VARIoT IoT vulnerabilities database
| VAR-202203-0003 | CVE-2021-35103 | Out-of-bounds write vulnerability in multiple Qualcomm products |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Possible out of bound write due to improper validation of number of timer values received from firmware while syncing timers in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables, Snapdragon Wired Infrastructure and Networking. AR8035 firmware, AR9380 firmware, CSR8811 Several Qualcomm products, such as firmware, contain an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202203-0081 | CVE-2021-35117 | Out-of-bounds read vulnerability in multiple Qualcomm products |
CVSS V2: 9.4 CVSS V3: 9.1 Severity: CRITICAL |
An Out of Bounds read may potentially occur while processing an IBSS beacon, in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music. APQ8096AU firmware, AQT1000 firmware, AR8031 Multiple Qualcomm products, such as firmware, contain an out-of-bounds read vulnerability.Information is obtained and service operation is interrupted (DoS) It may be in a state
| VAR-202203-0027 | CVE-2021-30333 | Out-of-bounds write vulnerability in multiple Qualcomm products |
CVSS V2: 4.6 CVSS V3: 7.8 Severity: HIGH |
Improper validation of buffer size input to the EFS file can lead to memory corruption in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. APQ8009W firmware, APQ8017 firmware, APQ8053 Several Qualcomm products, such as firmware, contain an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202203-0071 | CVE-2021-35105 | Incorrect type conversion vulnerability in multiple Qualcomm products |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
Possible out of bounds access due to improper input validation during graphics profiling in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables. APQ8009W firmware, APQ8017 firmware, APQ8053 Multiple Qualcomm products such as firmware contain vulnerabilities related to illegal type conversion.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state
| VAR-202203-0043 | CVE-2022-0847 | Linux Kernel Initialization vulnerability in |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system. Linux Kernel Has an initialization vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Summary:
The Migration Toolkit for Containers (MTC) 1.5.4 is now available. Description:
The Migration Toolkit for Containers (MTC) enables you to migrate
Kubernetes resources, persistent volume data, and internal container images
between OpenShift Container Platform clusters, using the MTC web console or
the Kubernetes API. Bugs fixed (https://bugzilla.redhat.com/):
1995656 - CVE-2021-36221 golang: net/http/httputil: panic due to racy read of persistConn after handler panic
5. This update provides security fixes, bug
fixes, and updates the container images. Description:
Red Hat Advanced Cluster Management for Kubernetes 2.4.3 images
Red Hat Advanced Cluster Management for Kubernetes provides the
capabilities to address common challenges that administrators and site
reliability engineers face as they work across a range of public and
private cloud environments. Clusters and applications are all visible and
managed from a single console—with security policy built in.
See the following Release Notes documentation, which will be updated
shortly for this release, for additional details about this release:
https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_management_for_kubernetes/2.4/html/release_notes/
Security updates:
* golang.org/x/crypto: empty plaintext packet causes panic (CVE-2021-43565)
* nats-server: misusing the "dynamically provisioned sandbox accounts"
feature authenticated user can obtain the privileges of the System account
(CVE-2022-24450)
* nanoid: Information disclosure via valueOf() function (CVE-2021-23566)
* nodejs-shelljs: improper privilege management (CVE-2022-0144)
* search-ui-container: follow-redirects: Exposure of Private Personal
Information to an Unauthorized Actor (CVE-2022-0155)
* node-fetch: exposure of sensitive information to an unauthorized actor
(CVE-2022-0235)
