<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">Security update for the Linux Kernel</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2022:0768-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2022-03-09T09:09:29Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2022-03-09T09:09:29Z</InitialReleaseDate>
    <CurrentReleaseDate>2022-03-09T09:09:29Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for the Linux Kernel</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">The SUSE Linux Enterprise 15 SP1 kernel was updated to receive various security and bugfixes.


Transient execution side-channel attacks attacking the Branch History Buffer (BHB),
named 'Branch Target Injection' and 'Intra-Mode Branch History Injection' are now mitigated.

The following security bugs were fixed:

- CVE-2022-0001: Fixed Branch History Injection vulnerability (bsc#1191580).
- CVE-2022-0002: Fixed Intra-Mode Branch Target Injection vulnerability (bsc#1191580).
- CVE-2022-0847: Fixed a vulnerability were a local attackers could overwrite data in arbitrary (read-only) files (bsc#1196584).
- CVE-2022-0617: Fixed a null pointer dereference in UDF file system functionality. A local user could crash the system by triggering udf_file_write_iter() via a malicious UDF image. (bsc#1196079)
- CVE-2022-0644: Fixed a denial of service by a local user. A assertion failure could be triggered in kernel_read_file_from_fd() (bsc#1196155).
- CVE-2021-44879: In gc_data_segment() in fs/f2fs/gc.c, special files were not considered, which lead to a move_data_page NULL pointer dereference (bsc#1195987).
- CVE-2022-24959: Fixed a memory leak in yam_siocdevprivate() in drivers/net/hamradio/yam.c (bsc#1195897).
- CVE-2022-0487: A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove() in drivers/memstick/host/rtsx_usb_ms.c (bsc#1194516).
- CVE-2022-0492: Fixed a privilege escalation related to cgroups v1 release_agent feature, which allowed bypassing namespace isolation unexpectedly (bsc#1195543).
- CVE-2022-24448: Fixed an issue in fs/nfs/dir.c. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR should have occured, but the server instead returned uninitialized data in the file descriptor (bsc#1195612).


The following non-security bugs were fixed:

