Advisories ยป MGASA-2024-0033

Updated kernel packages fix security vulnerabilities and other bugs

Publication date: 09 Feb 2024
Modification date: 09 Feb 2024
Type: security
Affected Mageia releases : 9
CVE: CVE-2023-6610 , CVE-2023-46838

Description

Upstream version 6.6.14 with many bugfixes and at least the following
security fixes:
An out-of-bounds read vulnerability was found in smb2_dump_detail in
fs/smb/client/smb2ops.c in the Linux Kernel. This issue could allow a
local attacker to crash the system or leak internal kernel information.
(CVE-2023-6610)
An unprivileged guest can cause Denial of Service (DoS) of the host by
sending network packets to the backend, causing the backend to crash.
Data corruption or privilege escalation have not been ruled out.
https://xenbits.xen.org/xsa/advisory-448.html (CVE-2023-46838)
                

References

SRPMS

9/core