Lucene search

K
oraclelinuxOracleLinuxELSA-2024-12193
HistoryMar 01, 2024 - 12:00 a.m.

Unbreakable Enterprise kernel security update

2024-03-0100:00:00
linux.oracle.com
31
enterprise kernel
security update
input_set_capability
bounds checking
netfilter
ctnetlink
refcount leak fix
cve-2022-48619
cve-2023-7192
cve-2024-0775
cve-2023-51780
cve-2021-34981

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

28.8%

[4.1.12-124.83.2]

  • Input: add bounds checking to input_set_capability() (Jeff LaBundy) [Orabug: 36192120] {CVE-2022-48619}
  • netfilter: ctnetlink: fix possible refcount leak in ctnetlink_create_conntrack() (Hangyu Hua) [Orabug: 36155598] {CVE-2023-7192}
    [4.1.12-124.83.1]
  • ext4: improve error recovery code paths in __ext4_remount() (Theodore Ts’o) [Orabug: 36229451] {CVE-2024-0775}
  • atm: Fix Use-After-Free in do_vcc_ioctl (Hyunwoo Kim) [Orabug: 36229396] {CVE-2023-51780}
  • Bluetooth: cmtp: fix file refcount when cmtp_attach_device fails (Thadeu Lima de Souza Cascardo) [Orabug: 36229182] {CVE-2021-34981}

CVSS3

7.1

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H

AI Score

7.2

Confidence

Low

EPSS

0.001

Percentile

28.8%