* follow-redirects: Exposure of Sensitive Information via Authorization
Header leak (CVE-2022-0536)
* openssl: Infinite loop in BN_mod_sqrt() reachable when parsing
certificates (CVE-2022-0778)
* imgcrypt: Unauthorized access to encryted container image on a shared
system due to missing check in CheckAuthorization() code path
(CVE-2022-24778)
* golang: crash in a golang.org/x/crypto/ssh server (CVE-2022-27191)
* opencontainers: OCI manifest and index parsing confusion (CVE-2021-41190)
Related bugs:
* RHACM 2.4.3 image files (BZ #2057249)
* Observability - dashboard name contains `/` would cause error when
generating dashboard cm (BZ #2032128)
* ACM application placement fails after renaming the application name (BZ
#2033051)
* Disable the obs metric collect should not impact the managed cluster
upgrade (BZ #2039197)
* Observability - cluster list should only contain OCP311 cluster on OCP311
dashboard (BZ #2039820)
* The value of name label changed from clusterclaim name to cluster name
(BZ #2042223)
* VMWare Cluster creation does not accept ecdsa-sha2-nistp521 ssh keys (BZ
#2048500)
* clusterSelector matchLabels spec are cleared when changing app
name/namespace during creating an app in UI (BZ #2053211)
* Application cluster status is not updated in UI after restoring (BZ
#2053279)
* OpenStack cluster creation is using deprecated floating IP config for
4.7+ (BZ #2056610)
* The value of Vendor reported by cluster metrics was Other even if the
vendor label in managedcluster was Openshift (BZ #2059039)
* Subscriptions stop reconciling after channel secrets are recreated (BZ
#2059954)
* Placementrule is not reconciling on a new fresh environment (BZ #2074156)
* The cluster claimed from clusterpool cannot auto imported (BZ #2074543)
3. Bugs fixed (https://bugzilla.redhat.com/):
2024938 - CVE-2021-41190 opencontainers: OCI manifest and index parsing confusion
2030787 - CVE-2021-43565 golang.org/x/crypto: empty plaintext packet causes panic
2032128 - Observability - dashboard name contains `/` would cause error when generating dashboard cm
2033051 - ACM application placement fails after renaming the application name
2039197 - disable the obs metric collect should not impact the managed cluster upgrade
2039820 - Observability - cluster list should only contain OCP311 cluster on OCP311 dashboard
2042223 - the value of name label changed from clusterclaim name to cluster name
2043535 - CVE-2022-0144 nodejs-shelljs: improper privilege management
2044556 - CVE-2022-0155 follow-redirects: Exposure of Private Personal Information to an Unauthorized Actor
2044591 - CVE-2022-0235 node-fetch: exposure of sensitive information to an unauthorized actor
2048500 - VMWare Cluster creation does not accept ecdsa-sha2-nistp521 ssh keys
2050853 - CVE-2021-23566 nanoid: Information disclosure via valueOf() function
2052573 - CVE-2022-24450 nats-server: misusing the "dynamically provisioned sandbox accounts" feature authenticated user can obtain the privileges of the System account
2053211 - clusterSelector matchLabels spec are cleared when changing app name/namespace during creating an app in UI
2053259 - CVE-2022-0536 follow-redirects: Exposure of Sensitive Information via Authorization Header leak
2053279 - Application cluster status is not updated in UI after restoring
2056610 - OpenStack cluster creation is using deprecated floating IP config for 4.7+
2057249 - RHACM 2.4.3 images
2059039 - The value of Vendor reported by cluster metrics was Other even if the vendor label in managedcluster was Openshift
2059954 - Subscriptions stop reconciling after channel secrets are recreated
2062202 - CVE-2022-0778 openssl: Infinite loop in BN_mod_sqrt() reachable when parsing certificates
2064702 - CVE-2022-27191 golang: crash in a golang.org/x/crypto/ssh server
2069368 - CVE-2022-24778 imgcrypt: Unauthorized access to encryted container image on a shared system due to missing check in CheckAuthorization() code path
2074156 - Placementrule is not reconciling on a new fresh environment
2074543 - The cluster claimed from clusterpool can not auto imported
5.
