No Image

USN-5978-1: Linux kernel (OEM) vulnerabilities

2023-03-28 KENNETH 0

USN-5978-1: Linux kernel (OEM) vulnerabilities It was discovered that the network queuing discipline implementation in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-1281) It was discovered that the KVM VMX implementation in the Linux kernel did not properly handle indirect branch prediction isolation between L1 and L2 VMs. An attacker in a guest VM could use this to expose sensitive information from the host OS or other guest VMs. (CVE-2022-2196) It was discovered that some AMD x86-64 processors with SMT enabled could speculatively execute instructions using a return address from a sibling thread. A local attacker could possibly use this to expose sensitive information. (CVE-2022-27672) Gerald Lee discovered that the USB Gadget file system implementation in the Linux kernel contained a [ more… ]

No Image

USN-5977-1: Linux kernel (OEM) vulnerabilities

2023-03-28 KENNETH 0

USN-5977-1: Linux kernel (OEM) vulnerabilities It was discovered that the network queuing discipline implementation in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-1281) It was discovered that the KVM VMX implementation in the Linux kernel did not properly handle indirect branch prediction isolation between L1 and L2 VMs. An attacker in a guest VM could use this to expose sensitive information from the host OS or other guest VMs. (CVE-2022-2196) Thadeu Cascardo discovered that the io_uring subsystem contained a double- free vulnerability in certain memory allocation error conditions. A local attacker could possibly use this to cause a denial of service (system crash). (CVE-2023-1032) Source: USN-5977-1: Linux kernel (OEM) vulnerabilities

No Image

USN-5976-1: Linux kernel (OEM) vulnerabilities

2023-03-28 KENNETH 0

USN-5976-1: Linux kernel (OEM) vulnerabilities It was discovered that the Upper Level Protocol (ULP) subsystem in the Linux kernel did not properly handle sockets entering the LISTEN state in certain protocols, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-0461) It was discovered that the KVM VMX implementation in the Linux kernel did not properly handle indirect branch prediction isolation between L1 and L2 VMs. An attacker in a guest VM could use this to expose sensitive information from the host OS or other guest VMs. (CVE-2022-2196) It was discovered that the Intel 740 frame buffer driver in the Linux kernel contained a divide by zero vulnerability. A local attacker could use this to cause a denial of service (system crash). (CVE-2022-3061) It was [ more… ]

[도서] 고객 여정 지도 워크숍 가이드

2023-03-28 KENNETH 0

[도서] 고객 여정 지도 워크숍 가이드 분야별 신상품 – 국내도서 – 컴퓨터와 인터넷 [도서]고객 여정 지도 워크숍 가이드 가토 미코토 저/이정미 역 | 유엑스리뷰 | 2023년 04월 판매가 23,400원 (10%할인) | YES포인트 1,300원(5%지급) CX, CS, UX의 필수 전략을 제대로 배우고 활용할 기회! 효과적인 고객 여정 지도 제작을 위한 국내 최초의 가이드! CX(고객 경험), CS(고객 서비스), UX(사용자 경험) 분야에서 가장 유용한 고객 조사 방법이자 Source: [도서] 고객 여정 지도 워크숍 가이드

No Image

USN-5975-1: Linux kernel vulnerabilities

2023-03-28 KENNETH 0

USN-5975-1: Linux kernel vulnerabilities It was discovered that the Upper Level Protocol (ULP) subsystem in the Linux kernel did not properly handle sockets entering the LISTEN state in certain protocols, leading to a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2023-0461) It was discovered that the System V IPC implementation in the Linux kernel did not properly handle large shared memory counts. A local attacker could use this to cause a denial of service (memory exhaustion). (CVE-2021-3669) It was discovered that an out-of-bounds write vulnerability existed in the Video for Linux 2 (V4L2) implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-20369) Pawan Kumar Gupta, Alyssa Milburn, Amit Peled, Shani [ more… ]