Red Hat Security Advisory: kernel security and bug fix update
🔗 CVE IDs covered (9)
📋 Description
CVE-2020-0465 — kernel: out of bounds write in hid-multitouch.c may lead to escalation of privilege CVE-2020-0466 — kernel: use after free in eventpoll.c may lead to escalation of privilege CVE-2021-0920 — kernel: Use After Free in unix_gc() which could result in a local privilege escalation CVE-2021-3564 — kernel: double free in bluetooth subsystem when the HCI device initialization fails CVE-2021-3573 — kernel: use-after-free in function hci_sock_bound_ioctl() CVE-2021-3752 — kernel: possible use-after-free in bluetooth module CVE-2021-4155 — kernel: xfs: raw block device data leak in XFS_IOC_ALLOCSP IOCTL CVE-2022-0330 — kernel: possible privileges escalation due to missing TLB flush CVE-2022-22942 — kernel: failing usercopy allows for use-after-free exploitation
🔗 References (12)
- selfhttps://access.redhat.com/errata/RHSA-2022:0620
- externalhttps://access.redhat.com/security/updates/classification/#important
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1920471
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1920480
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1964139
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1966578
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=1999544
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2031930
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2034813
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2042404
- externalhttps://bugzilla.redhat.com/show_bug.cgi?id=2044809
- selfhttps://security.access.redhat.com/data/csaf/v2/advisories/2022/rhsa-2022_0620.json