Bug Fix(es):
* [Intel 8.3 Bug] ICX Whitley: PCIe - kernel panic with AER-INJECT
(BZ#2040309)
* [ESXi][RHEL8] A task is stuck waiting for the completion of the
vmci_resouce releasing upon the balloon reset. [None8.2.0.z] (BZ#2052200)
4. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
=====================================================================
Red Hat Security Advisory
Synopsis: Important: kernel security, bug fix, and enhancement update
Advisory ID: RHSA-2022:0825-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2022:0825
Issue date: 2022-03-10
CVE Names: CVE-2021-0920 CVE-2021-4154 CVE-2022-0330
CVE-2022-0435 CVE-2022-0492 CVE-2022-0516
CVE-2022-0847 CVE-2022-22942
=====================================================================
1. Summary:
An update for kernel is now available for Red Hat Enterprise Linux 8.
Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat CodeReady Linux Builder (v. 8) - aarch64, ppc64le, x86_64
Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, noarch, ppc64le, s390x, x86_64
3. Description:
The kernel packages contain the Linux kernel, the core of any Linux
operating system.
The following packages have been upgraded to a later upstream version:
kernel (4.18.0). (BZ#2036888)
Security Fix(es):
* kernel: improper initialization of the "flags" member of the new
pipe_buffer (CVE-2022-0847)
* kernel: Use After Free in unix_gc() which could result in a local
privilege escalation (CVE-2021-0920)
* kernel: local privilege escalation by exploiting the fsconfig syscall
parameter leads to container breakout (CVE-2021-4154)
* kernel: possible privileges escalation due to missing TLB flush
(CVE-2022-0330)
* kernel: remote stack overflow via kernel panic on systems using TIPC may
lead to DoS (CVE-2022-0435)
* kernel: cgroups v1 release_agent feature may allow privilege escalation
(CVE-2022-0492)
* kernel: missing check in ioctl allows kernel memory read/write
(CVE-2022-0516)
* kernel: failing usercopy allows for use-after-free exploitation
(CVE-2022-22942)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Bug Fix(es):
* Intel QAT Kernel power up fix (BZ#2016437)
* RHEL8.4 seeing scsi_dma_map failed with mpt3sas driver and affecting
performance (BZ#2018928)
* [Lenovo 8.4 bug] audio_HDMI certification failed on RHEL 8.4GA (No hdmi
out) (BZ#2027335)
* [RHEL-8.5][4.18.0-323.el8.ppc64le][POWER8/9/10] security_flavor mode is
not set back to zero post online migration (BZ#2027448)
* iommu/amd: Fix unable to handle page fault due to AVIC (BZ#2030854)
* [Lenovo 8.4 bug]The VGA display shows no signal (black screen) when
install RHEL8.4(beta or rc1) in the legacy BIOS mode. (BZ#2034949)
* Double free of kmalloc-64 cache struct ib_port->pkey_group from module
ib_core . (BZ#2038724)
* Bus error with huge pages enabled (BZ#2039015)
* RHEL8 - kvm: floating interrupts may get stuck (BZ#2040769)
* Data corruption on small files served by httpd, which is backed by
cifs-mount (BZ#2041529)
* Add a net/mlx5 patch for Hardware Offload Fix (BZ#2042663)
* Windows guest random Bsod when 'hv-tlbflush' enlightenment is enabled
(BZ#2043237)
* DNS lookup failures when run two times in a row (BZ#2043548)
* net/sched: Fix ct zone matching for invalid conntrack state (BZ#2043550)
* Kernel 4.18.0-348.2.1 secpath_cache memory leak involving strongswan
tunnel (BZ#2047427)
* OCP node XFS metadata corruption after numerous reboots (BZ#2049292)
* Broadcom bnxt_re: RDMA stats are not incrementing (BZ#2049684)
* ice: bug fix series for 8.6 (BZ#2051951)
* panic while looking up a symlink due to NULL i_op->get_link (BZ#2052558)
* ceph omnibus backport for RHEL-8.6.0 (BZ#2053725)
* SCTP peel-off with SELinux and containers in OCP (BZ#2054112)
* Selinux is not allowing SCTP connection setup between inter pod
communication in enforcing mode (BZ#2054117)
* dnf fails with fsync() over local repository present on CIFS mount point
(BZ#2055824)
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
The system must be rebooted for this update to take effect.
