Re: CVE-2022-25636 - privilege escalation through netfilter bug
Mathias Homann <[email protected]> Wed, 16 Mar 2022 07:17:50 +0100
| Newsgroups | gmane.linux.suse.security |
|---|---|
| Message-ID | <2050556.n7jcWBlgn4@kumiko> |
--nextPart10375279.cNCT3uQDyu Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="UTF-8"; protected-headers="v1" From: Mathias Homann <[email protected]> To: [email protected] Date: Wed, 16 Mar 2022 07:17:50 +0100 Message-ID: <2050556.n7jcWBlgn4@kumiko> In-Reply-To: <7468548.biPmuPOh8k@kumiko> References: <7468548.biPmuPOh8k@kumiko> Am Mittwoch, 16. M=C3=A4rz 2022, 07:05:04 CET schrieb Mathias Homann: > Hi, >=20 > just came across CVE-2022-25636 in this article: https://www.zdnet.com/ > article/nasty-linux-netfilter-firewall-security-hole-found/ >=20 > Is there an update for Leap 15.3 and SLES in the works? >=20 > Tumbleweed should be ok since the bug is "only" in kernels up to 5.6.10 a= nd > TW currently runs on 5.16.14. on second thought, Leap and SLES should be fine too: Kernels affected are 5= =2E4=20 to 5.10 - Leap and SLES use 5.3.x, TW uses 5.16. I hate ZD Net sensationalism. But please someone verify that we're safe abo= ut=20 this one, I hate local privilege elevation holes more. Cheers MH =2D-=20 Mathias Homann [email protected] Jabber (XMPP): [email protected] Matrix: @mathias:eregion.de IRC: [Lemmy] on freenode and ircnet (bouncer active) keybase: https://keybase.io/lemmy gpg key fingerprint: 8029 2240 F4DD 7776 E7D2 C042 6B8E 029E 13F2 C102 --nextPart10375279.cNCT3uQDyu Content-Type: application/pgp-signature; name="signature.asc" Content-Description: This is a digitally signed message part. Content-Transfer-Encoding: 7Bit -----BEGIN PGP SIGNATURE----- iQGzBAABCgAdFiEEgCkiQPTdd3bn0sBCa44CnhPywQIFAmIxgQ4ACgkQa44CnhPy wQL9UgwAlfsnc+zyBPJrU2lSPeYVGMOgUX0bZQcYVT4xbHPBK9+zpbA2bEDhfIwW 3JOsq0jhjsp5k4ORe6D6zzNJhTLRd6HR6nfyUftQpRp+GsyVTvrT1Imd8JTkFZ6/ 4Hao23PMdBjJ6DA7q39h2N7JB4Qummmhynpiw6Qx2ybU2eXa0w/QUFFIy6DhVdZR mPqBbsqUHhA7Q7SqJ72a9rNSoCNgXPWYaKYg2ayXGSOuFQf/FAZFLz8g9Utp9eVQ UVS5VVY1B6WiX+CUPeT0TTR9CZsDPsXn5oPD44IBBaE61lT4OJv5VDB1022k4l0t c/nVIwhuyC7Cu3MXprwun3hwMz2/3Q/rIDxJgokERs04gq4iV707gzszWZRoZbWL YnvDQEnO+k9th0lvQ+jmWtVlwYuyE7by+7IGNGwzKofrofTQxIMg0HHudZWdmWZI z99lAIuslop6RpztDjjl0duaJb6Uouvmiz9Yi8fG2bt4chYvDrJYOlVxSfbftg+X EbjU0Xul =vEZb -----END PGP SIGNATURE----- --nextPart10375279.cNCT3uQDyu--