Skip to main content

Boteraser | Website and Server Security Solutions

🛡️ openSUSE-SU-2022:1039-1 — dtb-aarch64 (CVE-2022-25636 +21 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security and bugfixes.

The following security bugs were fixed:

  • CVE-2022-25636: Fixed an issue which allowed a local users to gain privileges because of a heap out-of-bounds write in nf_dup_netdev.c, related to nf_tables_offload (bsc#1196299).
  • CVE-2022-26490: Fixed a buffer overflow in the st21nfca driver. An attacker with adjacent NFC access could trigger crash the system or corrupt system memory (bsc#1196830).
  • CVE-2022-0487: A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove() in drivers/memstick/host/rtsx_usb_ms.c (bsc#1194516).
  • CVE-2022-24448: Fixed an issue if an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR should have occured, but the server instead returned uninitialized data in the file descriptor (bsc#1195612).
  • CVE-2022-0617: Fixed a null pointer dereference in UDF file system functionality. A local user could crash the system by triggering udf_file_write_iter() via a malicious UDF image. (bsc#1196079)
  • CVE-2022-0644: Fixed a denial of service by a local user. A assertion failure could be triggered in kernel_read_file_from_fd(). (bsc#1196155)
  • CVE-2022-25258: The USB Gadget subsystem lacked certain validation of interface OS descriptor requests, which could have lead to memory corruption (bsc#1196096).
  • CVE-2022-24958: drivers/usb/gadget/legacy/inode.c mishandled dev->buf release (bsc#1195905).
  • CVE-2022-24959: Fixed a memory leak in yam_siocdevprivate() in drivers/net/hamradio/yam.c (bsc#1195897).
  • CVE-2021-44879: In gc_data_segment() in fs/f2fs/gc.c, special files were not considered, which lead to a move_data_page NULL pointer dereference (bsc#1195987).
  • CVE-2021-0920: Fixed a local privilege escalation due to a use-after-free vulnerability in unix_scm_to_skb of af_unix (bsc#1193731).
  • CVE-2021-39657: Fixed an information leak in the Universal Flash Storage subsystem (bsc#1193864).
  • CVE-2022-26966: Fixed an issue in drivers/net/usb/sr9700.c, which allowed attackers to obtain sensitive information from heap memory via crafted frame lengths from a device (bsc#1196836).
  • CVE-2021-39698: Fixed a possible memory corruption due to a use after free in aio_poll_complete_work. This could lead to local escalation of privilege with no additional execution privileges needed. (bsc#1196956)
  • CVE-2021-45402: The check_alu_op function in kernel/bpf/verifier.c did not properly update bounds while handling the mov32 instruction, which allowed local users to obtain potentially sensitive address information (bsc#1196130).
  • CVE-2022-23036,CVE-2022-23037,CVE-2022-23038,CVE-2022-23039,CVE-2022-23040,CVE-2022-23041,CVE-2022-23042: Fixed multiple issues which could have lead to read/write access to memory pages or denial of service. These issues are related to the Xen PV device frontend drivers. (bsc#1196488)

The following non-security bugs were fixed:

  • ALSA: intel_hdmi: Fix reference to PCM buffer address (git-fixes).
  • ARM: 9182/1: mmu: fix returns from early_param() and __setup() functions (git-fixes).
  • ARM: Fix kgdb breakpoint for Thumb2 (git-fixes).
  • ASoC: cs4265: Fix the duplicated control name (git-fixes).
  • ASoC: ops: Shift tested values in snd_soc_put_volsw() by +min (git-fixes).
  • ASoC: rt5668: do not block workqueue if card is unbound (git-fixes).
  • ASoC: rt5682: do not block workqueue if card is unbound (git-fixes).
  • Bluetooth: btusb: Add missing Chicony device for Realtek RTL8723BE (bsc#1196779).
  • EDAC/altera: Fix deferred probing (bsc#1178134).
  • EDAC: Fix calculation of returned address and next offset in edac_align_ptr() (bsc#1178134).
  • HID: add mapping for KEY_ALL_APPLICATIONS (git-fixes).
  • HID: add mapping for KEY_DICTATE (git-fixes).
  • Hand over the maintainership to SLE15-SP3 maintainers
  • IB/hfi1: Correct guard on eager buffer deallocation (git-fixes).
  • IB/hfi1: Fix early init panic (git-fixes).
  • IB/hfi1: Fix leak of rcvhdrtail_dummy_kvaddr (git-fixes).
  • IB/hfi1: Insure use of smp_processor_id() is preempt disabled (git-fixes).
  • IB/rdmavt: Validate remote_addr during loopback atomic tests (git-fixes).
  • Input: clear BTN_RIGHT/MIDDLE on buttonpads (git-fixes).
  • Input: elan_i2c - fix regulator enable count imbalance after suspend/resume (git-fixes).
  • Input: elan_i2c - move regulator_[en|dis]able() out of elan_[en|dis]able_power() (git-fixes).
  • NFC: port100: fix use-after-free in port100_send_complete (git-fixes).
  • RDMA/bnxt_re: Scan the whole bitmap when checking if 'disabling RCFW with pending cmd-bit' (git-fixes).
  • RDMA/cma: Do not change route.addr.src_addr outside state checks (bsc#1181147).
  • RDMA/cma: Let cma_resolve_ib_dev() continue search even after empty entry (git-fixes).
  • RDMA/cma: Remove open coding of overflow checking for private_data_len (git-fixes).
  • RDMA/core: Do not infoleak GRH fields (git-fixes).
  • RDMA/core:

Affected software

openSUSE-SU-2022:1039-1 is recorded against 13 packages.

  • dtb-aarch64 (fixed in 5.3.18-150300.59.60.4)
  • kernel-64kb (fixed in 5.3.18-150300.59.60.4)
  • kernel-debug (fixed in 5.3.18-150300.59.60.4)
  • kernel-default (fixed in 5.3.18-150300.59.60.4)
  • kernel-default-base (fixed in 5.3.18-150300.59.60.4.150300.18.37.5)
  • kernel-docs (fixed in 5.3.18-150300.59.60.4)
  • kernel-kvmsmall (fixed in 5.3.18-150300.59.60.4)
  • kernel-obs-build (fixed in 5.3.18-150300.59.60.4)
  • kernel-obs-qa (fixed in 5.3.18-150300.59.60.4)
  • kernel-preempt (fixed in 5.3.18-150300.59.60.4)
  • kernel-source (fixed in 5.3.18-150300.59.60.4)
  • kernel-syms (fixed in 5.3.18-150300.59.60.4)
  • kernel-zfcpdump (fixed in 5.3.18-150300.59.60.4)

Timeline and source

Published on 30 March 2022 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

lists.opensuse.org (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2022-03-30
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
dtb-aarch64 5.3.18-150300.59.60.4
kernel-64kb 5.3.18-150300.59.60.4
kernel-debug 5.3.18-150300.59.60.4
kernel-default 5.3.18-150300.59.60.4
kernel-default-base 5.3.18-150300.59.60.4.150300.18.37.5
kernel-docs 5.3.18-150300.59.60.4
kernel-kvmsmall 5.3.18-150300.59.60.4
kernel-obs-build 5.3.18-150300.59.60.4
kernel-obs-qa 5.3.18-150300.59.60.4
kernel-preempt 5.3.18-150300.59.60.4
kernel-source 5.3.18-150300.59.60.4
kernel-syms 5.3.18-150300.59.60.4
kernel-zfcpdump 5.3.18-150300.59.60.4

References

Free Vulnerability Check

Is your site affected by openSUSE-SU-2022:1039-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against openSUSE-SU-2022:1039-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.