ALT-BU-2022-5048-2
Branch sisyphus update bulletin.
Package xfce4-panel updated to version 4.17.1-alt1 for branch sisyphus in task 300455.
Closed bugs
Некорректное изменение степени прозрачности у панели XFCE4
Closed bugs
Отсутствуют бинарники gdcm2vtk и gdcm2pnm
Package kernel-image-centos updated to version 5.14.0.97-alt1.el9 for branch sisyphus in task 300479.
Closed vulnerabilities
BDU:2022-01567
Уязвимость модулей esp4 и esp6 ядра операционной системы Linux, позволяющая нарушителю повысить свои привилегии
Modified: 2024-11-21
CVE-2022-1012
A memory leak problem was found in the TCP source port generation algorithm in net/ipv4/tcp.c due to the small table perturb size. This flaw may allow an attacker to information leak and may cause a denial of service problem.
- https://bugzilla.redhat.com/show_bug.cgi?id=2064604
- https://bugzilla.redhat.com/show_bug.cgi?id=2064604
- https://lore.kernel.org/lkml/20220427065233.2075-1-w%401wt.eu/T/
- https://lore.kernel.org/lkml/20220427065233.2075-1-w%401wt.eu/T/
- https://security.netapp.com/advisory/ntap-20221020-0006/
- https://security.netapp.com/advisory/ntap-20221020-0006/
Modified: 2024-11-21
CVE-2022-27666
A heap buffer overflow flaw was found in IPsec ESP transformation code in net/ipv4/esp4.c and net/ipv6/esp6.c. This flaw allows a local attacker with a normal user privilege to overwrite kernel heap objects and may cause a local privilege escalation threat.
- https://bugzilla.redhat.com/show_bug.cgi?id=2061633
- https://bugzilla.redhat.com/show_bug.cgi?id=2061633
- https://github.com/torvalds/linux/commit/ebe48d368e97d007bfeb76fcb065d6cfc4c96645
- https://github.com/torvalds/linux/commit/ebe48d368e97d007bfeb76fcb065d6cfc4c96645
- https://security.netapp.com/advisory/ntap-20220429-0001/
- https://security.netapp.com/advisory/ntap-20220429-0001/
- DSA-5127
- DSA-5127
- DSA-5173
- DSA-5173
Closed vulnerabilities
BDU:2023-02633
Уязвимость функции set_sixel компонента graphics_sixel.c эмулятора терминала XTerm, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2022-24130
xterm through Patch 370, when Sixel support is enabled, allows attackers to trigger a buffer overflow in set_sixel in graphics_sixel.c via crafted text.
- https://invisible-island.net/xterm/xterm.log.html
- https://invisible-island.net/xterm/xterm.log.html
- [debian-lts-announce] 20220207 [SECURITY] [DLA 2913-1] xterm security update
- [debian-lts-announce] 20220207 [SECURITY] [DLA 2913-1] xterm security update
- FEDORA-2022-965978ed67
- FEDORA-2022-965978ed67
- FEDORA-2022-9bf751cdf7
- FEDORA-2022-9bf751cdf7
- GLSA-202208-22
- GLSA-202208-22
- https://twitter.com/nickblack/status/1487731459398025216
- https://twitter.com/nickblack/status/1487731459398025216
- https://www.openwall.com/lists/oss-security/2022/01/30/2
- https://www.openwall.com/lists/oss-security/2022/01/30/2
- https://www.openwall.com/lists/oss-security/2022/01/30/3
- https://www.openwall.com/lists/oss-security/2022/01/30/3
Package sddm-theme-SugarCandy updated to version 1.5-alt2 for branch sisyphus in task 300496.
Closed bugs
Виртуальная клавиатура открывается в верхней части экарана и появляется после ее закрытия
После установки автоматически применяется, на другую сменить не удается