SUSE SLES15: cluster-md-kmp-azure / dlm-kmp-azure / gfs2-kmp-azure / etc (SUSE-SU-2022:2722-1)

high Nessus Plugin ID 163995

Language:

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES15 / SLES_SAP15 / openSUSE 15 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2022:2722-1 advisory.

The SUSE Linux Enterprise 15 SP4 Azure kernel was updated to receive various security and bugfixes.

The following security bugs were fixed:

- CVE-2021-33655: Fixed out of bounds write with ioctl FBIOPUT_VSCREENINFO (bnc#1201635).
- CVE-2022-1462: Fixed an out-of-bounds read flaw in the TeleTYpe subsystem (bnc#1198829).
- CVE-2022-21505: Fixed kexec lockdown bypass with IMA policy (bsc#1201458).
- CVE-2022-29581: Fixed improper update of Reference Count in net/sched that could cause root privilege escalation (bnc#1199665).
- CVE-2022-32250: Fixed an use-after-free bug in the netfilter subsystem. This flaw allowed a local attacker with user access to cause a privilege escalation issue (bnc#1200015, bnc#1200494).


Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1190256

https://bugzilla.suse.com/1190497

https://bugzilla.suse.com/1198410

https://bugzilla.suse.com/1198829

https://bugzilla.suse.com/1199086

https://bugzilla.suse.com/1199291

https://bugzilla.suse.com/1199364

https://bugzilla.suse.com/1199665

https://bugzilla.suse.com/1199670

https://bugzilla.suse.com/1200015

https://bugzilla.suse.com/1200465

https://bugzilla.suse.com/1200494

https://bugzilla.suse.com/1200644

https://bugzilla.suse.com/1200651

https://bugzilla.suse.com/1201258

https://bugzilla.suse.com/1201323

https://bugzilla.suse.com/1201381

https://bugzilla.suse.com/1201391

https://bugzilla.suse.com/1201427

https://bugzilla.suse.com/1201458

https://bugzilla.suse.com/1201471

https://bugzilla.suse.com/1201524

https://bugzilla.suse.com/1201592

https://bugzilla.suse.com/1201593

https://bugzilla.suse.com/1201595

https://bugzilla.suse.com/1201596

https://bugzilla.suse.com/1201635

https://bugzilla.suse.com/1201651

https://bugzilla.suse.com/1201675

https://bugzilla.suse.com/1201691

https://bugzilla.suse.com/1201705

https://bugzilla.suse.com/1201725

https://bugzilla.suse.com/1201846

https://bugzilla.suse.com/1201930

https://bugzilla.suse.com/1201954

https://bugzilla.suse.com/1201958

https://www.suse.com/security/cve/CVE-2021-33655

https://www.suse.com/security/cve/CVE-2022-1462

https://www.suse.com/security/cve/CVE-2022-21505

https://www.suse.com/security/cve/CVE-2022-29581

https://www.suse.com/security/cve/CVE-2022-32250

http://www.nessus.org/u?e5085422

Plugin Details

Severity: High

ID: 163995

File Name: suse_SU-2022-2722-1.nasl

Version: 1.8

Type: Local

Agent: unix

Published: 8/10/2022

Updated: 6/25/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Nessus

Risk Information

VPR

Risk Factor: Critical

Score: 9.5

CVSS v2

Risk Factor: High

Base Score: 7.2

Temporal Score: 6.3

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2022-32250

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:H/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:kernel-source-azure, p-cpe:/a:novell:suse_linux:kernel-syms-azure, p-cpe:/a:novell:suse_linux:kernel-azure-devel, p-cpe:/a:novell:suse_linux:kernel-devel-azure, p-cpe:/a:novell:suse_linux:kernel-azure, cpe:/o:novell:suse_linux:15

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 8/9/2022

Vulnerability Publication Date: 5/17/2022

Reference Information

CVE: CVE-2021-33655, CVE-2022-1462, CVE-2022-21505, CVE-2022-29581, CVE-2022-32250

SuSE: SUSE-SU-2022:2722-1