Activity log for bug #1969605

Date Who What changed Old value New value Message
2022-04-20 10:00:06 Yue Tao bug added bug
2022-04-20 10:00:34 Yue Tao starlingx: assignee Joe Slater (jslater0wind)
2022-04-24 08:38:40 Yue Tao description CVE-2022-0435: kernel: remote stack overflow via kernel panic on systems using TIPC may lead to DoS Score: 9.0: AV:N/AC:L/Au:S/C:C/I:C/A:C Description: CVE-2022-0435 A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network. References: https://nvd.nist.gov/vuln/detail/CVE-2022-0435 https://access.redhat.com/security/cve/CVE-2022-0435 The CVE has been fixed by Linux yocto kernel 5.10.100 CVE-2022-0435: kernel: remote stack overflow via kernel panic on systems using TIPC may lead to DoS Score: 9.0: AV:N/AC:L/Au:S/C:C/I:C/A:C Description: CVE-2022-0435 A stack overflow flaw was found in the Linux kernel's TIPC protocol functionality in the way a user sends a packet with malicious content where the number of domain member nodes is higher than the 64 allowed. This flaw allows a remote user to crash the system or possibly escalate their privileges if they have access to the TIPC network. References: https://nvd.nist.gov/vuln/detail/CVE-2022-0435 https://access.redhat.com/security/cve/CVE-2022-0435 The CVE has been fixed by Linux yocto kernel 5.10.102
2022-04-24 08:39:26 Yue Tao cve linked 2022-0847
2022-04-25 07:23:21 Yue Tao starlingx: assignee Joe Slater (jslater0wind) Jiping Ma (jma11)
2022-04-25 22:46:51 Ghada Khalil tags stx.security
2022-04-25 22:47:16 Ghada Khalil starlingx: importance Undecided Medium
2022-04-25 22:47:33 Ghada Khalil tags stx.security stx.6.0 stx.7.0 stx.security
2022-05-02 13:42:56 Ghada Khalil information type Public Public Security
2022-05-02 13:43:14 Ghada Khalil starlingx: status New Triaged
2022-05-16 06:30:51 OpenStack Infra starlingx: status Triaged In Progress
2022-05-23 00:58:19 OpenStack Infra starlingx: status In Progress Fix Released
2022-05-23 00:58:20 OpenStack Infra cve linked 2022-0435