🛡️ MGASA-2022-0155 — kernel-linus
Description
Updated kernel-linus packages fix security vulnerabilities
This kernel-linus update is based on upstream 5.15.35 and fixes at least the
following security issues:
A denial of service (DOS) issue was found in the Linux kernel
smb2_ioctl_query_info function in the fs/cifs/smb2ops.c Common Internet
File System (CIFS) due to an incorrect return from the memdup_user function.
This flaw allows a local, privileged (CAP_SYS_ADMIN) attacker to crash the
system (CVE-2022-0168).
x86/kvm: cmpxchg_gpte can write to pfns outside the userspace region
(CVE-2022-1158).
A use-after-free vulnerabilities in drivers/net/hamradio/6pack.c allow
attacker to crash linux kernel by simulating Amateur Radio from user-space
(CVE-2022-1198).
A use-after-free flaw was found in the Linux kernel’s Amateur Radio AX.25
protocol functionality in the way a user connects with the protocol. This
flaw allows a local user to crash the system (CVE-2022-1204).
A NULL pointer dereference flaw was found in the Linux kernel’s Amateur
Radio AX.25 protocol functionality in the way a user connects with the
protocol. This flaw allows a local user to crash the system
(CVE-2022-1205).
A null pointer dereference was found in the kvm module which can lead to
denial of service (CVE-2022-1263).
A vulnerability was found in the pfkey_register function in net/key/af_key.c
in the Linux kernel. This flaw allows a local, unprivileged user to gain
access to kernel memory, leading to a system crash or a leak of internal
kernel information (CVE-2022-1353).
usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel
through 5.17.1 has a double free (CVE-2022-28388).
mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel
through 5.17.1 has a double free (CVE-2022-28389).
ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel
through 5.17.1 has a double free (CVE-2022-28390).
In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due
to a race condition in io_uring timeouts. This can be triggered by a local
user who has no access to any user namespace (CVE-2022-29582).
For other upstream fixes, see the referenced changelogs.
Affected software
MGASA-2022-0155 is recorded against 1 package.
- kernel-linus (fixed in 5.15.35-1.mga8)
Timeline and source
Published on 28 April 2022 and last revised on 16 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.
References
advisories.mageia.org (Advisory)
bugs.mageia.org (Report)
cdn.kernel.org (Web)
cdn.kernel.org (Web)
cdn.kernel.org (Web)
Details
Affected Packages
| Software | From version | Fixed in |
|---|---|---|
| kernel-linus | — | 5.15.35-1.mga8 |
References
Similar Threats
- Unknown MGASA-2022-0243
- Unknown MGASA-2022-0230
- Unknown MGASA-2022-0213
- Unknown MGASA-2022-0195
- Unknown MGASA-2022-0122
More MGASA 2022 advisories
Browse all of MGASA 2022 in the advisory index.
Free Vulnerability Check
Is your site affected by MGASA-2022-0155?
BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MGASA-2022-0155 and other known CVE records.
Scan My Site Free →No credit card required · Results in minutes
ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.