QID 353211
Date Published: 2022-04-13
QID 353211: Amazon Linux Security Advisory for kernel : ALAS-2022-1577
A flaw was found in the linux kernel in linux/net/netfilter/nf_tables_api.c of the netfilter subsystem.
This flaw allows a local user to cause an out-of-bounds write issue. (
( CVE-2022-1015) a flaw was found in the linux kernel in net/netfilter/nf_tables_core.c:nft_do_chain, which can cause a use-after-free.
This issue needs to handle return with proper preconditions, as it can lead to a kernel information leak problem caused by a local, unprivileged attacker. (
( CVE-2022-1016)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
Solution
Please refer to Amazon advisory: ALAS-2022-1577 for affected packages and patching details, or update with your package manager.
Vendor References
- ALAS-2022-1577 -
alas.aws.amazon.com/ALAS-2022-1577.html
CVEs related to QID 353211
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS-2022-1577 | Amazon Linux |
|