Amazon Linux 2 Security Advisory: ALASLIVEPATCH-2022-078
Advisory Release Date: 2022-06-30 22:29 Pacific
Advisory Updated Date: 2022-07-15 00:58 Pacific
A use-after-free vulnerability was found in the Linux kernel's Netfilter subsystem in net/netfilter/nf_tables_api.c. This flaw allows a local attacker with user access to cause a privilege escalation issue. (CVE-2022-1966)
Affected Packages:
kernel-livepatch-5.10.112-108.499
Issue Correction:
Please ensure you have live patching enabled.
Run yum update kernel-livepatch-5.10.112-108.499 to update your system.
aarch64:
kernel-livepatch-5.10.112-108.499-1.0-3.amzn2.aarch64
kernel-livepatch-5.10.112-108.499-debuginfo-1.0-3.amzn2.aarch64
src:
kernel-livepatch-5.10.112-108.499-1.0-3.amzn2.src
x86_64:
kernel-livepatch-5.10.112-108.499-1.0-3.amzn2.x86_64
kernel-livepatch-5.10.112-108.499-debuginfo-1.0-3.amzn2.x86_64