ALAS-2024-1951


Amazon Linux 1 Security Advisory: ALAS-2024-1951
Advisory Release Date: 2024-11-09 00:22 Pacific
Advisory Updated Date: 2024-11-14 12:00 Pacific
Severity: Medium

Issue Overview:

A vulnerability, which was classified as problematic, was found in Linux Kernel. This affects the function tcp_getsockopt/tcp_setsockopt of the component TCP Handler. The manipulation leads to race condition. It is recommended to apply a patch to fix this issue. The identifier VDB-211089 was assigned to this vulnerability. (CVE-2022-3566)

A vulnerability has been found in Linux Kernel and classified as problematic. This vulnerability affects the function inet6_stream_ops/inet6_dgram_ops of the component IPv6 Handler. The manipulation leads to race condition. It is recommended to apply a patch to fix this issue. VDB-211090 is the identifier assigned to this vulnerability. (CVE-2022-3567)


Affected Packages:

kernel


Issue Correction:
Run yum update kernel to update your system.
System reboot is required in order to complete this update.

New Packages:
i686:
    kernel-4.14.350-188.564.amzn1.i686
    kernel-debuginfo-common-i686-4.14.350-188.564.amzn1.i686
    kernel-debuginfo-4.14.350-188.564.amzn1.i686
    perf-debuginfo-4.14.350-188.564.amzn1.i686
    kernel-tools-devel-4.14.350-188.564.amzn1.i686
    kernel-devel-4.14.350-188.564.amzn1.i686
    perf-4.14.350-188.564.amzn1.i686
    kernel-tools-4.14.350-188.564.amzn1.i686
    kernel-headers-4.14.350-188.564.amzn1.i686
    kernel-tools-debuginfo-4.14.350-188.564.amzn1.i686

src:
    kernel-4.14.350-188.564.amzn1.src

x86_64:
    kernel-tools-debuginfo-4.14.350-188.564.amzn1.x86_64
    kernel-4.14.350-188.564.amzn1.x86_64
    kernel-headers-4.14.350-188.564.amzn1.x86_64
    kernel-debuginfo-4.14.350-188.564.amzn1.x86_64
    perf-4.14.350-188.564.amzn1.x86_64
    kernel-tools-4.14.350-188.564.amzn1.x86_64
    kernel-devel-4.14.350-188.564.amzn1.x86_64
    perf-debuginfo-4.14.350-188.564.amzn1.x86_64
    kernel-debuginfo-common-x86_64-4.14.350-188.564.amzn1.x86_64
    kernel-tools-devel-4.14.350-188.564.amzn1.x86_64