QID 354270
Date Published: 2022-12-14
QID 354270: Amazon Linux Security Advisory for kernel : ALAS2022-2022-114
a use-after-free flaw was found in fs/ext4/namei.c:dx_insert_block() in the linux kernels filesystem sub-component.
This flaw allows a local attacker with a user privilege to cause a denial of service. (
( CVE-2022-1184) a flaw was found in kvm.
With shadow paging enabled if invpcid is executed with cr0.pg=0, the invlpg callback is not set, and the result is a null pointer dereference.
This flaw allows a guest user to cause a kernel oops condition on the host, resulting in a denial of service. (
( CVE-2022-1789) a null pointer dereference flaw was found in the linux kernels kvm module, which can lead to a denial of service in the x86_emulate_insn in arch/x86/kvm/emulate.c.
This flaw occurs while executing an illegal instruction in guest in the intel cpu. (
( CVE-2022-1852) a use-after-free vulnerability was found in the linux kernels netfilter subsystem in net/netfilter/nf_tables_api.c.
This flaw allows a local attacker with user access to cause a privilege escalation issue. (
( CVE-2022-1966) no description is available for this( CVE. (
( CVE-2022-1972) a use-after-free flaw was found in the linux kernel in log_replay in fs/ntfs3/fslog.c in the ntfs journal.
This flaw allows a local attacker to crash the system and leads to a kernel information leak problem. (
( CVE-2022-1973) a vulnerability was found in the linux kernels nft_set_desc_concat_parse() function .this flaw allows an attacker to trigger a buffer overflow via nft_set_desc_concat_parse() , causing a denial of service and possibly to run code. (
Linux block and network pv device frontends dont zero memory regions before sharing them with the backend (cve-2022-26365,( CVE-2022-33740).
( CVE-2022-34918)
Note: The preceding description block is extracted directly from the security advisory. Using automation, we have attempted to clean and format it as much as possible without introducing additional issues.
Successful exploitation of this vulnerability could lead to a securitybreach or could affect integrity, availability, and confidentiality.
- ALAS2022-2022-114 -
alas.aws.amazon.com/AL2022/ALAS-2022-114.html
CVEs related to QID 354270
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ALAS2022-2022-114 | amazon linux 2022 |
|