- crypto: af_alg - get_page upon reassignment to TX SGL (bsc#1195840).
- lib/iov_iter: initialize 'flags' in new pipe_buffer (bsc#1196584).
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-SLE-15.3-2022-768,openSUSE-SLE-15.4-2022-768</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/</URL>
      <Description>E-Mail link for openSUSE-SU-2022:0768-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1185973</URL>
      <Description>SUSE Bug 1185973</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1191580</URL>
      <Description>SUSE Bug 1191580</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1194516</URL>
      <Description>SUSE Bug 1194516</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1195536</URL>
      <Description>SUSE Bug 1195536</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1195543</URL>
      <Description>SUSE Bug 1195543</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1195612</URL>
      <Description>SUSE Bug 1195612</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1195840</URL>
      <Description>SUSE Bug 1195840</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1195897</URL>
      <Description>SUSE Bug 1195897</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1195908</URL>
      <Description>SUSE Bug 1195908</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1195949</URL>
      <Description>SUSE Bug 1195949</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1195987</URL>
      <Description>SUSE Bug 1195987</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196079</URL>
      <Description>SUSE Bug 1196079</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196155</URL>
      <Description>SUSE Bug 1196155</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196584</URL>
      <Description>SUSE Bug 1196584</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196612</URL>
      <Description>SUSE Bug 1196612</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-44879/</URL>
      <Description>SUSE CVE CVE-2021-44879 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-0001/</URL>
      <Description>SUSE CVE CVE-2022-0001 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-0002/</URL>
      <Description>SUSE CVE CVE-2022-0002 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-0487/</URL>
      <Description>SUSE CVE CVE-2022-0487 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-0492/</URL>
      <Description>SUSE CVE CVE-2022-0492 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-0617/</URL>
      <Description>SUSE CVE CVE-2022-0617 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-0644/</URL>
      <Description>SUSE CVE CVE-2022-0644 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-0847/</URL>
      <Description>SUSE CVE CVE-2022-0847 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-24448/</URL>
      <Description>SUSE CVE CVE-2022-24448 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-24959/</URL>
      <Description>SUSE CVE CVE-2022-24959 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="openSUSE Leap 15.3">
      <Branch Type="Product Name" Name="openSUSE Leap 15.3">
        <FullProductName ProductID="openSUSE Leap 15.3" CPE="cpe:/o:opensuse:leap:15.3">openSUSE Leap 15.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="kernel-debug-base-4.12.14-197.108.1">
      <FullProductName ProductID="kernel-debug-base-4.12.14-197.108.1">kernel-debug-base-4.12.14-197.108.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-default-man-4.12.14-197.108.1">
      <FullProductName ProductID="kernel-default-man-4.12.14-197.108.1">kernel-default-man-4.12.14-197.108.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-kvmsmall-base-4.12.14-197.108.1">
      <FullProductName ProductID="kernel-kvmsmall-base-4.12.14-197.108.1">kernel-kvmsmall-base-4.12.14-197.108.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-vanilla-4.12.14-197.108.1">
      <FullProductName ProductID="kernel-vanilla-4.12.14-197.108.1">kernel-vanilla-4.12.14-197.108.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-vanilla-base-4.12.14-197.108.1">
      <FullProductName ProductID="kernel-vanilla-base-4.12.14-197.108.1">kernel-vanilla-base-4.12.14-197.108.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-vanilla-devel-4.12.14-197.108.1">
      <FullProductName ProductID="kernel-vanilla-devel-4.12.14-197.108.1">kernel-vanilla-devel-4.12.14-197.108.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-vanilla-livepatch-devel-4.12.14-197.108.1">
      <FullProductName ProductID="kernel-vanilla-livepatch-devel-4.12.14-197.108.1">kernel-vanilla-livepatch-devel-4.12.14-197.108.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-zfcpdump-man-4.12.14-197.108.1">
      <FullProductName ProductID="kernel-zfcpdump-man-4.12.14-197.108.1">kernel-zfcpdump-man-4.12.14-197.108.1</FullProductName>
    </Branch>
    <Relationship ProductReference="kernel-debug-base-4.12.14-197.108.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:kernel-debug-base-4.12.14-197.108.1">kernel-debug-base-4.12.14-197.108.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-default-man-4.12.14-197.108.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:kernel-default-man-4.12.14-197.108.1">kernel-default-man-4.12.14-197.108.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-kvmsmall-base-4.12.14-197.108.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:kernel-kvmsmall-base-4.12.14-197.108.1">kernel-kvmsmall-base-4.12.14-197.108.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-vanilla-4.12.14-197.108.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:kernel-vanilla-4.12.14-197.108.1">kernel-vanilla-4.12.14-197.108.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-vanilla-base-4.12.14-197.108.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:kernel-vanilla-base-4.12.14-197.108.1">kernel-vanilla-base-4.12.14-197.108.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-vanilla-devel-4.12.14-197.108.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:kernel-vanilla-devel-4.12.14-197.108.1">kernel-vanilla-devel-4.12.14-197.108.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-vanilla-livepatch-devel-4.12.14-197.108.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:kernel-vanilla-livepatch-devel-4.12.14-197.108.1">kernel-vanilla-livepatch-devel-4.12.14-197.108.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-zfcpdump-man-4.12.14-197.108.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:kernel-zfcpdump-man-4.12.14-197.108.1">kernel-zfcpdump-man-4.12.14-197.108.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
  </ProductTree>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference.</Note>
    </Notes>
    <CVE>CVE-2021-44879</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:kernel-debug-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-default-man-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-kvmsmall-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-livepatch-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-zfcpdump-man-4.12.14-197.108.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.3</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-44879.html</URL>
        <Description>CVE-2021-44879</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1195987</URL>
        <Description>SUSE Bug 1195987</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.</Note>
    </Notes>
    <CVE>CVE-2022-0001</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:kernel-debug-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-default-man-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-kvmsmall-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-livepatch-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-zfcpdump-man-4.12.14-197.108.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>2.1</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:P/I:N/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.6</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-0001.html</URL>
        <Description>CVE-2022-0001</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1191580</URL>
        <Description>SUSE Bug 1191580</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1196901</URL>
        <Description>SUSE Bug 1196901</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">Non-transparent sharing of branch predictor within a context in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access.</Note>
