{"schema_version":"1.7.3","id":"SUSE-SU-2022:3274-1","published":"2022-09-14T07:59:26Z","modified":"2026-02-04T03:37:31.430703Z","related":["CVE-2020-36516","CVE-2020-36557","CVE-2020-36558","CVE-2021-4203","CVE-2022-20166","CVE-2022-20368","CVE-2022-20369","CVE-2022-21385","CVE-2022-2588","CVE-2022-26373","CVE-2022-2639","CVE-2022-2977","CVE-2022-3028","CVE-2022-36879","CVE-2022-36946"],"upstream":["CVE-2020-36516","CVE-2020-36557","CVE-2020-36558","CVE-2021-4203","CVE-2022-20166","CVE-2022-20368","CVE-2022-20369","CVE-2022-21385","CVE-2022-2588","CVE-2022-26373","CVE-2022-2639","CVE-2022-2977","CVE-2022-3028","CVE-2022-36879","CVE-2022-36946"],"summary":"Security update for the Linux Kernel","details":"\nThe SUSE Linux Enterprise 12 SP4 LTSS kernel was updated to receive various security and bugfixes.\n\n\nThe following security bugs were fixed:\n\n- CVE-2022-36946: Fixed a denial of service (panic) inside nfqnl_mangle in net/netfilter/nfnetlink_queue.c (bnc#1201940).\n- CVE-2022-36879: Fixed an issue in xfrm_expand_policies in net/xfrm/xfrm_policy.c where a refcount could be dropped twice (bnc#1201948).\n- CVE-2022-3028: Fixed race condition that was found in the IP framework for transforming packets (XFRM subsystem) (bnc#1202898).\n- CVE-2022-2977: Fixed reference counting for struct tpm_chip (bsc#1202672).\n- CVE-2022-2639: Fixed an integer coercion error that was found in the openvswitch kernel module (bnc#1202154).\n- CVE-2022-26373: Fixed non-transparent sharing of return predictor targets between contexts in some Intel Processors (bnc#1201726).\n- CVE-2022-2588: Fixed use-after-free in cls_route (bsc#1202096).\n- CVE-2022-21385: Fixed a flaw in net_rds_alloc_sgs() that allowed unprivileged local users to crash the machine (bnc#1202897).\n- CVE-2022-20369: Fixed out of bounds write in v4l2_m2m_querybuf of v4l2-mem2mem.c (bnc#1202347).\n- CVE-2022-20368: Fixed slab-out-of-bounds access in packet_recvmsg() (bsc#1202346).\n- CVE-2022-20166: Fixed possible out of bounds write due to a heap buffer overflow in various methods of kernel base drivers (bnc#1200598).\n- CVE-2021-4203: Fixed use-after-free read flaw that was found in sock_getsockopt() in net/core/sock.c due to SO_PEERCRED and SO_PEERGROUPS race with listen() (bnc#1194535).\n- CVE-2020-36558: Fixed a race condition involving VT_RESIZEX could lead to a NULL pointer dereference and general protection fault (bnc#1200910).\n- CVE-2020-36557: Fixed a race condition between the VT_DISALLOCATE ioctl and closing/opening of ttys that could have led to a use-after-free (bnc#1201429).\n- CVE-2020-36516: Fixed an issue in the mixed IPID assignment method where an attacker was able to inject data into or terminate a victim's TCP session (bnc#1196616).\n\nThe following non-security bugs were fixed:\n\n- cifs: fix error paths in cifs_tree_connect() (bsc#1177440).\n- cifs: fix uninitialized pointer in error case in dfs_cache_get_tgt_share (bsc#1188944).\n- cifs: report error instead of invalid when revalidating a dentry fails (bsc#1177440).\n- cifs: skip trailing separators of prefix paths (bsc#1188944).\n- kernel-obs-build: include qemu_fw_cfg (boo#1201705)\n- lightnvm: Remove lightnvm implemenation (bsc#1191881 bsc#1201420 ZDI-CAN-17325).\n- mm/rmap.c: do not reuse anon_vma if we just want a copy (git-fixes, bsc#1203098).\n- mm/rmap: Fix anon_vma->degree ambiguity leading to double-reuse (git-fixes, bsc#1203098).\n- net_sched: cls_route: disallow handle of 0 (bsc#1202393).\n- objtool: Add --backtrace support (bsc#1202396).\n- objtool: Add support for intra-function calls (bsc#1202396).\n- objtool: Allow no-op CFI ops in alternatives (bsc#1202396).\n- objtool: Convert insn type to enum (bsc#1202396).\n- objtool: Do not use ignore flag for fake jumps (bsc#1202396).\n- objtool: Fix !CFI insn_state propagation (bsc#1202396).\n- objtool: Fix ORC vs alternatives (bsc#1202396).\n- objtool: Fix sibling call detection (bsc#1202396).\n- objtool: Make handle_insn_ops() unconditional (bsc#1202396).\n- objtool: Remove INSN_STACK (bsc#1202396).\n- objtool: Remove check preventing branches within alternative (bsc#1202396).\n- objtool: Rename elf_open() to prevent conflict with libelf from elftoolchain (bsc#1202396).\n- objtool: Rename struct cfi_state (bsc#1202396).\n- objtool: Rework allocating stack_ops on decode (bsc#1202396).\n- objtool: Rewrite alt->skip_orig (bsc#1202396).\n- objtool: Set insn->func for alternatives (bsc#1202396).\n- objtool: Support conditional retpolines (bsc#1202396).\n- objtool: Support multiple stack_op per instruction (bsc#1202396).\n- objtool: Track original function across branches (bsc#1202396).\n- objtool: Uniquely identify alternative instruction groups (bsc#1202396).\n- objtool: Use Elf_Scn typedef instead of assuming struct name (bsc#1202396).\n- powerpc/pci: Fix broken INTx configuration via OF (bsc#1172145 ltc#184630 bsc#1200770 ltc#198666).\n- powerpc/pci: Remove LSI mappings on device teardown (bsc#1172145 ltc#184630 bsc#1200770 ltc#198666).\n- powerpc/pci: Use of_irq_parse_and_map_pci() helper (bsc#1172145 ltc#184630 bsc#1200770 ltc#198666).