2024-01-10 07:45:25 +00:00

204 lines
8.3 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20221611",
"Version": "oval:org.altlinux.errata:def:20221611",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2022-1611: package `kernel-image-std-def` update to version 5.10.109-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p10"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2022-1611",
"RefURL": "https://errata.altlinux.org/ALT-PU-2022-1611",
"Source": "ALTPU"
},
{
"RefID": "BDU:2022-01597",
"RefURL": "https://bdu.fstec.ru/vul/2022-01597",
"Source": "BDU"
},
{
"RefID": "BDU:2022-02968",
"RefURL": "https://bdu.fstec.ru/vul/2022-02968",
"Source": "BDU"
},
{
"RefID": "CVE-2022-0995",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-0995",
"Source": "CVE"
},
{
"RefID": "CVE-2022-29156",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-29156",
"Source": "CVE"
}
],
"Description": "This update upgrades kernel-image-std-def to version 5.10.109-alt1. \nSecurity Fix(es):\n\n * BDU:2022-01597: Уязвимость компонента watch_queue ядра операционной системы Linux, позволяющая нарушителю выполнить произвольный код с привилегиями root\n\n * BDU:2022-02968: Уязвимость функции rtrs_clt_dev_release (drivers/infiniband/ulp/rtrs/rtrs-clt.c) ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2022-0995: An out-of-bounds (OOB) memory write flaw was found in the Linux kernels watch_queue event notification subsystem. This flaw can overwrite parts of the kernel state, potentially allowing a local user to gain privileged access or cause a denial of service on the system.\n\n * CVE-2022-29156: drivers/infiniband/ulp/rtrs/rtrs-clt.c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_release.\n\n * #42123: Не работает правая кнопка мыши на тачпаде ноутбука ICL Si1516",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2023 BaseALT Ltd.",
"Issued": {
"Date": "2022-04-01"
},
"Updated": {
"Date": "2022-04-01"
},
"bdu": [
{
"Cvss": "AV:L/AC:L/Au:S/C:C/I:C/A:C",
"Cvss3": "AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"Cwe": "CWE-787",
"Href": "https://bdu.fstec.ru/vul/2022-01597",
"Impact": "High",
"Public": "20220325",
"CveID": "BDU:2022-01597"
},
{
"Cvss": "AV:L/AC:L/Au:S/C:C/I:C/A:C",
"Cvss3": "AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"Cwe": "CWE-415",
"Href": "https://bdu.fstec.ru/vul/2022-02968",
"Impact": "High",
"Public": "20220413",
"CveID": "BDU:2022-02968"
}
],
"Cves": [
{
"Cvss": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"Cvss3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"Cwe": "CWE-787",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-0995",
"Impact": "High",
"Public": "20220325",
"CveID": "CVE-2022-0995"
},
{
"Cvss": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"Cvss3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"Cwe": "CWE-415",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-29156",
"Impact": "High",
"Public": "20220413",
"CveID": "CVE-2022-29156"
}
],
"Bugzilla": [
{
"Id": "42123",
"Href": "https://bugzilla.altlinux.org/42123",
"Data": "Не работает правая кнопка мыши на тачпаде ноутбука ICL Si1516"
}
],
"AffectedCpeList": {
"Cpe": [
"cpe:/o:alt:kworkstation:10",
"cpe:/o:alt:workstation:10",
"cpe:/o:alt:server:10",
"cpe:/o:alt:server-v:10",
"cpe:/o:alt:education:10",
"cpe:/o:alt:slinux:10",
"cpe:/o:alt:starterkit:p10",
"cpe:/o:alt:kworkstation:10.1",
"cpe:/o:alt:workstation:10.1",
"cpe:/o:alt:server:10.1",
"cpe:/o:alt:server-v:10.1",
"cpe:/o:alt:education:10.1",
"cpe:/o:alt:slinux:10.1",
"cpe:/o:alt:starterkit:10.1",
"cpe:/o:alt:kworkstation:10.2",
"cpe:/o:alt:workstation:10.2",
"cpe:/o:alt:server:10.2",
"cpe:/o:alt:server-v:10.2",
"cpe:/o:alt:education:10.2",
"cpe:/o:alt:slinux:10.2",
"cpe:/o:alt:starterkit:10.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:2001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20221611001",
"Comment": "kernel-doc-std is earlier than 2:5.10.109-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20221611002",
"Comment": "kernel-headers-modules-std-def is earlier than 2:5.10.109-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20221611003",
"Comment": "kernel-headers-std-def is earlier than 2:5.10.109-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20221611004",
"Comment": "kernel-image-domU-std-def is earlier than 2:5.10.109-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20221611005",
"Comment": "kernel-image-std-def is earlier than 2:5.10.109-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20221611006",
"Comment": "kernel-image-std-def-checkinstall is earlier than 2:5.10.109-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20221611007",
"Comment": "kernel-modules-drm-ancient-std-def is earlier than 2:5.10.109-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20221611008",
"Comment": "kernel-modules-drm-nouveau-std-def is earlier than 2:5.10.109-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20221611009",
"Comment": "kernel-modules-drm-std-def is earlier than 2:5.10.109-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20221611010",
"Comment": "kernel-modules-ide-std-def is earlier than 2:5.10.109-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20221611011",
"Comment": "kernel-modules-midgard-be-m1000-std-def is earlier than 2:5.10.109-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20221611012",
"Comment": "kernel-modules-staging-std-def is earlier than 2:5.10.109-alt1"
}
]
}
]
}
}
]
}