    </Notes>
    <CVE>CVE-2022-0002</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:kernel-debug-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-default-man-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-kvmsmall-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-livepatch-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-zfcpdump-man-4.12.14-197.108.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>2.1</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:P/I:N/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.6</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:N/A:N</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-0002.html</URL>
        <Description>CVE-2022-0002</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1191580</URL>
        <Description>SUSE Bug 1191580</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1196901</URL>
        <Description>SUSE Bug 1196901</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidentiality. This flaw affects kernel versions prior to 5.14 rc1.</Note>
    </Notes>
    <CVE>CVE-2022-0487</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:kernel-debug-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-default-man-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-kvmsmall-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-livepatch-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-zfcpdump-man-4.12.14-197.108.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>2.1</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:P/I:N/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>7</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-0487.html</URL>
        <Description>CVE-2022-0487</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1194516</URL>
        <Description>SUSE Bug 1194516</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1195949</URL>
        <Description>SUSE Bug 1195949</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1198615</URL>
        <Description>SUSE Bug 1198615</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. This flaw, under certain circumstances, allows the use of the cgroups v1 release_agent feature to escalate privileges and bypass the namespace isolation unexpectedly.</Note>
    </Notes>
    <CVE>CVE-2022-0492</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:kernel-debug-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-default-man-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-kvmsmall-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-livepatch-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-zfcpdump-man-4.12.14-197.108.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.9</BaseScoreV2>
        <VectorV2>AV:L/AC:M/Au:N/C:C/I:C/A:C</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>7</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-0492.html</URL>
        <Description>CVE-2022-0492</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1195543</URL>
        <Description>SUSE Bug 1195543</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1195908</URL>
        <Description>SUSE Bug 1195908</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1196612</URL>
        <Description>SUSE Bug 1196612</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1196776</URL>
        <Description>SUSE Bug 1196776</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1198615</URL>
        <Description>SUSE Bug 1198615</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1199255</URL>
        <Description>SUSE Bug 1199255</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1199615</URL>
        <Description>SUSE Bug 1199615</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1200084</URL>
        <Description>SUSE Bug 1200084</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc1 till 5.17-rc2.</Note>
    </Notes>
    <CVE>CVE-2022-0617</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:kernel-debug-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-default-man-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-kvmsmall-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-livepatch-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-zfcpdump-man-4.12.14-197.108.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.9</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:N/I:N/A:C</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-0617.html</URL>
        <Description>CVE-2022-0617</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1196079</URL>
        <Description>SUSE Bug 1196079</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.</Note>
    </Notes>
    <CVE>CVE-2022-0644</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:kernel-debug-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-default-man-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-kvmsmall-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-livepatch-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-zfcpdump-man-4.12.14-197.108.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-0644.html</URL>
        <Description>CVE-2022-0644</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1196155</URL>
        <Description>SUSE Bug 1196155</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in copy_page_to_iter_pipe and push_pipe functions in the Linux kernel and could thus contain stale values. An unprivileged local user could use this flaw to write to pages in the page cache backed by read only files and as such escalate their privileges on the system.</Note>
    </Notes>
    <CVE>CVE-2022-0847</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:kernel-debug-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-default-man-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-kvmsmall-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-livepatch-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-zfcpdump-man-4.12.14-197.108.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>7.2</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:C/I:C/A:C</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>7.8</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-0847.html</URL>
        <Description>CVE-2022-0847</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1196584</URL>
        <Description>SUSE Bug 1196584</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1196601</URL>
        <Description>SUSE Bug 1196601</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR should occur, but the server instead returns uninitialized data in the file descriptor.</Note>
    </Notes>
    <CVE>CVE-2022-24448</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:kernel-debug-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-default-man-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-kvmsmall-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-livepatch-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-zfcpdump-man-4.12.14-197.108.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>1.9</BaseScoreV2>
        <VectorV2>AV:L/AC:M/Au:N/C:P/I:N/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-24448.html</URL>
        <Description>CVE-2022-24448</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1195612</URL>
        <Description>SUSE Bug 1195612</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in the Linux kernel before 5.16.5. There is a memory leak in yam_siocdevprivate in drivers/net/hamradio/yam.c.</Note>
    </Notes>
    <CVE>CVE-2022-24959</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:kernel-debug-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-default-man-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-kvmsmall-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-base-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-vanilla-livepatch-devel-4.12.14-197.108.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-zfcpdump-man-4.12.14-197.108.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>2.1</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/MWGLT5YBYSSX5MP2JBKT3N3QV2IWMC5F/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-24959.html</URL>
        <Description>CVE-2022-24959</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1195897</URL>
        <Description>SUSE Bug 1195897</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
</cvrfdoc>