\n- rpm: Fix parsing of rpm/macros.kernel-source on SLE12 (bsc#1201019).\n","affected":[{"package":{"name":"kernel-default","ecosystem":"SUSE:OpenStack Cloud 9","purl":"pkg:rpm/suse/kernel-default&distro=SUSE%20OpenStack%20Cloud%209"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.108.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.108.1","kernel-default-base":"4.12.14-95.108.1","kernel-default-devel":"4.12.14-95.108.1","kernel-devel":"4.12.14-95.108.1","kernel-macros":"4.12.14-95.108.1","kernel-source":"4.12.14-95.108.1","kernel-syms":"4.12.14-95.108.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3274-1.json"}},{"package":{"name":"kernel-source","ecosystem":"SUSE:OpenStack Cloud 9","purl":"pkg:rpm/suse/kernel-source&distro=SUSE%20OpenStack%20Cloud%209"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.108.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.108.1","kernel-default-base":"4.12.14-95.108.1","kernel-default-devel":"4.12.14-95.108.1","kernel-devel":"4.12.14-95.108.1","kernel-macros":"4.12.14-95.108.1","kernel-source":"4.12.14-95.108.1","kernel-syms":"4.12.14-95.108.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3274-1.json"}},{"package":{"name":"kernel-syms","ecosystem":"SUSE:OpenStack Cloud 9","purl":"pkg:rpm/suse/kernel-syms&distro=SUSE%20OpenStack%20Cloud%209"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.108.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.108.1","kernel-default-base":"4.12.14-95.108.1","kernel-default-devel":"4.12.14-95.108.1","kernel-devel":"4.12.14-95.108.1","kernel-macros":"4.12.14-95.108.1","kernel-source":"4.12.14-95.108.1","kernel-syms":"4.12.14-95.108.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3274-1.json"}},{"package":{"name":"kernel-default","ecosystem":"SUSE:OpenStack Cloud Crowbar 9","purl":"pkg:rpm/suse/kernel-default&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.108.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.108.1","kernel-default-base":"4.12.14-95.108.1","kernel-default-devel":"4.12.14-95.108.1","kernel-devel":"4.12.14-95.108.1","kernel-macros":"4.12.14-95.108.1","kernel-source":"4.12.14-95.108.1","kernel-syms":"4.12.14-95.108.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3274-1.json"}},{"package":{"name":"kernel-source","ecosystem":"SUSE:OpenStack Cloud Crowbar 9","purl":"pkg:rpm/suse/kernel-source&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.108.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.108.1","kernel-default-base":"4.12.14-95.108.1","kernel-default-devel":"4.12.14-95.108.1","kernel-devel":"4.12.14-95.108.1","kernel-macros":"4.12.14-95.108.1","kernel-source":"4.12.14-95.108.1","kernel-syms":"4.12.14-95.108.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3274-1.json"}},{"package":{"name":"kernel-syms","ecosystem":"SUSE:OpenStack Cloud Crowbar 9","purl":"pkg:rpm/suse/kernel-syms&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.108.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.108.1","kernel-default-base":"4.12.14-95.108.1","kernel-default-devel":"4.12.14-95.108.1","kernel-devel":"4.12.14-95.108.1","kernel-macros":"4.12.14-95.108.1","kernel-source":"4.12.14-95.108.1","kernel-syms":"4.12.14-95.108.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3274-1.json"}},{"package":{"name":"kernel-default","ecosystem":"SUSE:Linux Enterprise High Availability Extension 12 SP4","purl":"pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.108.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-default":"4.12.14-95.108.1","dlm-kmp-default":"4.12.14-95.108.1","gfs2-kmp-default":"4.12.14-95.108.1","ocfs2-kmp-default":"4.12.14-95.108.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3274-1.json"}},{"package":{"name":"kernel-default","ecosystem":"SUSE:Linux Enterprise Live Patching 12 SP4","purl":"pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.108.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default-kgraft":"4.12.14-95.108.1","kernel-default-kgraft-devel":"4.12.14-95.108.1","kgraft-patch-4_12_14-95_108-default":"1-6.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3274-1.json"}},{"package":{"name":"kgraft-patch-SLE12-SP4_Update_30","ecosystem":"SUSE:Linux Enterprise Live Patching 12 SP4","purl":"pkg:rpm/suse/kgraft-patch-SLE12-SP4_Update_30&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1-6.3.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default-kgraft":"4.12.14-95.108.1","kernel-default-kgraft-devel":"4.12.14-95.108.1","kgraft-patch-4_12_14-95_108-default":"1-6.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3274-1.json"}},{"package":{"name":"kernel-default","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP4","purl":"pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.108.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.108.1","kernel-default-base":"4.12.14-95.108.1","kernel-default-devel":"4.12.14-95.108.1","kernel-devel":"4.12.14-95.108.1","kernel-macros":"4.12.14-95.108.1","kernel-source":"4.12.14-95.108.1","kernel-syms":"4.12.14-95.108.