Alibaba Cloud Linux 2.1903 Security Advisory: ALINUX2-SA-2022:0022
Issued: 2022-04-12
Updated: 2022-04-12
Summary
cloud-kernel bugfix, enhancement and security update
Severity
Important
Description
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities:
CVE-2022-1016:
CVE-2022-1016 kernel: uninitialized registers on stack in nft_do_chain can cause kernel pointer leakage to UM
CVE-2022-27666:
CVE-2022-27666 kernel: buffer overflow in IPsec ESP transformation code
CVE-2021-3743:
CVE-2021-3743 kernel: out-of-bound Read in qrtr_endpoint_post in net/qrtr/qrtr.c
CVE-2021-45868:
CVE-2021-45868 kernel: fs/quota/quota_tree.c does not validate the block number in the quota tree
CVE-2021-4002:
CVE-2021-4002 kernel: possible leak or coruption of data residing on hugetlbfs
CVE-2020-36516:
CVE-2020-36516 kernel: an off-path attacker may inject data or terminate a victim's TCP session
CVE-2020-36516:
CVE-2020-36516 kernel: an off-path attacker may inject data or terminate a victim's TCP session
CVE-2021-44879:
CVE-2021-44879 kernel: NULL pointer dereference in folio_mark_dirty() via a crafted f2fs image
CVE-2022-24448:
CVE-2022-24448 kernel: nfs_atomic_open() returns uninitialized data instead of ENOTDIR
CVE-2021-4135:
CVE-2021-4135 kernel: Heap information leak in map_lookup_elem function
References
Updated Packages
- aarch64
- bpftool-4.19.91-25.8.al7.aarch64.rpm → (download)
- kernel-4.19.91-25.8.al7.aarch64.rpm → (download)
- kernel-debug-4.19.91-25.8.al7.aarch64.rpm → (download)
- kernel-debug-debuginfo-4.19.91-25.8.al7.aarch64.rpm → (download)
- kernel-debug-devel-4.19.91-25.8.al7.aarch64.rpm → (download)
- kernel-debuginfo-4.19.91-25.8.al7.aarch64.rpm → (download)
- kernel-debuginfo-common-aarch64-4.19.91-25.8.al7.aarch64.rpm → (download)
- kernel-devel-4.19.91-25.8.al7.aarch64.rpm → (download)
- kernel-headers-4.19.91-25.8.al7.aarch64.rpm → (download)
- kernel-tools-4.19.91-25.8.al7.aarch64.rpm → (download)
- kernel-tools-debuginfo-4.19.91-25.8.al7.aarch64.rpm → (download)
- kernel-tools-libs-4.19.91-25.8.al7.aarch64.rpm → (download)
- kernel-tools-libs-devel-4.19.91-25.8.al7.aarch64.rpm → (download)
- perf-4.19.91-25.8.al7.aarch64.rpm → (download)
- perf-debuginfo-4.19.91-25.8.al7.aarch64.rpm → (download)
- python-perf-4.19.91-25.8.al7.aarch64.rpm → (download)
- python-perf-debuginfo-4.19.91-25.8.al7.aarch64.rpm → (download)
- x86_64
- bpftool-4.19.91-25.8.al7.x86_64.rpm → (download)
- kernel-4.19.91-25.8.al7.x86_64.rpm → (download)
- kernel-debug-4.19.91-25.8.al7.x86_64.rpm → (download)
- kernel-debug-debuginfo-4.19.91-25.8.al7.x86_64.rpm → (download)
- kernel-debug-devel-4.19.91-25.8.al7.x86_64.rpm → (download)
- kernel-debuginfo-4.19.91-25.8.al7.x86_64.rpm → (download)
- kernel-debuginfo-common-x86_64-4.19.91-25.8.al7.x86_64.rpm → (download)
- kernel-devel-4.19.91-25.8.al7.x86_64.rpm → (download)
- kernel-headers-4.19.91-25.8.al7.x86_64.rpm → (download)
- kernel-tools-4.19.91-25.8.al7.x86_64.rpm → (download)
- kernel-tools-debuginfo-4.19.91-25.8.al7.x86_64.rpm → (download)
- kernel-tools-libs-4.19.91-25.8.al7.x86_64.rpm → (download)
- kernel-tools-libs-devel-4.19.91-25.8.al7.x86_64.rpm → (download)
- perf-4.19.91-25.8.al7.x86_64.rpm → (download)
- perf-debuginfo-4.19.91-25.8.al7.x86_64.rpm → (download)
- python-perf-4.19.91-25.8.al7.x86_64.rpm → (download)
- python-perf-debuginfo-4.19.91-25.8.al7.x86_64.rpm → (download)
- src
- kernel-4.19.91-25.8.al7.src.rpm → (download)
- i686
- kernel-headers-4.19.91-25.8.al7.i686.rpm → (download)