Synopsis:
kernel security updateSummary:
An update for kernel is now available for openEuler-20.03-LTS-SP4Description:
The Linux Kernel, the operating system core itself.
Security Fix(es):
In the Linux kernel, the following vulnerability has been resolved:
dm: fix a buffer overflow in ioctl processing
Tony Asleson (using Claude) found a buffer overflow in dm-ioctl in the function retrieve_status:
Luckily, this bug has no security implications because:
An update for kernel is now available for openEuler-20.03-LTS-SP4/openEuler-22.03-LTS-SP3/openEuler-24.03-LTS/openEuler-24.03-LTS-SP2.
openEuler Security has rated this update as having a security impact of high. A Common Vunlnerability Scoring System(CVSS)base score,which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.Severity:
HighAffected Component:
kernel
4.19.90-2606.4.0.0377.oe2003sp44.19.90-2606.4.0.0377.oe2003sp44.19.90-2606.4.0.0377.oe2003sp44.19.90-2606.4.0.0377.oe2003sp44.19.90-2606.4.0.0377.oe2003sp44.19.90-2606.4.0.0377.oe2003sp44.19.90-2606.4.0.0377.oe2003sp44.19.90-2606.4.0.0377.oe2003sp44.19.90-2606.4.0.0377.oe2003sp44.19.90-2606.4.0.0377.oe2003sp4Exploitability
AV:LAC:HPR:LUI:NScope
S:UImpact
C:HI:HA:H7.0/CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H