SUSE-SU-2022:3291-1

Advisory lineage Upstream: 13 Downstream: 0
Published: 16 Sept 2022, 14:57
Last modified:04 Feb 2026, 03:41

Vulnerability Summary

Overall Risk (default)
minimal
0/100
CVSS Score
No data
EPSS Score
No data
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

16 Sept 2022, 14:57
Published
Vulnerability first disclosed
04 Feb 2026, 03:41
Last Modified
Vulnerability information updated

Description

Security update for the Linux Kernel The SUSE Linux Enterprise 15 LTSS kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-36516: Fixed an issue in the mixed IPID assignment method where an attacker was able to inject data into or terminate a victim's TCP session (bnc#1196616). - CVE-2021-4203: Fixed use-after-free read flaw that was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (bnc#1194535). - CVE-2022-20368: Fixed slab-out-of-bounds access in packet_recvmsg() (bsc#1202346). - CVE-2022-20369: Fixed possible out of bounds write due to improper input validation in v4l2_m2m_querybuf of v4l2-mem2mem.c (bnc#1202347). - CVE-2022-21385: Fixed a flaw in net_rds_alloc_sgs() that allowed unprivileged local users to crash the machine (bnc#1202897). - CVE-2022-2588: Fixed use-after-free in cls_route (bsc#1202096). - CVE-2022-26373: Fixed non-transparent sharing of return predictor targets between contexts in some Intel Processors (bnc#1201726). - CVE-2022-2639: Fixed an integer coercion error that was found in the openvswitch kernel module (bnc#1202154). - CVE-2022-2663: Fixed an issue that was found in nf_conntrack_irc where the message handling could be confused and incorrectly matches the message (bnc#1202097). - CVE-2022-2977: Fixed reference counting for struct tpm_chip (bsc#1202672). - CVE-2022-3028: Fixed race condition that was found in the IP framework for transforming packets (XFRM subsystem) (bnc#1202898). - CVE-2022-36879: Fixed an issue in xfrm_expand_policies in net/xfrm/xfrm_policy.c where a refcount could be dropped twice (bnc#1201948). - CVE-2022-39188: Fixed race condition in include/asm-generic/tlb.h where a device driver can free a page while it still has stale TLB entries (bnc#1203107). The following non-security bugs were fixed: - cifs: fix error paths in cifs_tree_connect() (bsc#1177440). - cifs: fix uninitialized pointer in error case in dfs_cache_get_tgt_share (bsc#1188944). - cifs: report error instead of invalid when revalidating a dentry fails (bsc#1177440). - cifs: skip trailing separators of prefix paths (bsc#1188944). - kernel-obs-build: include qemu_fw_cfg (boo#1201705) - lightnvm: Remove lightnvm implemenation (bsc#1191881 bsc#1201420 ZDI-CAN-17325). - mm/rmap.c: do not reuse anon_vma if we just want a copy (git-fixes, bsc#1203098). - mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (git-fixes, bsc#1203098). - net_sched: cls_route: disallow handle of 0 (bsc#1202393). - objtool: Add --backtrace support (bsc#1202396). - objtool: Add relocation check for alternative sections (bsc#1202396). - objtool: Add support for intra-function calls (bsc#1202396). - objtool: Allow no-op CFI ops in alternatives (bsc#1202396). - objtool: Clean instruction state before each function validation (bsc#1169514). - objtool: Convert insn type to enum (bsc#1202396). - objtool: Do not use ignore flag for fake jumps (bsc#1202396). - objtool: Fix !CFI insn_state propagation (bsc#1202396). - objtool: Fix ORC vs alternatives (bsc#1202396). - objtool: Fix sibling call detection (bsc#1202396). - objtool: Fix switch table detection in .text.unlikely (bsc#1202396). - objtool: Ignore empty alternatives (bsc#1169514). - objtool: Make BP scratch register warning more robust (bsc#1202396). - objtool: Make handle_insn_ops() unconditional (bsc#1202396). - objtool: Remove INSN_STACK (bsc#1202396). - objtool: Remove check preventing branches within alternative (bsc#1202396). - objtool: Rename elf_open() to prevent conflict with libelf from elftoolchain (bsc#1202396). - objtool: Rename struct cfi_state (bsc#1202396). - objtool: Rework allocating stack_ops on decode (bsc#1202396). - objtool: Rewrite alt->skip_orig (bsc#1202396). - objtool: Set insn->func for alternatives (bsc#1202396). - objtool: Support conditional retpolines (bsc#1202396). - objtool: Support multiple stack_op per instruction (bsc#1202396). - objtool: Track original function across branches (bsc#1202396). - objtool: Uniquely identify alternative instruction groups (bsc#1202396). - objtool: Use Elf_Scn typedef instead of assuming struct name (bsc#1202396). - rpm: Fix parsing of rpm/macros.kernel-source on SLE12 (bsc#1201019).

