{"schema_version":"1.7.3","id":"SUSE-SU-2022:0289-1","published":"2022-02-02T09:02:15Z","modified":"2026-02-04T04:27:01.045634Z","related":["CVE-2021-4083","CVE-2021-4135","CVE-2021-4149","CVE-2021-4197","CVE-2021-4202","CVE-2021-44733","CVE-2021-45485","CVE-2021-45486","CVE-2022-0185","CVE-2022-0322"],"upstream":["CVE-2021-4083","CVE-2021-4135","CVE-2021-4149","CVE-2021-4197","CVE-2021-4202","CVE-2021-44733","CVE-2021-45485","CVE-2021-45486","CVE-2022-0185","CVE-2022-0322"],"summary":"Security update for the Linux Kernel","details":"The SUSE Linux Enterprise 15 SP2 RT kernel was updated to receive various security and bugfixes.\n\nThe following security bugs were fixed:\n\n- CVE-2021-4083: Fixed race condition in Unix domain socket garbage collection that could lead to read memory after free (bsc#1193727).\n- CVE-2021-4135: Fixed an information leak in the nsim_bpf_map_alloc function (bsc#1193927).\n- CVE-2021-4149: Fixed improper lock operation in btrfs that allowed users to crash the kernel or deadlock the system (bsc#1194001).\n- CVE-2021-4197: Fixed a cgroup issue where lower privileged processes could write to fds of lower privileged ones that could lead to privilege escalation (bsc#1194302).\n- CVE-2021-4202: Fixed race condition in nci_request() that could cause use-after-free (bsc#1194529).\n- CVE-2021-44733: Fixed a use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel that occured because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object (bnc#1193767).\n- CVE-2021-45485: Fixed an information leak because of certain use of a hash table which use IPv6 source addresses (bsc#1194094).\n- CVE-2021-45486: Fixed an information leak because the hash table is very small in net/ipv4/route.c (bnc#1194087).\n- CVE-2022-0185: Incorrect param length parsing in legacy_parse_param which could have led to a local privilege escalation (bsc#1194517).\n- CVE-2022-0322: Fixed a denial of service in SCTP sctp_addto_chunk (bsc#1194985).\n\nThe following non-security bugs were fixed:\n\n- ext4: Avoid trim error on fs with small groups (bsc#1191271).\n- fget: clarify and improve __fget_files() implementation (bsc#1193727).\n- kabi/severities: Add a kabi exception for drivers/tee/tee\n- kprobes: Limit max data_size of the kretprobe instances (bsc#1193669).\n- livepatch: Avoid CPU hogging with cond_resched (bsc#1071995).\n- media: Revert 'media: uvcvideo: Set unique vdev name based in type' (bsc#1193255).\n- moxart: fix potential use-after-free on remove path (bsc#1194516).\n- powerpc/fadump: Fix inaccurate CPU state info in vmcore generated with panic (bsc#1193901).\n- powerpc: handle kdump appropriately with crash_kexec_post_notifiers option (bsc#1193901).\n- tpm: fix potential NULL pointer access in tpm_del_char_device (bsc#1184209, bsc#1193660).\n- vfs: check fd has read access in kernel_read_file_from_fd() (bsc#1194888).\n","affected":[{"package":{"name":"kernel-rt","ecosystem":"SUSE:Real Time Module 15 SP2","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-68.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"5.3.18-68.1","dlm-kmp-rt":"5.3.18-68.1","gfs2-kmp-rt":"5.3.18-68.1","kernel-devel-rt":"5.3.18-68.1","kernel-rt":"5.3.18-68.1","kernel-rt-devel":"5.3.18-68.1","kernel-rt_debug":"5.3.18-68.1","kernel-rt_debug-devel":"5.3.18-68.1","kernel-source-rt":"5.3.18-68.1","kernel-syms-rt":"5.3.18-68.1","ocfs2-kmp-rt":"5.3.18-68.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:0289-1.json"}},{"package":{"name":"kernel-rt_debug","ecosystem":"SUSE:Real Time Module 15 SP2","purl":"pkg:rpm/suse/kernel-rt_debug&distro=SUSE%20Real%20Time%20Module%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-68.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"5.3.18-68.1","dlm-kmp-rt":"5.3.18-68.1","gfs2-kmp-rt":"5.3.18-68.1","kernel-devel-rt":"5.3.18-68.1","kernel-rt":"5.3.18-68.1","kernel-rt-devel":"5.3.18-68.1","kernel-rt_debug":"5.3.18-68.1","kernel-rt_debug-devel":"5.3.18-68.1","kernel-source-rt":"5.3.18-68.1","kernel-syms-rt":"5.3.18-68.1","ocfs2-kmp-rt":"5.3.18-68.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:0289-1.json"}},{"package":{"name":"kernel-source-rt","ecosystem":"SUSE:Real Time Module 15 SP2","purl":"pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-68.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"5.3.18-68.1","dlm-kmp-rt":"5.3.18-68.1","gfs2-kmp-rt":"5.3.18-68.1","kernel-devel-rt":"5.3.18-68.1","kernel-rt":"5.3.18-68.1","kernel-rt-devel":"5.3.18-68.1","kernel-rt_debug":"5.3.18-68.1","kernel-rt_debug-devel":"5.3.18-68.1","kernel-source-rt":"5.3.18-68.1","kernel-syms-rt":"5.3.18-68.1","ocfs2-kmp-rt":"5.3.18-68.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:0289-1.json"}},{"package":{"name":"kernel-syms-rt","ecosystem":"SUSE:Real Time Module 15 SP2","purl":"pkg:rpm/suse/kernel-syms-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-68.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"5.3.18-68.1","dlm-kmp-rt":"5.3.18-68.1","gfs2-kmp-rt":"5.3.18-68.1","kernel-devel-rt":"5.3.18-68.1","kernel-rt":"5.3.18-68.1","kernel-rt-devel":"5.3.18-68.1","kernel-rt_debug":"5.3.18-68.1","kernel-rt_debug-devel":"5.3.18-68.1","kernel-source-rt":"5.3.18-68.1","kernel-syms-rt":"5.3.18-68.1","ocfs2-kmp-rt":"5.3.18-68.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:0289-1.json"}},{"package":{"name":"kernel-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.0","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-68.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.3.18-68.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:0289-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20220289-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1071995"},{"type":"REPORT","url":"https://bugzilla.suse.com/1184209"},{"type":"REPORT","url":"https://bugzilla.suse.com/1191271"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193255"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193660"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193669"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193727"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193767"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193901"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193927"},{"type":"REPORT","url":"https://bugzilla.suse.com/1194001"},{"type":"REPORT","url":"https://bugzilla.suse.com/1194087"},{"type":"REPORT","url":"https://bugzilla.suse.com/1194094"},{"type":"REPORT","url":"https://bugzilla.suse.com/1194302"},{"type":"REPORT","url":"https://bugzilla.suse.com/1194516"},{"type":"REPORT","url":"https://bugzilla.suse.com/1194517"},{"type":"REPORT","url":"https://bugzilla.suse.com/1194529"},{"type":"REPORT","url":"https://bugzilla.suse.com/1194888"},{"type":"REPORT","url":"https://bugzilla.suse.com/1194985"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-4083"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-4135"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-4149"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-4197"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-4202"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-44733"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-45485"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-45486"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-0185"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-0322"}]}