{"schema_version":"1.7.3","id":"SUSE-SU-2022:0544-1","published":"2022-02-21T12:51:44Z","modified":"2026-02-04T02:54:23.883340Z","related":["CVE-2021-22600","CVE-2021-39648","CVE-2021-39657","CVE-2021-45095","CVE-2022-0330","CVE-2022-22942"],"upstream":["CVE-2021-22600","CVE-2021-39648","CVE-2021-39657","CVE-2021-45095","CVE-2022-0330","CVE-2022-22942"],"summary":"Security update for the Linux RT Kernel","details":"\nThe SUSE Linux Enterprise 15 SP2 RT kernel was updated to receive various security and bugfixes.\n\n\nThe following security bugs were fixed:\n\n- CVE-2022-0435: Fixed remote stack overflow in net/tipc module that validate domain record count on input (bsc#1195254).\n- CVE-2021-45095: Fixed refcount leak in pep_sock_accept in net/phonet/pep.c (bnc#1193867).\n- CVE-2022-22942: Fixed stale file descriptors on failed usercopy (bsc#1195065).\n- CVE-2021-22600: Fixed double free bug in packet_set_ring() in net/packet/af_packet.c that could have been exploited by a local user through crafted syscalls to escalate privileges or deny service (bnc#1195184).\n- CVE-2021-39657: Fixed out of bounds read due to a missing bounds check in ufshcd_eh_device_reset_handler of ufshcd.c. This could lead to local information disclosure with System execution privileges needed (bnc#1193864).\n- CVE-2021-39648: Fixed possible disclosure of kernel heap memory due to a race condition in gadget_dev_desc_UDC_show of configfs.c. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation (bnc#1193861).\n- CVE-2022-0330: Fixed flush TLBs before releasing backing store (bsc#1194880).\n\n\nThe following non-security bugs were fixed:\n\n- bpf: Verifer, adjust_scalar_min_max_vals to always call update_reg_bounds() (bsc#1194227).\n- btrfs: tree-checker: Add EXTENT_ITEM and METADATA_ITEM check (bsc#1195009).\n- btrfs: tree-checker: annotate all error branches as unlikely (bsc#1195009).\n- btrfs: tree-checker: check for BTRFS_BLOCK_FLAG_FULL_BACKREF being set improperly (bsc#1195009).\n- hv_netvsc: Set needed_headroom according to VF (bsc#1193506).\n- net, xdp: Introduce xdp_init_buff utility routine (bsc#1193506).\n- net, xdp: Introduce xdp_prepare_buff utility routine (bsc#1193506).\n- net: allow retransmitting a TCP packet if original is still in queue (bsc#1188605 bsc#1187428).\n- net: mana: Add RX fencing (bsc#1193506).\n- net: mana: Add XDP support (bsc#1193506).\n- net: sch_generic: aviod concurrent reset and enqueue op for lockless qdisc (bsc#1183405).\n- net: sched: add barrier to ensure correct ordering for lockless qdisc (bsc#1183405).\n- net: sched: avoid unnecessary seqcount operation for lockless qdisc (bsc#1183405).\n- net: sched: fix packet stuck problem for lockless qdisc (bsc#1183405).\n- net: sched: fix tx action reschedule issue with stopped queue (bsc#1183405).\n- net: sched: fix tx action rescheduling issue during deactivation (bsc#1183405).\n- net: sched: replaced invalid qdisc tree flush helper in qdisc_replace (bsc#1183405).\n- net_sched: avoid resetting active qdisc for multiple times (bsc#1183405).\n- net_sched: get rid of unnecessary dev_qdisc_reset() (bsc#1183405).\n- net_sched: use qdisc_reset() in qdisc_destroy() (bsc#1183405).\n- nvme: add 'iopolicy' module parameter (bsc#1177599 bsc#1193096).\n- xfrm: fix MTU regression (bsc#1185377, bsc#1194048).\n","affected":[{"package":{"name":"kernel-rt","ecosystem":"SUSE:Real Time Module 15 SP2","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-73.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"5.3.18-73.1","dlm-kmp-rt":"5.3.18-73.1","gfs2-kmp-rt":"5.3.18-73.1","kernel-devel-rt":"5.3.18-73.1","kernel-rt":"5.3.18-73.1","kernel-rt-devel":"5.3.18-73.1","kernel-rt_debug":"5.3.18-73.1","kernel-rt_debug-devel":"5.3.18-73.1","kernel-source-rt":"5.3.18-73.1","kernel-syms-rt":"5.3.18-73.1","ocfs2-kmp-rt":"5.3.18-73.