Lucene search

K
almalinuxAlmaLinuxALSA-2023:1703
HistoryApr 11, 2023 - 12:00 a.m.

Important: kernel security and bug fix update

2023-04-1100:00:00
errata.almalinux.org
28
kernel
linux
security
bug fix
fuse filesystem
user privileges escalation
cvss score
eaglestream
sapphire rapids
bz#2168361
bz#2168836

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

61.0%

The kernel packages contain the Linux kernel, the core of any Linux operating system.

Security Fix(es):

  • kernel: FUSE filesystem low-privileged user privileges escalation (CVE-2023-0386)

For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section.

Bug Fix(es):

  • Update intel_idle for Eaglestream/Sapphire Rapids support (BZ#2168361)
  • AlmaLinux9: An application stopped on robust futex used via pthread_mutex_lock() (BZ#2168836)

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0.002

Percentile

61.0%