Re: CVE-2022-25636 - privilege escalation through netfilter bug

Alexander Bergmann <[email protected]> Wed, 16 Mar 2022 08:47:20 +0100
Newsgroups gmane.linux.suse.security
Message-ID <20220316074720.mp2jwamxzv7xuier@castor>
--lh4kyl2xg6hbadub
Content-Type: text/plain; charset=iso-8859-1
Content-Disposition: inline
Content-Transfer-Encoding: quoted-printable

Hi Mathias,

That's for double checking this. Our tracking was a bit off as the fix
commit was not directly touching the code that introduced the issue in
kernel version 5.4.

I've updated our tracking and the CVE page will updated shortly.

https://www.suse.com/security/cve/CVE-2022-25636.html


Thanks again,
Alex~

On Wed, Mar 16, 2022 at 07:17:50AM +0100, Mathias Homann wrote:
> Am Mittwoch, 16. M=E4rz 2022, 07:05:04 CET schrieb Mathias Homann:
> > Hi,
> >=20
> > just came across CVE-2022-25636 in this article: https://www.zdnet.com/
> > article/nasty-linux-netfilter-firewall-security-hole-found/
> >=20
> > Is there an update for Leap 15.3 and SLES in the works?
> >=20
> > Tumbleweed should be ok since the bug is "only" in kernels up to 5.6.10=
 and
> > TW currently runs on 5.16.14.
>=20
> on second thought, Leap and SLES should be fine too: Kernels affected are=
 5.4=20
> to 5.10 - Leap and SLES use 5.3.x, TW uses 5.16.
>=20
> I hate ZD Net sensationalism. But please someone verify that we're safe a=
bout=20
> this one, I hate local privilege elevation holes more.
>=20
> Cheers
> MH
>=20
> --=20
> Mathias Homann
> [email protected]
> Jabber (XMPP): [email protected]
> Matrix: @mathias:eregion.de
> IRC: [Lemmy] on freenode and ircnet (bouncer active)
> keybase: https://keybase.io/lemmy
> gpg key fingerprint: 8029 2240 F4DD 7776 E7D2 C042 6B8E 029E 13F2 C102



--=20
Alexander Bergmann <[email protected]>
Security Engineer, GPG: E30A 65A4 0F50 0066 B2B5  F614 DE54 E875 9FFA 4886
SUSE Software Solutions Germany GmbH
Maxfeldstr. 5, 90409 Nuremberg, Germany
(HRB 36809, AG N=FCrnberg)
Managing Director/Gesch=E4ftsf=FChrer: Ivo Totev

--lh4kyl2xg6hbadub
Content-Type: application/pgp-signature; name="signature.asc"

-----BEGIN PGP SIGNATURE-----

iQEzBAABCAAdFiEE4wplpA9QAGaytfYU3lTodZ/6SIYFAmIxlgUACgkQ3lTodZ/6
SIbIQgf/ZKg3v0fyQ0CMjfasnPNR/aUwroKTSpESy7XuVEs+2Fi/HYI23zwWyd7u
QE6hOxbJomhFq/7ahemGzmK02+83q74szZo/8E9U05v7uZgDB6MrRCS8A/jODavC
wiuSgZk0w/JpvCXv97k93ZDVgeXknJJqE63BtHLx/qJ4FnOQnLSH+CReYyHtxMO7
B7n1SLeDCP9N2Y07/a932E1EcRcgQ/ESJW1FtcJSsusmEX2/UE9GIv9eb1Pk++oK
Mpu97DqH0XJF9mzRkeHW6cfkUGvJx+7SPdU5HpXOq3feImijdnUyp+cEGmlXxYZa
XNUmlMYyqk5oq/wI6smOJ/Tz1ogl5g==
=HF8S
-----END PGP SIGNATURE-----

--lh4kyl2xg6hbadub--