Affected Systems

  • susekernel-default&distro=SUSE Linux Enterprise High Availability Extension 15

    < 4.12.14-150000.150.101.1

  • susekernel-default&distro=SUSE Linux Enterprise High Performance Computing 15-ESPOS

    < 4.12.14-150000.150.101.1

  • susekernel-default&distro=SUSE Linux Enterprise High Performance Computing 15-LTSS

    < 4.12.14-150000.150.101.1

  • susekernel-default&distro=SUSE Linux Enterprise Live Patching 15

    < 4.12.14-150000.150.101.1

  • susekernel-default&distro=SUSE Linux Enterprise Server 15-LTSS

    < 4.12.14-150000.150.101.1

  • susekernel-default&distro=SUSE Linux Enterprise Server for SAP Applications 15

    < 4.12.14-150000.150.101.1

  • susekernel-docs&distro=SUSE Linux Enterprise High Performance Computing 15-ESPOS

    < 4.12.14-150000.150.101.1

  • susekernel-docs&distro=SUSE Linux Enterprise High Performance Computing 15-LTSS

    < 4.12.14-150000.150.101.1

  • susekernel-docs&distro=SUSE Linux Enterprise Server 15-LTSS

    < 4.12.14-150000.150.101.1

  • susekernel-docs&distro=SUSE Linux Enterprise Server for SAP Applications 15

    < 4.12.14-150000.150.101.1

  • susekernel-livepatch-SLE15_Update_33&distro=SUSE Linux Enterprise Live Patching 15

    < 1-150000.1.3.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise High Performance Computing 15-ESPOS

    < 4.12.14-150000.150.101.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise High Performance Computing 15-LTSS

    < 4.12.14-150000.150.101.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise Server 15-LTSS

    < 4.12.14-150000.150.101.1

  • susekernel-obs-build&distro=SUSE Linux Enterprise Server for SAP Applications 15

    < 4.12.14-150000.150.101.1

  • susekernel-source&distro=SUSE Linux Enterprise High Performance Computing 15-ESPOS

    < 4.12.14-150000.150.101.1

  • susekernel-source&distro=SUSE Linux Enterprise High Performance Computing 15-LTSS

    < 4.12.14-150000.150.101.1

  • susekernel-source&distro=SUSE Linux Enterprise Server 15-LTSS

    < 4.12.14-150000.150.101.1

  • susekernel-source&distro=SUSE Linux Enterprise Server for SAP Applications 15

    < 4.12.14-150000.150.101.1

  • susekernel-syms&distro=SUSE Linux Enterprise High Performance Computing 15-ESPOS

    < 4.12.14-150000.150.101.1

  • susekernel-syms&distro=SUSE Linux Enterprise High Performance Computing 15-LTSS

    < 4.12.14-150000.150.101.1

  • susekernel-syms&distro=SUSE Linux Enterprise Server 15-LTSS

    < 4.12.14-150000.150.101.1

  • susekernel-syms&distro=SUSE Linux Enterprise Server for SAP Applications 15

    < 4.12.14-150000.150.101.1

  • susekernel-vanilla&distro=SUSE Linux Enterprise High Performance Computing 15-ESPOS

    < 4.12.14-150000.150.101.1

  • susekernel-vanilla&distro=SUSE Linux Enterprise High Performance Computing 15-LTSS

    < 4.12.14-150000.150.101.1

  • susekernel-vanilla&distro=SUSE Linux Enterprise Server 15-LTSS

    < 4.12.14-150000.150.101.1

  • susekernel-vanilla&distro=SUSE Linux Enterprise Server for SAP Applications 15

    < 4.12.14-150000.150.101.1

  • susekernel-zfcpdump&distro=SUSE Linux Enterprise Server 15-LTSS

    < 4.12.14-150000.150.101.1

References (37)