-
CVE-2022-29156 drivers/infiniband/ulp/rtrs/rtrs-clt[.]c in the Linux kernel before 5.16.12 has a double free related to rtrs_clt_dev_release. 13th April 2022
Preface: In fact, when the details of a vulnerability were announced. It’s hard to guess when it first happened. This is a well-known fact in the cybersecurity community. However, security analysts and researchers don’t mind the delay. Since the goal is to fix the problem and avoid a similar vulnerability in another product.For example, the…
-
About CVE-2022-26151 – Citrix Endpoint Management (XenMobile Server) , whether to remediate a design flaw discovered in 2018. (12th April 2022)
Preface: Public Key Infrastructure is the proven solution for authentication, encryption and data integrity. DigiCert PKI solutions are built on trust. Public trust. Private trust. And the world’s most trusted roots. XenMobile Server GPKI support includes DigiCert Managed PKI, also referred to as MPKI. Background: XenMobile Server GPKI support includes DigiCert Managed PKI, also referred…
-
CVE-2022-22954 VMware Workspace ONE Access and Identity Manager encountered server-side template injection vulnerability (6 April 2022)
Preface: Several vulnerabilities in VMware products (CVE-2022-22954, CVE-2022-22955, CVE-2022-22956, CVE-2022-22957, and CVE-2022-22958) are reported to be at high risk of being exploited. System administrators should immediately install patches to affected systems to reduce the risk of cyber-attacks. Background: VMware Workspace ONE is an intelligence-driven digital workspace platform that enables you to simply and securely deliver…
-
About CVE-2022-28796 – A design flaw was found in transaction[.]c on Linux (8th Apr 2022)
Preface: JBD2 is the kernel thread of the ext4 file system. It often experiences the shadow (BH_Shadow) state during its use, which can affect the system performance. To solve this problem, Alibaba Cloud Linux 2 provides an interface in version 4.19. 81-17. Background: Ext3 would call an allocator for each blockA 100MB file would need…
-
About CVE-2022-22519: CODESYS V3 runtime systems (CmpWebServer) encounter buffer-over-read (7th April 2022)
Preface: President Biden’s Executive Order is modernizing the Federal Government defenses and improving the security of widely-used technology. On March 2022, he urged U.S. companies operating critical infrastructure, including in the energy sector, to harden their digital defenses. Background: CODESYS, formerly known as CoDeSys, is an acronym for Controller Development System, an Integrated Development Environment…
-
About CVE-2022-28390 – Linux kernel 5.17.1 found design flaw in can/usb interface driver (4th Apr 2022)
Preface: If the workstation is running in Linux kernel 5.17.1, due to this vulnerability (CVE-2022-28390). The adjacent communications peer device will be at risk. As a result, it allowing an attacker to execute arbitrary code to adjacent communications peer device. Background: The CANbus USB adapter connects a CANbus to the USB port of a PC…
-
About CVE-2022-26912 : Microsoft Edge privilege escalation (5th Apr, 2022)
Preface: Chromium is a free and open-source web browser project, principally developed and maintained by Google. This codebase provides the vast majority of code for the Google Chrome browser, which is proprietary software and has some additional features. The new Microsoft Edge is based on Chromium and was released on January 15, 2020. It is…
-
CVE-2022-28356 – Design weakness found on af_llc[.]c (in the Linux kernel before 5.17.1) -2nd Apr 2022
Preface: IEEE 802.2 provides two connectionless and one connection-oriented operational modes:– Type 1 is an unacknowledged connectionless mode for a datagram service.– Type 2 is a connection-oriented operational mode.– Type 3 is an acknowledged connectionless service. It supports point-to-point communication only. Background: af_llc[.]c (LLC User Interface SAPs):Description: Functions in this module are implementation of socket…
-
About CVE-2022-0998: Linux Kernel’s virtio device driver design weakness (30th Mar 2022)
-
CVE-2022-22948 – VMware vCenter Server updates address an information disclosure vulnerability 29th Mar, 2022
Preface: Security misconfiguration can happen at any level of an application stack, including the network services, platform, web server, application server, database, frameworks, custom code, and pre-installed virtual machines, containers, or storage. Automated scanners are useful for detecting misconfigurations, use of default accounts or configurations, unnecessary services, legacy options, etc. Background: vSphere is a product…