{"id":"MGASA-2022-0041","summary":"Updated kernel packages fix security vulnerabilities","details":"This kernel update is based on upstream 5.15.18 and fixes at least the\nfollowing security issues:\n\nA random memory access flaw was found in the Linux kernels GPU i915 kernel\ndriver functionality in the way a user may run malicious code on the GPU.\nThis flaw allows a local user to crash the system or escalate their\nprivileges on the system (CVE-2022-0330).\n\nA use-after-free flaw was found in the Linux kernels\nvmw_execbuf_copy_fence_user function in drivers/gpu/drm/vmwgfx/\nvmwgfx_execbuf.c in vmwgfx. This flaw allows a local attacker with user\nprivileges to cause a privilege escalation problem (CVE-2022-22942).\n\nkernel/ucount.c in the Linux kernel 5.14 through 5.16.4, when unprivileged\nuser namespaces are enabled, allows a use-after-free and privilege\nescalation because a ucounts object can outlive its namespace\n(CVE-2022-24122).\n\nOther fixes in this update:\n- fix broken RTL8814AU support (mga#29952)\n- fix cifs failing to load on server kernels (mga#29957)\n- fix broken plymouth scaling (mga#29925)\n- bpf: Guard against accessing NULL pt_regs in bpf_get_task_stack()\n- fs/exec: require argv[0] presence in do_execveat_common()\n\nFor other upstream fixes, see the referenced changelogs.\n","modified":"2026-04-16T04:43:25.388508156Z","published":"2022-02-01T15:26:02Z","upstream":["CVE-2022-0330","CVE-2022-22942","CVE-2022-24122"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2022-0041.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=29960"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=29952"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=29957"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=29925"},{"type":"WEB","url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.17"},{"type":"WEB","url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.18"}],"affected":[{"package":{"name":"kernel","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/kernel?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.15.18-2.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2022-0041.json"}},{"package":{"name":"kmod-virtualbox","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/kmod-virtualbox?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.32-1.4.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2022-0041.json"}},{"package":{"name":"kmod-xtables-addons","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/kmod-xtables-addons?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.18-1.52.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2022-0041.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}