OESA-2022-1559

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2022-1559
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2022-1559.json
JSON Data
https://api.osv.dev/v1/vulns/OESA-2022-1559
Upstream
Published
2022-03-07T11:03:36Z
Modified
2025-09-03T06:17:40.014891Z
Summary
kernel security update
Details

The Linux Kernel, the operating system core itself.

Security Fix(es):

A vulnerability was found in the Linux kernel's EBPF verifier when handling internal data structures. Internal memory locations could be returned to userspace. A local attacker with the permissions to insert eBPF code to the kernel can use this to leak internal kernel memory details defeating some of the exploit mitigations in place for the kernel.(CVE-2021-4159)

An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.(CVE-2022-25258)

An issue was discovered in drivers/usb/gadget/function/rndis.c in the Linux kernel before 5.16.10. The RNDIS USB gadget lacks validation of the size of the RNDISMSGSET command. Attackers can obtain sensitive information from kernel memory.(CVE-2022-25375)

A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udffilewrite_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc1 till 5.17-rc2.(CVE-2022-0617)

Database specific
{
    "severity": "Medium"
}
References

Affected packages

openEuler:20.03-LTS-SP1 / kernel

Package

Name
kernel
Purl
pkg:rpm/openEuler/kernel&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.19.90-2203.1.0.0139.oe1

Ecosystem specific

{
    "src": [
        "kernel-4.19.90-2203.1.0.0139.oe1.src.rpm"
    ],
    "x86_64": [
        "kernel-devel-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "python2-perf-debuginfo-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "kernel-source-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "perf-debuginfo-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "bpftool-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "python2-perf-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "kernel-debugsource-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "kernel-tools-devel-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "python3-perf-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "perf-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "kernel-tools-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "python3-perf-debuginfo-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "kernel-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "kernel-tools-debuginfo-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "kernel-debuginfo-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "bpftool-debuginfo-4.19.90-2203.1.0.0139.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "kernel-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "kernel-tools-devel-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "kernel-tools-debuginfo-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "python2-perf-debuginfo-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "kernel-debuginfo-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "python3-perf-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "python3-perf-debuginfo-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "kernel-source-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "python2-perf-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "bpftool-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "kernel-debugsource-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "bpftool-debuginfo-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "kernel-devel-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "kernel-tools-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "perf-debuginfo-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "perf-4.19.90-2203.1.0.0139.oe1.aarch64.rpm"
    ]
}

openEuler:20.03-LTS-SP2 / kernel

Package

Name
kernel
Purl
pkg:rpm/openEuler/kernel&distro=openEuler-20.03-LTS-SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.19.90-2203.1.0.0138.oe1

Ecosystem specific

{
    "src": [
        "kernel-4.19.90-2203.1.0.0138.oe1.src.rpm"
    ],
    "x86_64": [
        "kernel-devel-4.19.90-2203.1.0.0138.oe1.x86_64.rpm",
        "bpftool-debuginfo-4.19.90-2203.1.0.0138.oe1.x86_64.rpm",
        "kernel-tools-devel-4.19.90-2203.1.0.0138.oe1.x86_64.rpm",
        "perf-debuginfo-4.19.90-2203.1.0.0138.oe1.x86_64.rpm",
        "python3-perf-4.19.90-2203.1.0.0138.oe1.x86_64.rpm",
        "python2-perf-4.19.90-2203.1.0.0138.oe1.x86_64.rpm",
        "python3-perf-debuginfo-4.19.90-2203.1.0.0138.oe1.x86_64.rpm",
        "kernel-tools-debuginfo-4.19.90-2203.1.0.0138.oe1.x86_64.rpm",
        "kernel-debuginfo-4.19.90-2203.1.0.0138.oe1.x86_64.rpm",
        "perf-4.19.90-2203.1.0.0138.oe1.x86_64.rpm",
        "kernel-source-4.19.90-2203.1.0.0138.oe1.x86_64.rpm",
        "bpftool-4.19.90-2203.1.0.0138.oe1.x86_64.rpm",
        "python2-perf-debuginfo-4.19.90-2203.1.0.0138.oe1.x86_64.rpm",
        "kernel-debugsource-4.19.90-2203.1.0.0138.oe1.x86_64.rpm",
        "kernel-4.19.90-2203.1.0.0138.oe1.x86_64.rpm",
        "kernel-tools-4.19.90-2203.1.0.0138.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "kernel-debuginfo-4.19.90-2203.1.0.0138.oe1.aarch64.rpm",
        "perf-debuginfo-4.19.90-2203.1.0.0138.oe1.aarch64.rpm",
        "kernel-4.19.90-2203.1.0.0138.oe1.aarch64.rpm",
        "python2-perf-debuginfo-4.19.90-2203.1.0.0138.oe1.aarch64.rpm",
        "python3-perf-debuginfo-4.19.90-2203.1.0.0138.oe1.aarch64.rpm",
        "kernel-source-4.19.90-2203.1.0.0138.oe1.aarch64.rpm",
        "python3-perf-4.19.90-2203.1.0.0138.oe1.aarch64.rpm",
        "kernel-tools-devel-4.19.90-2203.1.0.0138.oe1.aarch64.rpm",
        "bpftool-4.19.90-2203.1.0.0138.oe1.aarch64.rpm",
        "kernel-debugsource-4.19.90-2203.1.0.0138.oe1.aarch64.rpm",
        "kernel-tools-debuginfo-4.19.90-2203.1.0.0138.oe1.aarch64.rpm",
        "kernel-devel-4.19.90-2203.1.0.0138.oe1.aarch64.rpm",
        "bpftool-debuginfo-4.19.90-2203.1.0.0138.oe1.aarch64.rpm",
        "python2-perf-4.19.90-2203.1.0.0138.oe1.aarch64.rpm",
        "kernel-tools-4.19.90-2203.1.0.0138.oe1.aarch64.rpm",
        "perf-4.19.90-2203.1.0.0138.oe1.aarch64.rpm"
    ]
}

openEuler:20.03-LTS-SP3 / kernel

Package

Name
kernel
Purl
pkg:rpm/openEuler/kernel&distro=openEuler-20.03-LTS-SP3

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.19.90-2203.1.0.0139.oe1

Ecosystem specific

{
    "src": [
        "kernel-4.19.90-2203.1.0.0139.oe1.src.rpm"
    ],
    "x86_64": [
        "bpftool-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "perf-debuginfo-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "perf-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "bpftool-debuginfo-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "python2-perf-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "kernel-tools-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "kernel-tools-debuginfo-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "kernel-debugsource-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "kernel-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "python3-perf-debuginfo-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "kernel-devel-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "kernel-tools-devel-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "python3-perf-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "kernel-source-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "python2-perf-debuginfo-4.19.90-2203.1.0.0139.oe1.x86_64.rpm",
        "kernel-debuginfo-4.19.90-2203.1.0.0139.oe1.x86_64.rpm"
    ],
    "aarch64": [
        "kernel-tools-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "kernel-debugsource-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "kernel-debuginfo-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "kernel-tools-devel-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "kernel-source-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "perf-debuginfo-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "python2-perf-debuginfo-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "kernel-devel-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "python3-perf-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "python3-perf-debuginfo-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "kernel-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "bpftool-debuginfo-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "perf-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "kernel-tools-debuginfo-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "bpftool-4.19.90-2203.1.0.0139.oe1.aarch64.rpm",
        "python2-perf-4.19.90-2203.1.0.0139.oe1.aarch64.rpm"
    ]
}