File _patchinfo of Package patchinfo.28707
<patchinfo incident="28707">
<issue id="1203993" tracker="bnc">VUL-0: CVE-2022-2991: kernel live patch: heap-based overflow in the lightnvm subsystem</issue>
<issue id="1207822" tracker="bnc">VUL-0: CVE-2023-0590: kernel live patch: Kernel: use-after-free due to race condition in qdisc_graft()</issue>
<issue id="1208910" tracker="bnc">VUL-0: CVE-2023-1118: kernel live patch: UAF drivers/media/rc directory</issue>
<issue id="2022-2991" tracker="cve" />
<issue id="2023-0590" tracker="cve" />
<issue id="2023-1118" tracker="cve" />
<category>security</category>
<rating>important</rating>
<packager>nstange</packager>
<description>This update for the Linux Kernel 4.12.14-150100_197_117 fixes several issues.
The following security issues were fixed:
- CVE-2023-0590: Fixed race condition in qdisc_graft() (bsc#1207795).
- CVE-2023-1118: Fixed a use-after-free bugs caused by ene_tx_irqsim() in media/rc (bsc#1208837).
- CVE-2022-2991: Fixed an heap-based overflow in the lightnvm implemenation (bsc#1201420).
</description>
<summary>Security update for the Linux Kernel (Live Patch 32 for SLE 15 SP1)</summary>
</patchinfo>