File _patchinfo of Package patchinfo.26777
<patchinfo incident="26777">
<issue id="1201742" tracker="bnc">VUL-0: CVE-2020-36557: kernel live patch: use after free due to race condition in ioctl(VT_DISALLOCATE)</issue>
<issue id="1201752" tracker="bnc">VUL-0: CVE-2020-36558: kernel live patch: use after free due to race condition between ioctl(VT_DISALLOCATE) and ioctl(VT_RESIZEX)</issue>
<issue id="1202087" tracker="bnc">VUL-0: CVE-2021-33655: kernel live patch: Out of bounds write with ioctl cmd FBIOPUT_VSCREENINFO</issue>
<issue id="1203613" tracker="bnc">VUL-0: CVE-2022-2588: kernel live patch: use-after-free in cls_route</issue>
<issue id="1204170" tracker="bnc">VUL-0: CVE-2022-42703: kernel live patch: mm/rmap.c has a use-after-free related to leaf anon_vma double reuse.</issue>
<issue id="1204381" tracker="bnc">kernel livepatch for: execve() incorrectly handles empty argv array</issue>
<issue id="2020-36557" tracker="cve" />
<issue id="2020-36558" tracker="cve" />
<issue id="2021-33655" tracker="cve" />
<issue id="2022-2588" tracker="cve" />
<issue id="2022-42703" tracker="cve" />
<category>security</category>
<rating>important</rating>
<packager>nstange</packager>
<description>This update for the Linux Kernel 4.12.14-150000_150_89 fixes several issues.
The following security issues were fixed:
- CVE-2020-36557: Fixed a race condition between the VT_DISALLOCATE ioctl and closing/opening of ttys that could have led to a use-after-free (bnc#1201429).
- CVE-2020-36558: Fixed a race condition involving VT_RESIZEX which could lead to a NULL pointer dereference and general protection fault (bnc#1200910).
- CVE-2021-33655: Fixed out of bounds write with ioctl FBIOPUT_VSCREENINFO (bnc#1201635).
- CVE-2022-2588: Fixed use-after-free in cls_route (bsc#1202096).
- CVE-2022-42703: Fixed use-after-free in mm/rmap.c related to leaf anon_vma double reuse (bnc#1204168).
- Fixed incorrect handling of empty arguments array in execve() (bsc#1200571).
</description>
<summary>Security update for the Linux Kernel (Live Patch 29 for SLE 15)</summary>
</patchinfo>