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:0544-1.json"}},{"package":{"name":"kernel-rt_debug","ecosystem":"SUSE:Real Time Module 15 SP2","purl":"pkg:rpm/suse/kernel-rt_debug&distro=SUSE%20Real%20Time%20Module%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-73.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"5.3.18-73.1","dlm-kmp-rt":"5.3.18-73.1","gfs2-kmp-rt":"5.3.18-73.1","kernel-devel-rt":"5.3.18-73.1","kernel-rt":"5.3.18-73.1","kernel-rt-devel":"5.3.18-73.1","kernel-rt_debug":"5.3.18-73.1","kernel-rt_debug-devel":"5.3.18-73.1","kernel-source-rt":"5.3.18-73.1","kernel-syms-rt":"5.3.18-73.1","ocfs2-kmp-rt":"5.3.18-73.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:0544-1.json"}},{"package":{"name":"kernel-source-rt","ecosystem":"SUSE:Real Time Module 15 SP2","purl":"pkg:rpm/suse/kernel-source-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-73.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"5.3.18-73.1","dlm-kmp-rt":"5.3.18-73.1","gfs2-kmp-rt":"5.3.18-73.1","kernel-devel-rt":"5.3.18-73.1","kernel-rt":"5.3.18-73.1","kernel-rt-devel":"5.3.18-73.1","kernel-rt_debug":"5.3.18-73.1","kernel-rt_debug-devel":"5.3.18-73.1","kernel-source-rt":"5.3.18-73.1","kernel-syms-rt":"5.3.18-73.1","ocfs2-kmp-rt":"5.3.18-73.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:0544-1.json"}},{"package":{"name":"kernel-syms-rt","ecosystem":"SUSE:Real Time Module 15 SP2","purl":"pkg:rpm/suse/kernel-syms-rt&distro=SUSE%20Real%20Time%20Module%2015%20SP2"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-73.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-rt":"5.3.18-73.1","dlm-kmp-rt":"5.3.18-73.1","gfs2-kmp-rt":"5.3.18-73.1","kernel-devel-rt":"5.3.18-73.1","kernel-rt":"5.3.18-73.1","kernel-rt-devel":"5.3.18-73.1","kernel-rt_debug":"5.3.18-73.1","kernel-rt_debug-devel":"5.3.18-73.1","kernel-source-rt":"5.3.18-73.1","kernel-syms-rt":"5.3.18-73.1","ocfs2-kmp-rt":"5.3.18-73.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:0544-1.json"}},{"package":{"name":"kernel-rt","ecosystem":"SUSE:Linux Enterprise Micro 5.0","purl":"pkg:rpm/suse/kernel-rt&distro=SUSE%20Linux%20Enterprise%20Micro%205.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"5.3.18-73.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-rt":"5.3.18-73.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:0544-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20220544-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177599"},{"type":"REPORT","url":"https://bugzilla.suse.com/1183405"},{"type":"REPORT","url":"https://bugzilla.suse.com/1185377"},{"type":"REPORT","url":"https://bugzilla.suse.com/1187428"},{"type":"REPORT","url":"https://bugzilla.suse.com/1188605"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193096"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193506"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193861"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193864"},{"type":"REPORT","url":"https://bugzilla.suse.com/1193867"},{"type":"REPORT","url":"https://bugzilla.suse.com/1194048"},{"type":"REPORT","url":"https://bugzilla.suse.com/1194227"},{"type":"REPORT","url":"https://bugzilla.suse.com/1194880"},{"type":"REPORT","url":"https://bugzilla.suse.com/1195009"},{"type":"REPORT","url":"https://bugzilla.suse.com/1195065"},{"type":"REPORT","url":"https://bugzilla.suse.com/1195184"},{"type":"REPORT","url":"https://bugzilla.suse.com/1195254"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-22600"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-39648"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-39657"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-45095"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-0330"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-22942"}]}