AlmaLinux 8 : kernel-rt (5834) (ALSA-2022:5834)

critical Nessus Plugin ID 163889

Synopsis

The remote AlmaLinux host is missing one or more security updates.

Description

The remote AlmaLinux 8 host has packages installed that are affected by multiple vulnerabilities as referenced in the ALSA-2022:5834 advisory.

- net/netfilter/nf_tables_api.c in the Linux kernel through 5.18.1 allows a local user (able to create user/net namespaces) to escalate privileges to root because an incorrect NFT_STATEFUL_EXPR check leads to a use-after-free. (CVE-2022-32250)

- kernel: Small table perturb size in the TCP source port generation algorithm can lead to information leak (CVE-2022-1012)

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://errata.almalinux.org/8/ALSA-2022-5834.html

Plugin Details

Severity: Critical

ID: 163889

File Name: alma_linux_ALSA-2022-5834.nasl

Version: 1.3

Type: local

Published: 8/5/2022

Updated: 8/12/2022

Risk Information

VPR

Risk Factor: High

Score: 8.4

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 5.3

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: E:U/RL:OF/RC:C

CVSS Score Source: CVE-2022-32250

CVSS v3

Risk Factor: Critical

Base Score: 9.1

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

Temporal Vector: E:U/RL:O/RC:C

CVSS Score Source: CVE-2022-1012

Vulnerability Information

CPE: p-cpe:2.3:a:alma:linux:kernel-rt-core:*:*:*:*:*:*:*, p-cpe:2.3:a:alma:linux:kernel-rt-debug-kvm:*:*:*:*:*:*:*, p-cpe:2.3:a:alma:linux:kernel-rt-modules-extra:*:*:*:*:*:*:*, p-cpe:2.3:a:alma:linux:kernel-rt-debug-devel:*:*:*:*:*:*:*, p-cpe:2.3:a:alma:linux:kernel-rt:*:*:*:*:*:*:*, p-cpe:2.3:a:alma:linux:kernel-rt-devel:*:*:*:*:*:*:*, p-cpe:2.3:a:alma:linux:kernel-rt-debug-modules:*:*:*:*:*:*:*, p-cpe:2.3:a:alma:linux:kernel-rt-debug:*:*:*:*:*:*:*, cpe:2.3:o:alma:linux:8:*:*:*:*:*:*:*, p-cpe:2.3:a:alma:linux:kernel-rt-modules:*:*:*:*:*:*:*, p-cpe:2.3:a:alma:linux:kernel-rt-kvm:*:*:*:*:*:*:*, p-cpe:2.3:a:alma:linux:kernel-rt-debug-core:*:*:*:*:*:*:*, p-cpe:2.3:a:alma:linux:kernel-rt-debug-modules-extra:*:*:*:*:*:*:*

Required KB Items: Host/local_checks_enabled, Host/AlmaLinux/release, Host/AlmaLinux/rpm-list, Host/cpu

Exploit Ease: No known exploits are available

Patch Publication Date: 8/2/2022

Vulnerability Publication Date: 6/2/2022

Reference Information

CVE: CVE-2022-1012, CVE-2022-32250

ALSA: 2022:5834