Lucene search

K
rosalinuxROSA LABROSA-SA-2023-2097
HistoryFeb 07, 2023 - 10:10 a.m.

Advisory ROSA-SA-2023-2097

2023-02-0710:10:41
ROSA LAB
abf.rosalinux.ru
19
kernel 3.10.0-1160.83.1.el7
rosa-server79
usb driver vulnerability
memory boundaries
gain access
sensitive information
lfence/jmp protection
amd processors

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.975 High

EPSS

Percentile

100.0%

Software: kernel 3.10.0-1160.83.1.el7
OS: rosa-server79

package_evr_string: 3.10.0-1160.83.1.el7

CVE-ID: CVE-2022-2964
BDU-ID: 2022-05848
CVE-Crit: HIGH
CVE-DESC: A vulnerability in the Linux operating system kernel driver for ASIX AX88179_178A-based USB 2.0/3.0 Gigabit Ethernet devices is related to read and write operations outside of memory boundaries. Exploitation of the vulnerability could allow an attacker to gain access to potentially sensitive information.
CVE-STATUS: Resolved
CVE-REV: Execute yum update command to close it

CVE-ID: CVE-2021-26401
BDU-ID: None
CVE-Crit: MEDIUM
CVE-DESC: LFENCE/JMP may not sufficiently protect against CVE-2017-5715 on some AMD processors.
CVE-STATUS: Fixed
CVE-REV: Run the yum update command to close it

OSVersionArchitecturePackageVersionFilename
rosaanynoarchkernel< 3.10.0UNKNOWN

1.9 Low

CVSS2

Attack Vector

LOCAL

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:M/Au:N/C:P/I:N/A:N

7.8 High

CVSS3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

0.975 High

EPSS

Percentile

100.0%