5. Bugs fixed (https://bugzilla.redhat.com/):
2031930 - CVE-2021-0920 kernel: Use After Free in unix_gc() which could result in a local privilege escalation
2034514 - CVE-2021-4154 kernel: local privilege escalation by exploiting the fsconfig syscall parameter leads to container breakout
2042404 - CVE-2022-0330 kernel: possible privileges escalation due to missing TLB flush
2044809 - CVE-2022-22942 kernel: failing usercopy allows for use-after-free exploitation
2048738 - CVE-2022-0435 kernel: remote stack overflow via kernel panic on systems using TIPC may lead to DoS
2050237 - CVE-2022-0516 kernel: missing check in ioctl allows kernel memory read/write
2051505 - CVE-2022-0492 kernel: cgroups v1 release_agent feature may allow privilege escalation
2060795 - CVE-2022-0847 kernel: improper initialization of the "flags" member of the new pipe_buffer
6. Package List:
Red Hat Enterprise Linux BaseOS (v. 8):
Source:
kernel-4.18.0-348.20.1.el8_5.src.rpm
aarch64:
bpftool-4.18.0-348.20.1.el8_5.aarch64.rpm
bpftool-debuginfo-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-core-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-cross-headers-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-debug-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-debug-core-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-debug-debuginfo-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-debug-devel-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-debug-modules-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-debug-modules-extra-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-debuginfo-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-debuginfo-common-aarch64-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-devel-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-headers-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-modules-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-modules-extra-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-tools-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-tools-debuginfo-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-tools-libs-4.18.0-348.20.1.el8_5.aarch64.rpm
perf-4.18.0-348.20.1.el8_5.aarch64.rpm
perf-debuginfo-4.18.0-348.20.1.el8_5.aarch64.rpm
python3-perf-4.18.0-348.20.1.el8_5.aarch64.rpm
python3-perf-debuginfo-4.18.0-348.20.1.el8_5.aarch64.rpm
noarch:
kernel-abi-stablelists-4.18.0-348.20.1.el8_5.noarch.rpm
kernel-doc-4.18.0-348.20.1.el8_5.noarch.rpm
ppc64le:
bpftool-4.18.0-348.20.1.el8_5.ppc64le.rpm
bpftool-debuginfo-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-core-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-cross-headers-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-debug-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-debug-core-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-debug-debuginfo-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-debug-devel-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-debug-modules-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-debug-modules-extra-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-debuginfo-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-debuginfo-common-ppc64le-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-devel-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-headers-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-modules-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-modules-extra-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-tools-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-tools-debuginfo-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-tools-libs-4.18.0-348.20.1.el8_5.ppc64le.rpm
perf-4.18.0-348.20.1.el8_5.ppc64le.rpm
perf-debuginfo-4.18.0-348.20.1.el8_5.ppc64le.rpm
