🛡️ MGASA-2022-0155 — kernel-linus

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Updated kernel-linus packages fix security vulnerabilities

This kernel-linus update is based on upstream 5.15.35 and fixes at least the

following security issues:

A denial of service (DOS) issue was found in the Linux kernel

smb2_ioctl_query_info function in the fs/cifs/smb2ops.c Common Internet

File System (CIFS) due to an incorrect return from the memdup_user function.

This flaw allows a local, privileged (CAP_SYS_ADMIN) attacker to crash the

system (CVE-2022-0168).

x86/kvm: cmpxchg_gpte can write to pfns outside the userspace region

(CVE-2022-1158).

A use-after-free vulnerabilities in drivers/net/hamradio/6pack.c allow

attacker to crash linux kernel by simulating Amateur Radio from user-space

(CVE-2022-1198).

A use-after-free flaw was found in the Linux kernel’s Amateur Radio AX.25

protocol functionality in the way a user connects with the protocol. This

flaw allows a local user to crash the system (CVE-2022-1204).

A NULL pointer dereference flaw was found in the Linux kernel’s Amateur

Radio AX.25 protocol functionality in the way a user connects with the

protocol. This flaw allows a local user to crash the system

(CVE-2022-1205).

A null pointer dereference was found in the kvm module which can lead to

denial of service (CVE-2022-1263).

A vulnerability was found in the pfkey_register function in net/key/af_key.c

in the Linux kernel. This flaw allows a local, unprivileged user to gain

access to kernel memory, leading to a system crash or a leak of internal

kernel information (CVE-2022-1353).

usb_8dev_start_xmit in drivers/net/can/usb/usb_8dev.c in the Linux kernel

through 5.17.1 has a double free (CVE-2022-28388).

mcba_usb_start_xmit in drivers/net/can/usb/mcba_usb.c in the Linux kernel

through 5.17.1 has a double free (CVE-2022-28389).

ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c in the Linux kernel

through 5.17.1 has a double free (CVE-2022-28390).

In the Linux kernel before 5.17.3, fs/io_uring.c has a use-after-free due

to a race condition in io_uring timeouts. This can be triggered by a local

user who has no access to any user namespace (CVE-2022-29582).

For other upstream fixes, see the referenced changelogs.

Affected software

MGASA-2022-0155 is recorded against 1 package.

  • kernel-linus (fixed in 5.15.35-1.mga8)

Timeline and source

Published on 28 April 2022 and last revised on 16 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

advisories.mageia.org (Advisory)
bugs.mageia.org (Report)
cdn.kernel.org (Web)
cdn.kernel.org (Web)
cdn.kernel.org (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2022-04-28
Updated 2026-08-12
Modified 2026-04-16
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel-linus 5.15.35-1.mga8

Similar Threats

Free Vulnerability Check

Is your site affected by MGASA-2022-0155?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against MGASA-2022-0155 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.