2024-12-12 21:07:30 +00:00

191 lines
8.0 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20222071",
"Version": "oval:org.altlinux.errata:def:20222071",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2022-2071: package `kernel-image-un-def` update to version 5.17.15-alt2",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p11"
],
"Products": [
"ALT Container"
]
}
],
"References": [
{
"RefID": "ALT-PU-2022-2071",
"RefURL": "https://errata.altlinux.org/ALT-PU-2022-2071",
"Source": "ALTPU"
},
{
"RefID": "BDU:2022-03532",
"RefURL": "https://bdu.fstec.ru/vul/2022-03532",
"Source": "BDU"
},
{
"RefID": "BDU:2022-03600",
"RefURL": "https://bdu.fstec.ru/vul/2022-03600",
"Source": "BDU"
},
{
"RefID": "BDU:2022-05155",
"RefURL": "https://bdu.fstec.ru/vul/2022-05155",
"Source": "BDU"
},
{
"RefID": "CVE-2022-21123",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-21123",
"Source": "CVE"
},
{
"RefID": "CVE-2022-21125",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-21125",
"Source": "CVE"
},
{
"RefID": "CVE-2022-21166",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2022-21166",
"Source": "CVE"
}
],
"Description": "This update upgrades kernel-image-un-def to version 5.17.15-alt2. \nSecurity Fix(es):\n\n * BDU:2022-03532: Уязвимость общих буферов системы ввода-вывода с отображением памяти (MMIO) процессоров Intel, позволяющая нарушителю раскрыть защищаемую информацию\n\n * BDU:2022-03600: Уязвимость набора средств разработки Intel Software Guard Extensions SDK, микропрограммного обеспечения Intel SGX DCAP, SGX PSW, PSW связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю раскрыть защищаемую информацию\n\n * BDU:2022-05155: Уязвимость системы ввода-вывода с отображением памяти (MMIO) процессоров Intel, позволяющая нарушителю раскрыть защищаемую информацию\n\n * CVE-2022-21123: Incomplete cleanup of multi-core shared buffers for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.\n\n * CVE-2022-21125: Incomplete cleanup of microarchitectural fill buffers on some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.\n\n * CVE-2022-21166: Incomplete cleanup in specific special register write operations for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2022-06-18"
},
"Updated": {
"Date": "2022-06-18"
},
"BDUs": [
{
"ID": "BDU:2022-03532",
"CVSS": "AV:L/AC:L/Au:S/C:C/I:P/A:N",
"CVSS3": "AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N",
"CWE": "CWE-200",
"Href": "https://bdu.fstec.ru/vul/2022-03532",
"Impact": "Low",
"Public": "20220614"
},
{
"ID": "BDU:2022-03600",
"CVSS": "AV:L/AC:L/Au:S/C:C/I:N/A:N",
"CVSS3": "AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-119",
"Href": "https://bdu.fstec.ru/vul/2022-03600",
"Impact": "Low",
"Public": "20220614"
},
{
"ID": "BDU:2022-05155",
"CVSS": "AV:L/AC:H/Au:S/C:C/I:N/A:N",
"CVSS3": "AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N",
"CWE": "CWE-200, CWE-459",
"Href": "https://bdu.fstec.ru/vul/2022-05155",
"Impact": "Low",
"Public": "20220614"
}
],
"CVEs": [
{
"ID": "CVE-2022-21123",
"CVSS": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-459",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-21123",
"Impact": "Low",
"Public": "20220615"
},
{
"ID": "CVE-2022-21125",
"CVSS": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-459",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-21125",
"Impact": "Low",
"Public": "20220615"
},
{
"ID": "CVE-2022-21166",
"CVSS": "AV:L/AC:L/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-459",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2022-21166",
"Impact": "Low",
"Public": "20220615"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:container:11"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:3001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20222071001",
"Comment": "kernel-doc-un is earlier than 1:5.17.15-alt2"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222071002",
"Comment": "kernel-headers-modules-un-def is earlier than 1:5.17.15-alt2"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222071003",
"Comment": "kernel-headers-un-def is earlier than 1:5.17.15-alt2"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222071004",
"Comment": "kernel-image-domU-un-def is earlier than 1:5.17.15-alt2"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222071005",
"Comment": "kernel-image-un-def is earlier than 1:5.17.15-alt2"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222071006",
"Comment": "kernel-image-un-def-checkinstall is earlier than 1:5.17.15-alt2"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222071007",
"Comment": "kernel-modules-drm-ancient-un-def is earlier than 1:5.17.15-alt2"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222071008",
"Comment": "kernel-modules-drm-nouveau-un-def is earlier than 1:5.17.15-alt2"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222071009",
"Comment": "kernel-modules-drm-un-def is earlier than 1:5.17.15-alt2"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20222071010",
"Comment": "kernel-modules-staging-un-def is earlier than 1:5.17.15-alt2"
}
]
}
]
}
}
]
}