python3-perf-4.18.0-348.20.1.el8_5.ppc64le.rpm
python3-perf-debuginfo-4.18.0-348.20.1.el8_5.ppc64le.rpm
s390x:
bpftool-4.18.0-348.20.1.el8_5.s390x.rpm
bpftool-debuginfo-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-core-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-cross-headers-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-debug-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-debug-core-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-debug-debuginfo-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-debug-devel-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-debug-modules-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-debug-modules-extra-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-debuginfo-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-debuginfo-common-s390x-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-devel-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-headers-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-modules-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-modules-extra-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-tools-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-tools-debuginfo-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-zfcpdump-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-zfcpdump-core-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-zfcpdump-debuginfo-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-zfcpdump-devel-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-zfcpdump-modules-4.18.0-348.20.1.el8_5.s390x.rpm
kernel-zfcpdump-modules-extra-4.18.0-348.20.1.el8_5.s390x.rpm
perf-4.18.0-348.20.1.el8_5.s390x.rpm
perf-debuginfo-4.18.0-348.20.1.el8_5.s390x.rpm
python3-perf-4.18.0-348.20.1.el8_5.s390x.rpm
python3-perf-debuginfo-4.18.0-348.20.1.el8_5.s390x.rpm
x86_64:
bpftool-4.18.0-348.20.1.el8_5.x86_64.rpm
bpftool-debuginfo-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-core-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-cross-headers-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-debug-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-debug-core-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-debug-debuginfo-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-debug-devel-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-debug-modules-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-debug-modules-extra-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-debuginfo-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-debuginfo-common-x86_64-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-devel-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-headers-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-modules-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-modules-extra-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-tools-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-tools-debuginfo-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-tools-libs-4.18.0-348.20.1.el8_5.x86_64.rpm
perf-4.18.0-348.20.1.el8_5.x86_64.rpm
perf-debuginfo-4.18.0-348.20.1.el8_5.x86_64.rpm
python3-perf-4.18.0-348.20.1.el8_5.x86_64.rpm
python3-perf-debuginfo-4.18.0-348.20.1.el8_5.x86_64.rpm
Red Hat CodeReady Linux Builder (v. 8):
aarch64:
bpftool-debuginfo-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-debug-debuginfo-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-debuginfo-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-debuginfo-common-aarch64-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-tools-debuginfo-4.18.0-348.20.1.el8_5.aarch64.rpm
kernel-tools-libs-devel-4.18.0-348.20.1.el8_5.aarch64.rpm
perf-debuginfo-4.18.0-348.20.1.el8_5.aarch64.rpm
python3-perf-debuginfo-4.18.0-348.20.1.el8_5.aarch64.rpm
