Alibaba Cloud Linux 2.1903 Security Advisory: ALINUX2-SA-2022:0016

Issued: 2022-03-08
Updated: 2022-03-08

Summary

cloud-kernel bugfix, enhancement and security update

Severity

Important

Description

Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities:

CVE-2022-0847:
CVE-2022-0847 kernel: improper initialization of the "flags" member of the new pipe_buffer

CVE-2022-0435:
CVE-2022-0435 kernel: remote stack overflow via kernel panic on systems using TIPC may lead to DoS

References

Updated Packages