Anfälligkeitssuche        Suche in 324607 CVE Beschreibungen
und 145615 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.1.10.2023.0149
Kategorie:Mageia Linux Local Security Checks
Titel:Mageia: Security Advisory (MGASA-2023-0149)
Zusammenfassung:The remote host is missing an update for the 'kernel-linus' package(s) announced via the MGASA-2023-0149 advisory.
Beschreibung:Summary:
The remote host is missing an update for the 'kernel-linus' package(s) announced via the MGASA-2023-0149 advisory.

Vulnerability Insight:
This kernel-linus update is based on upstream 5.15.106 and fixes at least the
following security issues:

A flaw was found in the Linux Kernel. The tun/tap sockets have their socket
UID hardcoded to 0 due to a type confusion in their initialization function.
While it will be often correct, as tuntap devices require CAP_NET_ADMIN,
it may not always be the case, e.g., a non-root user only having that
capability. This would make tun/tap sockets being incorrectly treated in
filtering/routing decisions, possibly bypassing network filters
(CVE-2023-1076).

In the Linux kernel, pick_next_rt_entity() may return a type confused entry,
not detected by the BUG_ON condition, as the confused entry will not be
NULL, but list_head.The buggy error condition would lead to a type confused
entry with the list head,which would then be used as a type confused
sched_rt_entity,causing memory corruption (CVE-2023-1077).

A flaw was found in the Linux kernel. A use-after-free may be triggered in
asus_kbd_backlight_set when plugging/disconnecting in a malicious USB device,
which advertises itself as an Asus device. Similarly to the previous known
CVE-2023-25012, but in asus devices, the work_struct may be scheduled by the
LED controller while the device is disconnecting, triggering a use-after-free
on the struct asus_kbd_leds *led structure. A malicious USB device may
exploit the issue to cause memory corruption with controlled data
(CVE-2023-1079).

A flaw use after free in the Linux kernel integrated infrared receiver/
transceiver driver was found in the way user detaching rc device. A local
user could use this flaw to crash the system or potentially escalate their
privileges on the system (CVE-2023-1118).

A use-after-free flaw was found in btrfs_search_slot in fs/btrfs/ctree.c
in btrfs in the Linux Kernel.This flaw allows an attacker to crash the
system and possibly cause a kernel information leak (CVE-2023-1611).

A flaw use after free in the Linux kernel Xircom 16-bit PCMCIA (PC-card)
Ethernet driver was found.A local user could use this flaw to crash the
system or potentially escalate their privileges on the system
(CVE-2023-1670).

A use-after-free vulnerability in the Linux Kernel traffic control index
filter (tcindex) can be exploited to achieve local privilege escalation.
The tcindex_delete function which does not properly deactivate filters in
case of a perfect hashes while deleting the underlying structure which can
later lead to double freeing the structure. A local attacker user can use
this vulnerability to elevate its privileges to root (CVE-2023-1829).

A use-after-free flaw was found in xgene_hwmon_remove in drivers/hwmon/
xgene-hwmon.c in the Hardware Monitoring Linux Kernel Driver (xgene-hwmon).
This flaw could allow a local attacker to crash the system due to a race
problem. This vulnerability could even lead to a kernel information leak
problem (CVE-2023-1855).

A ... [Please see the references for more information on the vulnerabilities]

Affected Software/OS:
'kernel-linus' package(s) on Mageia 8.

Solution:
Please install the updated package(s).