ppc64le:
bpftool-debuginfo-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-debug-debuginfo-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-debuginfo-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-debuginfo-common-ppc64le-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-tools-debuginfo-4.18.0-348.20.1.el8_5.ppc64le.rpm
kernel-tools-libs-devel-4.18.0-348.20.1.el8_5.ppc64le.rpm
perf-debuginfo-4.18.0-348.20.1.el8_5.ppc64le.rpm
python3-perf-debuginfo-4.18.0-348.20.1.el8_5.ppc64le.rpm
x86_64:
bpftool-debuginfo-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-debug-debuginfo-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-debuginfo-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-debuginfo-common-x86_64-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-tools-debuginfo-4.18.0-348.20.1.el8_5.x86_64.rpm
kernel-tools-libs-devel-4.18.0-348.20.1.el8_5.x86_64.rpm
perf-debuginfo-4.18.0-348.20.1.el8_5.x86_64.rpm
python3-perf-debuginfo-4.18.0-348.20.1.el8_5.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2021-0920
https://access.redhat.com/security/cve/CVE-2021-4154
https://access.redhat.com/security/cve/CVE-2022-0330
https://access.redhat.com/security/cve/CVE-2022-0435
https://access.redhat.com/security/cve/CVE-2022-0492
https://access.redhat.com/security/cve/CVE-2022-0516
https://access.redhat.com/security/cve/CVE-2022-0847
https://access.redhat.com/security/cve/CVE-2022-22942
https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/security/vulnerabilities/RHSB-2022-002
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2022 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBYippdNzjgjWX9erEAQjVrg//WBuZgEcpFf/4YBR6yXjJpyzeNdP/33wU
b+G6E6fGXrwoJkMNfLMMr+PmoK5QxZvX3GAqJFApn9SHXtk5M7IM68TCnTXZsXVF
M0V2ktlHJwOABXBJEXHFjnq9QllGzRkV+xJPOLKJwRB2fKtNAgOiLTJ7MrJZJtNu
WIt5IsPclPoTKrSChCL/b535XKh3hAUqD1eymuk05SqWv3mo2joLQbZpHbM0fQW3
pnvDPnE+HDM8lW8dPJTiw1K3nBRrwmuvyKxNpnGYoRN/8USNJrIGJP5gGjrI1/b8
IrV/OGeA2lk6lu48JmkAjrE/FZ+VeGn51fngrYYk6nfj8Ln8nklZjdLWQ8o+ImGD
/CbWFlY3qw1Ml90mjyFyXhUWnz6rhquJvIZo2w3CeCR6/in4qN195aikaLmMAzZm
5ar+9AkUGd2YsSAzeYn+FuGKEVucYZZCYc0wntVYwAMDTL3WPSIx+0m4TO+7pEvi
9ZqnZ0Rn7iaAx6nEc1TQynzGbWBQr13k6h/2xhPhURDYnkULuxjJlWtIo8r+SdEH
N8g66V55B16BkLXPRYg/DikuiF9+d2neszj8ZWvBKTnU2iSVaGCii7MQ5EdjkCdi
0xk52SLKdk2I+Q2fLa+DJh5RW3fnP1NULPuW7350UBgbCUX2QdHsLMK+UnYkkmyV
/Hdqi2gHENg=
=duKX
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce
| VAR-202203-2101 | No CVE | Information disclosure vulnerability exists in TOTOLINK-N302RE |
CVSS V2: 2.1 CVSS V3: - Severity: LOW |
TOTOLINK is a brand owned by Zeon Electronics (Shenzhen) Co., Ltd. The company was established in 1999. It is a high-tech foreign-funded enterprise and one of the global network equipment suppliers.
TOTOLINK-N302RE has an information disclosure vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202203-0928 | CVE-2021-46379 | of D-Link Japan Co., Ltd. dir-850l Open redirect vulnerability in firmware |
CVSS V2: 5.8 CVSS V3: 6.1 Severity: MEDIUM |
DLink DIR850 ET850-1.08TRb03 is affected by an incorrect access control vulnerability through URL redirection to untrusted site. of D-Link Japan Co., Ltd. dir-850l An open redirect vulnerability exists in firmware.Information may be obtained and information may be tampered with. D-Link DIR850 ET850-1.08TRb03 is a router from DLink. No detailed vulnerability details are currently provided
| VAR-202203-1139 | CVE-2021-46393 | Tenda-AX3 Buffer Overflow Vulnerability |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v10 variable is directly retrieved from the http request parameter startIp. Then v10 will be splice to stack by function sscanf without any security check,which causes stack overflow. By POSTing the page /goform/SetPptpServerCfg with proper startIp, the attacker can easily perform remote code execution with carefully crafted overflow data. The Tenda-AX3 is a dual-band wireless router from the Chinese company Tenda. No detailed vulnerability details are currently provided
