SB20250704140 - openEuler 20.03 LTS SP4 update for kernel



SB20250704140 - openEuler 20.03 LTS SP4 update for kernel

Published: July 4, 2025

Security Bulletin ID SB20250704140
Severity
Low
Patch available
YES
Number of vulnerabilities 13
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Low 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 13 secuirty vulnerabilities.


1) Improper locking (CVE-ID: CVE-2022-49814)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to improper locking within the requeue_rx_msgs(), kcm_wait_data(), KCM_STATS_INCR() and kcm_splice_read() functions in net/kcm/kcmsock.c. A local user can perform a denial of service (DoS) attack.


2) Resource management error (CVE-ID: CVE-2022-49917)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the ip_vs_app_net_init() function in net/netfilter/ipvs/ip_vs_app.c. A local user can perform a denial of service (DoS) attack.


3) Memory leak (CVE-ID: CVE-2022-49981)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the hidraw_release() function in drivers/hid/hidraw.c. A local user can perform a denial of service (DoS) attack.


4) Memory leak (CVE-ID: CVE-2022-49982)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the pvr2_hdw_create() function in drivers/media/usb/pvrusb2/pvrusb2-hdw.c. A local user can perform a denial of service (DoS) attack.


5) NULL pointer dereference (CVE-ID: CVE-2022-50080)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the tee_shm_register_user_buf() function in drivers/tee/tee_shm.c. A local user can perform a denial of service (DoS) attack.


6) Out-of-bounds read (CVE-ID: CVE-2022-50094)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to an out-of-bounds read error within the include/trace/events/spmi.h. A local user can perform a denial of service (DoS) attack.


7) Memory leak (CVE-ID: CVE-2022-50203)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the omapdss_init_fbdev() function in arch/arm/mach-omap2/display.c. A local user can perform a denial of service (DoS) attack.


8) Buffer overflow (CVE-ID: CVE-2022-50222)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory corruption within the vc_uniscr_alloc() function in drivers/tty/vt/vt.c. A local user can perform a denial of service (DoS) attack.


9) Resource management error (CVE-ID: CVE-2023-53053)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to resource management error within the ip6erspan_tunnel_xmit() function in net/ipv6/ip6_gre.c, within the erspan_fb_xmit() function in net/ipv4/ip_gre.c. A local user can perform a denial of service (DoS) attack.


10) Memory leak (CVE-ID: CVE-2023-53062)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the smsc95xx_rx_fixup() function in drivers/net/usb/smsc95xx.c. A local user can perform a denial of service (DoS) attack.


11) NULL pointer dereference (CVE-ID: CVE-2023-53066)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to NULL pointer dereference within the qed_iov_configure_min_tx_rate() and qed_iov_handle_trust_change() functions in drivers/net/ethernet/qlogic/qed/qed_sriov.c. A local user can perform a denial of service (DoS) attack.


12) Memory leak (CVE-ID: CVE-2023-53125)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to memory leak within the smsc75xx_rx_fixup() function in drivers/net/usb/smsc75xx.c. A local user can perform a denial of service (DoS) attack.


13) Incorrect calculation (CVE-ID: CVE-2025-38058)

The vulnerability allows a local user to perform a denial of service (DoS) attack.

The vulnerability exists due to incorrect calculation within the __legitimize_mnt() function in fs/namespace.c. A local user can perform a denial of service (DoS) attack.


Remediation

Install update from vendor's website.