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3274-1.json"}},{"package":{"name":"kernel-source","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP4","purl":"pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.108.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.108.1","kernel-default-base":"4.12.14-95.108.1","kernel-default-devel":"4.12.14-95.108.1","kernel-devel":"4.12.14-95.108.1","kernel-macros":"4.12.14-95.108.1","kernel-source":"4.12.14-95.108.1","kernel-syms":"4.12.14-95.108.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3274-1.json"}},{"package":{"name":"kernel-syms","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP4","purl":"pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.108.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.108.1","kernel-default-base":"4.12.14-95.108.1","kernel-default-devel":"4.12.14-95.108.1","kernel-devel":"4.12.14-95.108.1","kernel-macros":"4.12.14-95.108.1","kernel-source":"4.12.14-95.108.1","kernel-syms":"4.12.14-95.108.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3274-1.json"}},{"package":{"name":"kernel-default","ecosystem":"SUSE:Linux Enterprise Server 12 SP4-LTSS","purl":"pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.108.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.108.1","kernel-default-base":"4.12.14-95.108.1","kernel-default-devel":"4.12.14-95.108.1","kernel-default-man":"4.12.14-95.108.1","kernel-devel":"4.12.14-95.108.1","kernel-macros":"4.12.14-95.108.1","kernel-source":"4.12.14-95.108.1","kernel-syms":"4.12.14-95.108.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3274-1.json"}},{"package":{"name":"kernel-source","ecosystem":"SUSE:Linux Enterprise Server 12 SP4-LTSS","purl":"pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.108.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.108.1","kernel-default-base":"4.12.14-95.108.1","kernel-default-devel":"4.12.14-95.108.1","kernel-default-man":"4.12.14-95.108.1","kernel-devel":"4.12.14-95.108.1","kernel-macros":"4.12.14-95.108.1","kernel-source":"4.12.14-95.108.1","kernel-syms":"4.12.14-95.108.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3274-1.json"}},{"package":{"name":"kernel-syms","ecosystem":"SUSE:Linux Enterprise Server 12 SP4-LTSS","purl":"pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.108.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.108.1","kernel-default-base":"4.12.14-95.108.1","kernel-default-devel":"4.12.14-95.108.1","kernel-default-man":"4.12.14-95.108.1","kernel-devel":"4.12.14-95.108.1","kernel-macros":"4.12.14-95.108.1","kernel-source":"4.12.14-95.108.1","kernel-syms":"4.12.14-95.108.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2022:3274-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20223274-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1172145"},{"type":"REPORT","url":"https://bugzilla.suse.com/1177440"},{"type":"REPORT","url":"https://bugzilla.suse.com/1188944"},{"type":"REPORT","url":"https://bugzilla.suse.com/1191881"},{"type":"REPORT","url":"https://bugzilla.suse.com/1194535"},{"type":"REPORT","url":"https://bugzilla.suse.com/1196616"},{"type":"REPORT","url":"https://bugzilla.suse.com/1200598"},{"type":"REPORT","url":"https://bugzilla.suse.com/1200770"},{"type":"REPORT","url":"https://bugzilla.suse.com/1200910"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201019"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201420"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201429"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201705"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201726"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201940"},{"type":"REPORT","url":"https://bugzilla.suse.com/1201948"},{"type":"REPORT","url":"https://bugzilla.suse.com/1202096"},{"type":"REPORT","url":"https://bugzilla.suse.com/1202154"},{"type":"REPORT","url":"https://bugzilla.suse.com/1202346"},{"type":"REPORT","url":"https://bugzilla.suse.com/1202347"},{"type":"REPORT","url":"https://bugzilla.suse.com/1202393"},{"type":"REPORT","url":"https://bugzilla.suse.com/1202396"},{"type":"REPORT","url":"https://bugzilla.suse.com/1202672"},{"type":"REPORT","url":"https://bugzilla.suse.com/1202897"},{"type":"REPORT","url":"https://bugzilla.suse.com/1202898"},{"type":"REPORT","url":"https://bugzilla.suse.com/1203098"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-36516"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-36557"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-36558"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2021-4203"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-20166"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-20368"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-20369"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-21385"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-2588"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-26373"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-2639"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-2977"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-3028"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-36879"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-36946"}]}