| VAR-202203-1127 | CVE-2021-32008 | Secomea of gatemanager Past traversal vulnerability in |
CVSS V2: 8.5 CVSS V3: 8.7 Severity: HIGH |
This issue affects: Secomea GateManager Version 9.6.621421014 and all prior versions. Improper Limitation of a Pathname to restricted directory, allows logged in GateManager admin to delete system Files or Directories. Secomea of gatemanager Exists in a past traversal vulnerability.Information is tampered with and service operation is interrupted (DoS) It may be in a state
| VAR-202203-0202 | CVE-2022-25325 | Made by Omron CX-Programmer Multiple vulnerabilities in |
CVSS V2: 6.8 CVSS V3: 7.8 Severity: HIGH |
Use after free vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. This vulnerability is different from CVE-2022-25230. Provided by Omron Corporation CX-Programmer contains multiple vulnerabilities. * Out-of-bounds writing (CWE-787) - CVE-2022-21124 It was * Use of freed memory (Use-after-free) (CWE-416) - CVE-2022-25230 It was * Use of freed memory (Use-after-free) (CWE-416) - CVE-2022-25325 It was * Out-of-bounds read (CWE-125) - CVE-2022-21219 It was * Out-of-bounds writing (CWE-787) - CVE-2022-25234 This vulnerability information is JPCERT/CC Report to JPCERT/CC Coordinated with the developer
| VAR-202203-0201 | CVE-2022-25230 | Made by Omron CX-Programmer Multiple vulnerabilities in |
CVSS V2: 6.8 CVSS V3: 7.8 Severity: HIGH |
Use after free vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. This vulnerability is different from CVE-2022-25325. Provided by Omron Corporation CX-Programmer contains multiple vulnerabilities. * Out-of-bounds writing (CWE-787) - CVE-2022-21124 It was * Use of freed memory (Use-after-free) (CWE-416) - CVE-2022-25230 It was * Use of freed memory (Use-after-free) (CWE-416) - CVE-2022-25325 It was * Out-of-bounds read (CWE-125) - CVE-2022-21219 It was * Out-of-bounds writing (CWE-787) - CVE-2022-25234 This vulnerability information is JPCERT/CC Report to JPCERT/CC Coordinated with the developer
| VAR-202203-0474 | CVE-2021-46380 | WAGO Cross-Site Request Forgery Vulnerability |
CVSS V2: 6.8 CVSS V3: - Severity: MEDIUM |
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: Reason: This is a duplicate to CVE-2022-22511 Notes. WAGO is a 750-88x series programmable logic controller from WAGO. This device is a number-crunching operating electronic system specially designed for application in an industrial environment.
The WAGO 750-8212 PFC200 G2 2ETH RS has a security vulnerability stemming from a Chained Cross-Site Request Forgery (CSRF) with a Reflected Cross-Site Scripting (XSS) vulnerability in the WAGO 750-8212 PFC200 G2 2ETH RS that causes session hijacking. No detailed vulnerability details are currently available
| VAR-202203-2122 | No CVE | KingView (KingView) has a logic flaw vulnerability |
CVSS V2: 3.6 CVSS V3: - Severity: LOW |
KingView (KingView) is the flagship brand in the field of equipment monitoring in China. It has the characteristics of complete functions, simple, easy to learn, and easy to use. Its products are widely used in dozens of industries such as electric power, machinery, municipal administration, energy, environmental protection, and medicine. Hundreds of equipment supporting monitoring such as low-voltage power distribution, hoisting machinery, vacuum furnace, heat exchange station, fan power generation, dust blowing and dust removal, air separation equipment, pharmaceutical freeze dryer and so on.
There is a logic flaw vulnerability in KingView, an attacker can use this vulnerability to overwrite and delete any file.
