No Image

USN-5362-1: Linux kernel (Intel IOTG) vulnerabilities

2022-04-01 KENNETH 0

USN-5362-1: Linux kernel (Intel IOTG) vulnerabilities Nick Gregory discovered that the Linux kernel incorrectly handled network offload functionality. A local attacker could use this to cause a denial of service or possibly execute arbitrary code. (CVE-2022-25636) Enrico Barberis, Pietro Frigo, Marius Muench, Herbert Bos, and Cristiano Giuffrida discovered that hardware mitigations added by ARM to their processors to address Spectre-BTI were insufficient. A local attacker could potentially use this to expose sensitive information. (CVE-2022-23960) It was discovered that the BPF verifier in the Linux kernel did not properly restrict pointer types in certain situations. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-23222) Max Kellermann discovered that the Linux kernel incorrectly handled Unix pipes. A local attacker could potentially use this to modify any file that could be opened [ more… ]

No Image

USN-5361-1: Linux kernel vulnerabilities

2022-04-01 KENNETH 0

USN-5361-1: Linux kernel vulnerabilities It was discovered that the VFIO PCI driver in the Linux kernel did not properly handle attempts to access disabled memory spaces. A local attacker could use this to cause a denial of service (system crash). (CVE-2020-12888) Mathy Vanhoef discovered that the Linux kernel’s WiFi implementation did not properly verify certain fragmented frames. A physically proximate attacker could possibly use this issue to inject or decrypt packets. (CVE-2020-26141) Mathy Vanhoef discovered that the Linux kernel’s WiFi implementation accepted plaintext fragments in certain situations. A physically proximate attacker could use this issue to inject packets. (CVE-2020-26145) It was discovered that a race condition existed in the Atheros Ath9k WiFi driver in the Linux kernel. An attacker could possibly use this to expose sensitive information (WiFi network traffic). (CVE-2020-3702) It was discovered a race condition existed in the [ more… ]

No Image

USN-5358-2: Linux kernel vulnerabilities

2022-04-01 KENNETH 0

USN-5358-2: Linux kernel vulnerabilities It was discovered that the network traffic control implementation in the Linux kernel contained a use-after-free vulnerability. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-1055) It was discovered that the IPsec implementation in the Linux kernel did not properly allocate enough memory when performing ESP transformations, leading to a heap-based buffer overflow. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2022-27666) Source: USN-5358-2: Linux kernel vulnerabilities

No Image

USN-5357-2: Linux kernel vulnerability

2022-04-01 KENNETH 0

USN-5357-2: Linux kernel vulnerability It was discovered that the IPsec implementation in the Linux kernel did not properly allocate enough memory when performing ESP transformations, leading to a heap-based buffer overflow. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. Source: USN-5357-2: Linux kernel vulnerability

No Image

Sonic lands in the Candy Kingdom as Great Adventure Season begins

2022-04-01 KENNETH 0

Sonic lands in the Candy Kingdom as Great Adventure Season begins The first week in Candy Crush Saga’s Great Adventure Season has begun with the arrival of a guest starring character in the game – none other than Sonic the Hedgehog. All blue candies this week will be reskinned into a “sonictastic” design in the game, and two different adventures will invite you to join and to collect the blue Sonic Candies: Sonic Dash Collection and The Great Chase. If you manage to get to the top 10 on the leaderboard in the Great Chase or collect at least 5,000 blue Sonic Candies in Sonic Dash Collection, you can take a screenshot of your achievement and claim your Candy Community Sonic badge. Let the fun begin. After the first week Sonic will leave the arena, but the Great Adventure will [ more… ]