CVE-2022-25636 - privilege escalation through netfilter bug

Mathias Homann <[email protected]> Wed, 16 Mar 2022 07:05:04 +0100
Newsgroups gmane.linux.suse.security
Message-ID <7468548.biPmuPOh8k@kumiko>
--nextPart2115490.JSPIrGfTWz
Content-Transfer-Encoding: 7Bit
Content-Type: text/plain; charset="UTF-8"; protected-headers="v1"
From: Mathias Homann <[email protected]>
To: [email protected]
Subject: CVE-2022-25636 - privilege escalation through netfilter bug
Date: Wed, 16 Mar 2022 07:05:04 +0100
Message-ID: <7468548.biPmuPOh8k@kumiko>

Hi,

just came across CVE-2022-25636 in this article: https://www.zdnet.com/
article/nasty-linux-netfilter-firewall-security-hole-found/

Is there an update for Leap 15.3 and SLES in the works?

Tumbleweed should be ok since the bug is "only" in kernels up to 5.6.10 and TW 
currently runs on 5.16.14.

Cheers
MH

-- 
Mathias Homann
[email protected]
Jabber (XMPP): [email protected]
Matrix: @mathias:eregion.de
IRC: [Lemmy] on freenode and ircnet (bouncer active)
keybase: https://keybase.io/lemmy
gpg key fingerprint: 8029 2240 F4DD 7776 E7D2 C042 6B8E 029E 13F2 C102
--nextPart2115490.JSPIrGfTWz
Content-Type: application/pgp-signature; name="signature.asc"
Content-Description: This is a digitally signed message part.
Content-Transfer-Encoding: 7Bit

-----BEGIN PGP SIGNATURE-----

iQGzBAABCgAdFiEEgCkiQPTdd3bn0sBCa44CnhPywQIFAmIxfhAACgkQa44CnhPy
wQL/ZwwA4ZCfPfzCpZxmFprSWPDo/oarx8bs99RcM89AkiBFNjVQ+5sDNXvqvb82
1h9Vjru51lrKRBlzZPk950W+TgJq37qF8pGlyJPFAUFM3QuH34q3xNqkmIMEctSB
z6By1RgkAfKNlMF6ibxdTa+0qDUo1GqFegmHA1a10GbhdQBBrCmzpvd8PGz/h4VT
esEaC72U2gLg4dXyGhQsi5NiYw3K2fnC0kiYgoAT0/un81JFwLsxk2EAeGc3s7sM
BLYWCYqfwZ06/14agy1uGqW+2xqBed2olNo9y6Dpi8NJ+HC0TuFDFFpB2XG45WmS
UNh47E9lqgBbIMWGrfBePxBadzzoCd4e889FUESvBmvdOfMBJYpYbr6F8rwoGX5g
pJxqLKKiNpOLhlfRy/HTW/Lm7/rkSjpn+N338T+fQMahCqSPzdxwRNavYr92Pe4H
zv0xWi2aDGFJHxxkFvF7GpfHof2UUT4xh7A4AdS1IOUaBf4pvveTzU3P/XOF9uBF
n5rUZSaN
=rPDr
-----END PGP SIGNATURE-----

--nextPart2115490.JSPIrGfTWz--