| VAR-202203-0203 | CVE-2022-21219 | Made by Omron CX-Programmer Multiple vulnerabilities in |
CVSS V2: 6.8 CVSS V3: 7.8 Severity: HIGH |
Out-of-bounds read vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. Provided by Omron Corporation CX-Programmer contains multiple vulnerabilities. * Out-of-bounds writing (CWE-787) - CVE-2022-21124 It was * Use of freed memory (Use-after-free) (CWE-416) - CVE-2022-25230 It was * Use of freed memory (Use-after-free) (CWE-416) - CVE-2022-25325 It was * Out-of-bounds read (CWE-125) - CVE-2022-21219 It was * Out-of-bounds writing (CWE-787) - CVE-2022-25234 This vulnerability information is JPCERT/CC Report to JPCERT/CC Coordinated with the developer
| VAR-202203-0955 | CVE-2022-25106 | of D-Link Japan Co., Ltd. dir-859 firmware and dir-859 a3 Out-of-bounds write vulnerability in firmware |
CVSS V2: 7.1 CVSS V3: 5.5 Severity: MEDIUM |
D-Link DIR-859 v1.05 was discovered to contain a stack-based buffer overflow via the function genacgi_main. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted payload. of D-Link Japan Co., Ltd. dir-859 firmware and dir-859 a3 An out-of-bounds write vulnerability exists in firmware.Service operation interruption (DoS) It may be in a state. D-Link DIR-859 is a wireless router from D-Link Company in Taiwan
| VAR-202203-0205 | CVE-2022-25234 | Made by Omron CX-Programmer Multiple vulnerabilities in |
CVSS V2: 6.8 CVSS V3: 7.8 Severity: HIGH |
Out-of-bounds write vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. This vulnerability is different from CVE-2022-21124. Provided by Omron Corporation CX-Programmer contains multiple vulnerabilities. * Out-of-bounds writing (CWE-787) - CVE-2022-21124 It was * Use of freed memory (Use-after-free) (CWE-416) - CVE-2022-25230 It was * Use of freed memory (Use-after-free) (CWE-416) - CVE-2022-25325 It was * Out-of-bounds read (CWE-125) - CVE-2022-21219 It was * Out-of-bounds writing (CWE-787) - CVE-2022-25234 This vulnerability information is JPCERT/CC Report to JPCERT/CC Coordinated with the developer
| VAR-202203-0475 | CVE-2021-46381 | D-Link DAP-1620 Path Traversal Vulnerability |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
Local File Inclusion due to path traversal in D-Link DAP-1620 leads to unauthorized internal files reading [/etc/passwd] and [/etc/shadow]. of D-Link Japan Co., Ltd. dap-1620 A path traversal vulnerability exists in firmware.Information may be obtained. D-Link DAP-1620 is a wireless repeater extender from D-Link, Taiwan. No detailed vulnerability details are currently available
| VAR-202203-0476 | CVE-2021-46382 | NETGEAR WAC120 Cross-Site Scripting Vulnerability |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
Unauthenticated cross-site scripting (XSS) in Netgear WAC120 AC Access Point may lead to mulitple attacks like session hijacking even clipboard hijacking. of netgear wac120 ac Firmware has a cross-site scripting vulnerability.Information may be obtained and information may be tampered with. Netgear NETGEAR WAC120 is a wireless access point (AP) from Netgear. No detailed vulnerability details are currently provided
| VAR-202203-0478 | CVE-2021-46394 | Tenda-AX3 Buffer Overflow Vulnerability (CNVD-2022-20157) |
CVSS V2: 7.5 CVSS V3: 9.8 Severity: CRITICAL |
There is a stack buffer overflow vulnerability in the formSetPPTPServer function of Tenda-AX3 router V16.03.12.10_CN. The v13 variable is directly retrieved from the http request parameter startIp. Then v13 will be splice to stack by function sscanf without any security check, which causes stack overflow. By POSTing the page /goform/SetPptpServerCfg with proper startIp, the attacker can easily perform remote code execution with carefully crafted overflow data. The Tenda-AX3 is a dual-band wireless router from the Chinese company Tenda. No detailed vulnerability details are currently available
| VAR-202203-0926 | CVE-2021-44827 | Tp-link Archer C2 Operating System Command Injection Vulnerability |
CVSS V2: 9.0 CVSS V3: 8.8 Severity: HIGH |
There is remote authenticated OS command injection on TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n devices vie the X_TP_ExternalIPv6Address HTTP parameter, allowing a remote attacker to run arbitrary commands on the router with root privileges. TP-LINK Technologies of archer c20i The firmware has OS A command injection vulnerability exists.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. Tp-link Archer C2 is a wireless router from Tp-link company in China.
There is a security vulnerability in TP-Link Archer C20i 0.9.1 3.2 v003a.0 Build 170221 Rel.55462n. The vulnerability stems from the lack of filtering and escaping of user data in the HTTP parameter X_TP_ExternalIPv6Address in the device. Run arbitrary commands on the router with root privileges