU_CMD case. (CVE-2022-40768)
drivers/video/fbdev/smscufx.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free if a physically proximate attacker removes a USB device while calling open(), aka a race condition between ufx_ops_open and ufx_usb_disconnect. (CVE-2022-41849)
roccat_report_event in drivers/hid/hid-roccat.c in the Linux kernel through 5.19.12 has a race condition and resultant use-after-free in certain situations where a report is received while copying a report->value is in progress. (CVE-2022-41850)
drivers/usb/mon/mon_bin.c in usbmon in the Linux kernel before 5.19.15 and 6.x before 6.0.1 allows a user-space client to corrupt the monitor's internal memory. (CVE-2022-43750)
In the Linux kernel, the following vulnerability has been resolved:
netfilter: ebtables: fix memory leak when blob is malformed (CVE-2022-48641)
In the Linux kernel, the following vulnerability has been resolved: ipvlan: Fix out-of-bound bugs caused by unset skb->mac_header If an AF_PACKET socket is used to send packets through ipvlan and the default xmit function of the AF_PACKET socket is changed from dev_queue_xmit() to packet_direct_xmit() via setsockopt() with the option name of PACKET_QDISC_BYPASS, the skb->mac_header may not be reset and remains as the initial value of 65535, this may trigger slab-out-of-bounds bugs as following: (CVE-2022-48651)
In the Linux kernel, the following vulnerability has been resolved:
mm/slub: fix to return errno if kmalloc() fails (CVE-2022-48659)
In the Linux kernel, the following vulnerability has been resolved:
of: fdt: fix off-by-one error in unflatten_dt_nodes() (CVE-2022-48672)
Affected Packages:
kernel
Note:
This advisory is applicable to Amazon Linux 2 (AL2) Core repository. Visit this FAQ section for the difference between AL2 Core and AL2 Extras advisories.
Issue Correction:
Run yum update kernel to update your system.
aarch64:
kernel-4.14.296-222.539.amzn2.aarch64
kernel-headers-4.14.296-222.539.amzn2.aarch64
kernel-debuginfo-common-aarch64-4.14.296-222.539.amzn2.aarch64
perf-4.14.296-222.539.amzn2.aarch64
perf-debuginfo-4.14.296-222.539.amzn2.aarch64
python-perf-4.14.296-222.539.amzn2.aarch64
python-perf-debuginfo-4.14.296-222.539.amzn2.aarch64
kernel-tools-4.14.296-222.539.amzn2.aarch64
kernel-tools-devel-4.14.296-222.539.amzn2.aarch64
kernel-tools-debuginfo-4.14.296-222.539.amzn2.aarch64
kernel-devel-4.14.296-222.539.amzn2.aarch64
kernel-debuginfo-4.14.296-222.539.amzn2.aarch64
i686:
kernel-headers-4.14.296-222.539.amzn2.i686
src:
kernel-4.14.296-222.539.amzn2.src
x86_64:
kernel-4.14.296-222.539.amzn2.x86_64
kernel-headers-4.14.296-222.539.amzn2.x86_64
kernel-debuginfo-common-x86_64-4.14.296-222.539.amzn2.x86_64
perf-4.14.296-222.539.amzn2.x86_64
perf-debuginfo-4.14.296-222.539.amzn2.x86_64
python-perf-4.14.296-222.539.amzn2.x86_64
python-perf-debuginfo-4.14.296-222.539.amzn2.x86_64
kernel-tools-4.14.296-222.539.amzn2.x86_64
kernel-tools-devel-4.14.296-222.539.amzn2.x86_64
kernel-tools-debuginfo-4.14.296-222.539.amzn2.x86_64
kernel-devel-4.14.296-222.539.amzn2.x86_64
kernel-debuginfo-4.14.296-222.539.amzn2.x86_64
kernel-livepatch-4.14.296-222.539-1.0-0.amzn2.x86_64