File _patchinfo of Package patchinfo.23660
<patchinfo incident="23660"> <issue id="1195951" tracker="bnc">VUL-0: CVE-2022-22942: kernel live patch: Vulnerability in the vmwgfx driver</issue> <issue id="1197133" tracker="bnc"> VUL-0: CVE-2022-27666: kernel live patch: buffer overflow in IPsec ESP transformation code</issue> <issue id="2022-27666" tracker="cve" /> <issue id="2022-22942" tracker="cve" /> <category>security</category> <rating>important</rating> <packager>nstange</packager> <description>This update for the Linux Kernel 4.12.14-197_102 fixes several issues. The following security issues were fixed: - CVE-2022-27666: Fixed a buffer overflow vulnerability in IPsec ESP transformation code. This flaw allowed a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation. (bnc#1197462) - CVE-2022-22942: Fixed stale file descriptors on failed usercopy. (bsc#1195065) </description> <summary>Security update for the Linux Kernel (Live Patch 27 for SLE 15 SP1)</summary> </patchinfo>