QID 354237

Date Published: 2022-12-12

QID 354237: Amazon Linux Security Advisory for kernel : ALAS2KERNEL-5.15-2022-011

A vulnerability, which was classified as problematic, has been found in linux kernel.
This issue affects the function unix_sock_destructor/unix_release_sock of the file net/unix/af_unix.c of the component bpf.
The manipulation leads to memory leak.
It is recommended to apply a patch to fix this issue.
The associated identifier of this vulnerability is vdb-211043. (
( CVE-2022-3543) a vulnerability classified as critical was found in linux kernel.
Affected by this vulnerability is the function l2cap_reassemble_sdu of the file net/bluetooth/l2cap_core.c of the component bluetooth.
The manipulation leads to use after free.
The associated identifier of this vulnerability is vdb-211087. (
( CVE-2022-3564) a vulnerability has been found in linux kernel and classified as problematic.
This vulnerability affects the function l2cap_recv_acldata of the file net/bluetooth/l2cap_core.c of the component bluetooth.
Vdb-211918 is the identifier assigned to this vulnerability. (
( CVE-2022-3619) a vulnerability was found in linux kernel.
It has been declared as problematic.
Affected by this vulnerability is the function follow_page_pte of the file mm/gup.c of the component bpf.
The manipulation leads to race condition.
The attack can be launched remotely.
The identifier vdb-211921 was assigned to this vulnerability. (
( CVE-2022-3623)



Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.

Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution
    Please refer to Amazon advisory: ALAS2KERNEL-5.15-2022-011 for affected packages and patching details, or update with your package manager.
    Vendor References

    CVEs related to QID 354237

    Software Advisories
    Advisory ID Software Component Link
    ALAS2KERNEL-5.15-2022-011 Amazon Linux 2 URL Logo alas.aws.amazon.com/AL2/ALASKERNEL-5.15-2022-011.html