Advisories ยป MGASA-2022-0045

Updated connman packages fix security vulnerability

Publication date: 02 Feb 2022
Type: security
Affected Mageia releases : 8
CVE: CVE-2022-23096 , CVE-2022-23097 , CVE-2022-23098

Description

TCP Receive Path does not Check for Presence of Sufficient Header Data.
(CVE-2022-23096)

Possibly invalid memory reference in 'strnlen()' call in
'forward_dns_reply()'. (CVE-2022-23097)

TCP Receive Path Triggers 100 % CPU loop if DNS server does not Send Back
Data. (CVE-2022-23098)
                

References

SRPMS

8/core