Security update for the Linux Kernel (Live Patch 2 for SLE 15 SP4)
Details
This update for the Linux Kernel 5.14.21-1504002418 fixes several issues.
The following security issues were fixed:
CVE-2022-4379: A use-after-free vulnerability was found in _nfs42ssc_open() in fs/nfs/nfs4file.c in the Linux kernel. This flaw allowed an attacker to conduct a remote denial of service attack (bsc#1206373).
CVE-2022-3424: Fixed use-after-free in grusetcontextoption(), grufault() and gruhandleusercallos() that could lead to kernel panic (bsc#1204167).
CVE-2022-2602: Fixed a local privilege escalation vulnerability involving Unix socket Garbage Collection and io_uring (bsc#1205186).