{"id":"MGASA-2022-0229","summary":"Updated kernel packages fix security vulnerabilities","details":"This kernel update is based on upstream 5.15.46 and fixes at least the\nfollowing security issues:\n\nKVM: x86: avoid calling x86 emulator without a decoded instruction\n(CVE-2022-1852).\n\nA use-after-free vulnerability was found in the Linux kernel's Netfilter\nsubsystem in net/netfilter/nf_tables_api.c. This flaw allows a local\nattacker with user access to cause a privilege escalation issue\n(CVE-2022-1966).\n\nAn out-of-bound write vulnerability was identified within the netfilter\nsubsystem which can be exploited to achieve privilege escalation to\nroot. In order to trigger the issue it requires the ability to create\nuser/net namespaces (CVE-2022-1972).\n\nfs/ntfs3: Fix invalid free in log_replay (CVE-2022-1973).\n\nOther fixes in this update:\n- x86/amd_nb: Add AMD Family 17h A0-AF IDs\n- x86/amd_nb: Add Family 19h model 70h-7Fh IDs\n- x86/amd_nb: Add Family 19h model 60h-6Fh IDs\n- hwmon: (k10temp): Add support for family 17h models A0h-AFh\n- hwmon: (k10temp): Add support for family 19h models 70h-7Fh\n- hwmon: (k10temp): Add support for family 19h models 60h-6Fh\n\nFor other upstream fixes, see the referenced changelogs.\n","modified":"2026-04-16T04:40:55.923959238Z","published":"2022-06-13T20:44:20Z","upstream":["CVE-2022-1852","CVE-2022-1966","CVE-2022-1972","CVE-2022-1973"],"references":[{"type":"ADVISORY","url":"https://advisories.mageia.org/MGASA-2022-0229.html"},{"type":"REPORT","url":"https://bugs.mageia.org/show_bug.cgi?id=30536"},{"type":"WEB","url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.44"},{"type":"WEB","url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.45"},{"type":"WEB","url":"https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.15.46"}],"affected":[{"package":{"name":"kernel","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/kernel?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.15.46-1.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2022-0229.json"}},{"package":{"name":"kmod-virtualbox","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/kmod-virtualbox?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"6.1.34-1.14.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2022-0229.json"}},{"package":{"name":"kmod-xtables-addons","ecosystem":"Mageia:8","purl":"pkg:rpm/mageia/kmod-xtables-addons?arch=source&distro=mageia-8"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.20-1.12.mga8"}]}],"ecosystem_specific":{"section":"core"},"database_specific":{"source":"https://advisories.mageia.org/MGASA-2022-0229.json"}}],"schema_version":"1.7.5","credits":[{"name":"Mageia","contact":["https://wiki.mageia.org/en/Packages_Security_Team"],"type":"COORDINATOR"}]}