CVSS Score:
6.8

CVSS Vector:
AV:L/AC:L/Au:S/C:C/I:C/A:C

Querverweis: Common Vulnerability Exposure (CVE) ID: CVE-2022-4269
Debian Security Information: DSA-5480 (Google Search)
https://www.debian.org/security/2023/dsa-5480
https://lore.kernel.org/netdev/33dc43f587ec1388ba456b4915c75f02a8aae226.1663945716.git.dcaratti%40redhat.com/
https://lists.debian.org/debian-lts-announce/2023/10/msg00027.html
Common Vulnerability Exposure (CVE) ID: CVE-2022-4379
FEDORA-2023-3fd7349f60
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/LECFVUHKIRBV5JJBE3KQCLGKNYJPBRCN/
FEDORA-2023-f4f9182dc8
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/RAVD6JIILAVSRHZ4VXSV3RAAGUXKVXZA/
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=75333d48f92256a0dec91dbf07835e804fc411c0
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=aeba12b26c79fc35e07e511f692a8907037d95da
https://seclists.org/oss-sec/2022/q4/185
https://lists.debian.org/debian-lts-announce/2023/05/msg00005.html
Common Vulnerability Exposure (CVE) ID: CVE-2023-1076
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=66b2c338adce580dfce2199591e65e2bab889cff
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=a096ccca6e503a5c575717ff8a36ace27510ab0a
Common Vulnerability Exposure (CVE) ID: CVE-2023-1077
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=7c4a5b89a0b5a57a64b601775b296abf77a9fe97
https://lists.debian.org/debian-lts-announce/2024/01/msg00004.html
Common Vulnerability Exposure (CVE) ID: CVE-2023-1079
https://git.kernel.org/pub/scm/linux/kernel/git/next/linux-next.git/commit/?id=4ab3a086d10eeec1424f2e8a968827a6336203df
https://lists.debian.org/debian-lts-announce/2023/05/msg00006.html
Common Vulnerability Exposure (CVE) ID: CVE-2023-1118
https://github.com/torvalds/linux/commit/29b0589a865b6f66d141d79b2dd1373e4e50fe17
Common Vulnerability Exposure (CVE) ID: CVE-2023-1611
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZWECAZ7V7EPSXMINO6Q6KWNKDY2CO6ZW/
https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/5QCM6XO4HSPLGR3DFYWFRIA3GCBIHZR4/
https://github.com/torvalds/linux/commit/2f1a6be12ab6c8470d5776e68644726c94257c54
https://bugzilla.redhat.com/show_bug.cgi?id=2181342
https://lore.kernel.org/linux-btrfs/35b9a70650ea947387cf352914a8774b4f7e8a6f.1679481128.git.fdmanana@suse.com/
Common Vulnerability Exposure (CVE) ID: CVE-2023-1670
https://lore.kernel.org/all/20230316161526.1568982-1-zyytlz.wz@163.com/
Common Vulnerability Exposure (CVE) ID: CVE-2023-1829
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=8c710f75256bb3cf05ac7b1672c82b92c43f3d28
https://kernel.dance/#8c710f75256bb3cf05ac7b1672c82b92c43f3d28
Common Vulnerability Exposure (CVE) ID: CVE-2023-1855
https://github.com/torvalds/linux/commit/cb090e64cf25602b9adaf32d5dfc9c8bec493cd1
https://lore.kernel.org/all/20230318122758.2140868-1-linux@roeck-us.net/
Common Vulnerability Exposure (CVE) ID: CVE-2023-1989
Debian Security Information: DSA-5492 (Google Search)
https://www.debian.org/security/2023/dsa-5492
https://git.kernel.org/pub/scm/linux/kernel/git/bluetooth/bluetooth-next.git/commit/?id=f132c2d13088
Common Vulnerability Exposure (CVE) ID: CVE-2023-1990
https://lore.kernel.org/all/20230312160837.2040857-1-zyytlz.wz@163.com/
Common Vulnerability Exposure (CVE) ID: CVE-2023-25012
https://bugzilla.suse.com/show_bug.cgi?id=1207560
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=27d2a2fd844ec7da70d19fabb482304fd1e0595b
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=76ca8da989c7d97a7f76c75d475fe95a584439d7
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9fefb6201c4f8dd9f58c581b2a66e5cde2895ea2
https://lore.kernel.org/all/20230125-hid-unregister-leds-v1-1-9a5192dcef16@diag.uniroma1.it/
https://seclists.org/oss-sec/2023/q1/53
http://www.openwall.com/lists/oss-security/2023/02/02/1
http://www.openwall.com/lists/oss-security/2023/11/05/1
Common Vulnerability Exposure (CVE) ID: CVE-2023-28466
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=49c47cc21b5b7a3d8deb18fc57b0aa2ab1286962
Common Vulnerability Exposure (CVE) ID: CVE-2023-30456
http://packetstormsecurity.com/files/173757/Kernel-Live-Patch-Security-Notice-LSN-0096-1.html
https://cdn.kernel.org/pub/linux/kernel/v6.x/ChangeLog-6.2.8
https://github.com/torvalds/linux/commit/112e66017bff7f2837030f34c2bc19501e9212d5
Common Vulnerability Exposure (CVE) ID: CVE-2023-30772
CopyrightCopyright (C) 2023 Greenbone AG

Dies ist nur einer von 145615 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2025 E-Soft Inc. Alle Rechte vorbehalten.