No Image

USN-5987-1: Linux kernel vulnerabilities

2023-03-30 KENNETH 0

USN-5987-1: Linux kernel vulnerabilities It was discovered that the KVM VMX implementation in the Linux kernel did not properly handle indirect branch prediction isolation between L1 and L2 VMs. An attacker in a guest VM could use this to expose sensitive information from the host OS or other guest VMs. (CVE-2022-2196) It was discovered that a use-after-free vulnerability existed in the SGI GRU driver in the Linux kernel. A local attacker could possibly use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-3424) Ziming Zhang discovered that the VMware Virtual GPU DRM driver in the Linux kernel contained an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-36280) Hyunwoo Kim discovered that the DVB Core driver in the Linux kernel did not properly perform reference [ more… ]

No Image

USN-5986-1: X.Org X Server vulnerability

2023-03-30 KENNETH 0

USN-5986-1: X.Org X Server vulnerability Jan-Niklas Sohn discovered that the X.Org X Server incorrectly handled certain memory operations. An attacker could possibly use these issues to cause the X Server to crash, execute arbitrary code, or escalate privileges. Source: USN-5986-1: X.Org X Server vulnerability

No Image

USN-5985-1: Linux kernel vulnerabilities

2023-03-30 KENNETH 0

USN-5985-1: Linux kernel vulnerabilities It was discovered that the System V IPC implementation in the Linux kernel did not properly handle large shared memory counts. A local attacker could use this to cause a denial of service (memory exhaustion). (CVE-2021-3669) It was discovered that the KVM VMX implementation in the Linux kernel did not properly handle indirect branch prediction isolation between L1 and L2 VMs. An attacker in a guest VM could use this to expose sensitive information from the host OS or other guest VMs. (CVE-2022-2196) Gerald Lee discovered that the USB Gadget file system implementation in the Linux kernel contained a race condition, leading to a use-after-free vulnerability in some situations. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-4382) It was discovered that the RNDIS USB [ more… ]

No Image

USN-5984-1: Linux kernel vulnerabilities

2023-03-30 KENNETH 0

USN-5984-1: Linux kernel vulnerabilities It was discovered that the System V IPC implementation in the Linux kernel did not properly handle large shared memory counts. A local attacker could use this to cause a denial of service (memory exhaustion). (CVE-2021-3669) It was discovered that a use-after-free vulnerability existed in the SGI GRU driver in the Linux kernel. A local attacker could possibly use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-3424) Ziming Zhang discovered that the VMware Virtual GPU DRM driver in the Linux kernel contained an out-of-bounds write vulnerability. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-36280) Hyunwoo Kim discovered that the DVB Core driver in the Linux kernel did not properly perform reference counting in some situations, leading to a use- after-free vulnerability. A [ more… ]

No Image

Lenovo introduces new Windows 11 laptops for creators and gamers with Yoga and Legion lineups

2023-03-30 KENNETH 0

Lenovo introduces new Windows 11 laptops for creators and gamers with Yoga and Legion lineups Creators and gamers in search of updating their PCs have new options with the lineups Lenovo recently released that aim to deliver performance, versatility and mobility in portable designs. Lenovo’s PCs come with Windows 11, which introduced a major update at the end of February. One of the biggest additions is a typable Windows search box that brings the new AI-powered Bing front and center. The update also includes improved touch experiences, full screen widgets, quick access to the Windows 365 app and new AI features in Start. Additionally, Windows announced a preview of Phone Link for iOS which is currently available to Windows Insiders and available to all Windows users in the coming months. The flagship Yoga Pro 9i (available in 16-inch and 14.5-inch [ more… ]