No Image

USN-5865-1: Linux kernel (Azure) vulnerabilities

2023-02-10 KENNETH 0

USN-5865-1: Linux kernel (Azure) vulnerabilities It was discovered that an out-of-bounds write vulnerability existed in the Video for Linux 2 (V4L2) implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-20369) Pawan Kumar Gupta, Alyssa Milburn, Amit Peled, Shani Rehana, Nir Shildan and Ariel Sabba discovered that some Intel processors with Enhanced Indirect Branch Restricted Speculation (eIBRS) did not properly handle RET instructions after a VM exits. A local attacker could potentially use this to expose sensitive information. (CVE-2022-26373) David Leadbeater discovered that the netfilter IRC protocol tracking implementation in the Linux Kernel incorrectly handled certain message payloads in some situations. A remote attacker could possibly use this to cause a denial of service or bypass firewall filtering. (CVE-2022-2663) Johannes Wikner and Kaveh Razavi discovered [ more… ]

No Image

쿠버네티스 프로비저닝 툴과의 만남부터 헤어짐까지 . . .

2023-02-10 KENNETH 0

쿠버네티스 프로비저닝 툴과의 만남부터 헤어짐까지 . . . 들어가며 안녕하세요, 카카오 클라우드 네이티브 파트에서 DKOS의 개발을 맡고 있는 우주, 후니, 존, 루키입니다. DKOS는 카카오 사내 개발자들을 위한 KaaS (Kubernetes as a service)입니다. 지난 4년간 DKOS를 서비스하며, 다수의 프로젝트가 리소스를 잘 사용할 수 있도록 Kubespray를 사용하여 쿠버네티스를 프로비저닝(Provisioning) 했었습니다. 이번 글에서는 “왜” Kubespray를 걷어내게 되었고, 또 “어떻게” 걷어낼 수 있었는지에 대해 이야기해보려 합니다. 쿠버네티스 프로비저닝이란?쿠버네티스 […] Source: 쿠버네티스 프로비저닝 툴과의 만남부터 헤어짐까지 . . .

No Image

USN-5863-1: Linux kernel (Azure) vulnerabilities

2023-02-10 KENNETH 0

USN-5863-1: Linux kernel (Azure) vulnerabilities It was discovered that the NFSD implementation in the Linux kernel did not properly handle some RPC messages, leading to a buffer overflow. A remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-43945) Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation in the Linux kernel contained multiple use-after-free vulnerabilities. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-42896) It was discovered that the Xen netback driver in the Linux kernel did not properly handle packets structured in certain ways. An attacker in a guest VM could possibly use this to cause a denial of service (host NIC availability). (CVE-2022-3643) It was discovered that an integer overflow vulnerability existed in the Bluetooth subsystem [ more… ]

No Image

USN-5862-1: Linux kernel (Qualcomm Snapdragon) vulnerabilities

2023-02-10 KENNETH 0

USN-5862-1: Linux kernel (Qualcomm Snapdragon) vulnerabilities It was discovered that an out-of-bounds write vulnerability existed in the Video for Linux 2 (V4L2) implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-20369) Pawan Kumar Gupta, Alyssa Milburn, Amit Peled, Shani Rehana, Nir Shildan and Ariel Sabba discovered that some Intel processors with Enhanced Indirect Branch Restricted Speculation (eIBRS) did not properly handle RET instructions after a VM exits. A local attacker could potentially use this to expose sensitive information. (CVE-2022-26373) David Leadbeater discovered that the netfilter IRC protocol tracking implementation in the Linux Kernel incorrectly handled certain message payloads in some situations. A remote attacker could possibly use this to cause a denial of service or bypass firewall filtering. (CVE-2022-2663) Johannes Wikner and Kaveh Razavi [ more… ]

No Image

USN-5861-1: Linux kernel (Dell300x) vulnerabilities

2023-02-10 KENNETH 0

USN-5861-1: Linux kernel (Dell300x) vulnerabilities It was discovered that the NFSD implementation in the Linux kernel did not properly handle some RPC messages, leading to a buffer overflow. A remote attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-43945) Tamás Koczka discovered that the Bluetooth L2CAP handshake implementation in the Linux kernel contained multiple use-after-free vulnerabilities. A physically proximate attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-42896) It was discovered that an out-of-bounds write vulnerability existed in the Video for Linux 2 (V4L2) implementation in the Linux kernel. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-20369) Pawan Kumar Gupta, Alyssa Milburn, Amit Peled, Shani Rehana, Nir Shildan and Ariel [ more… ]