CVE-2022-3564

Support for security such as Firewalls and securing linux
Post Reply
vvprasadj
Posts: 7
Joined: 2023/07/28 17:12:44

CVE-2022-3564

Post by vvprasadj » 2023/07/31 14:57:28

Fix for CVE-2022-3564 (kernel is Vulnerable) has been released for RHEL 7 on 19 July 2023.
This is not yet available for CentOS.
Does next batch of updates for CentOS 7 contains fix for this?

User avatar
TrevorH
Site Admin
Posts: 33223
Joined: 2009/09/24 10:40:56
Location: Brighton, UK

Re: CVE-2022-3564

Post by TrevorH » 2023/07/31 16:10:20

kernel 3.10.0-1160.95.1.el7.x86_64 is indeed one of the updates that is pending release. Currently stuck on failing CI tests I think.
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke

User avatar
TrevorH
Site Admin
Posts: 33223
Joined: 2009/09/24 10:40:56
Location: Brighton, UK

Re: CVE-2022-3564

Post by TrevorH » 2023/08/03 16:54:16

Just released.
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke

vvprasadj
Posts: 7
Joined: 2023/07/28 17:12:44

Re: CVE-2022-3564

Post by vvprasadj » 2023/08/03 19:22:44

Thank you for the update TrevorH.

pmalenfant
Posts: 3
Joined: 2023/08/24 20:23:28

Re: CVE-2022-3564

Post by pmalenfant » 2023/08/24 20:25:34

I just updated my kernel to 3.10.0-1160.95.1.el7.x86_64, but our security scanner (Kenna) still flags it as containing this CVE.
Could someone please confirm that this kernel contains the patch for the CVE?
Or, is there something different that I need to apply?

Thanks in advance

User avatar
TrevorH
Site Admin
Posts: 33223
Joined: 2009/09/24 10:40:56
Location: Brighton, UK

Re: CVE-2022-3564

Post by TrevorH » 2023/08/24 22:12:18

rpm -q --changelog kernel-$(uname -r) on a system running that kernel says
* Mon Jun 05 2023 Rado Vrbovsky <rvrbovsk@redhat.com> [3.10.0-1160.93.1.el7]
- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}
What does uname -r say on your machine?
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke

User avatar
jlehtone
Posts: 4532
Joined: 2007/12/11 08:17:33
Location: Finland

Re: CVE-2022-3564

Post by jlehtone » 2023/08/25 11:38:44

Does Kenna belong to the group of "some tools" that Red Hat mentions in: https://access.redhat.com/solutions/57665

pmalenfant
Posts: 3
Joined: 2023/08/24 20:23:28

Re: CVE-2022-3564

Post by pmalenfant » 2023/08/25 12:22:02

uname output for my system:

# uname -r
3.10.0-1160.95.1.el7.x86_64

pmalenfant
Posts: 3
Joined: 2023/08/24 20:23:28

Re: CVE-2022-3564

Post by pmalenfant » 2023/08/25 12:28:30

I ran the rpm -q -changelog kernel-$(uname -r) | grep "CVE-2022-3564"
it returns
- Bluetooth: L2CAP: Fix use-after-free caused by l2cap_reassemble_sdu (Wander Lairson Costa) [2152941] {CVE-2022-3564}

I can't attach the entire file -- says too large.

That makes me think this vulnerability should be fixed

User avatar
TrevorH
Site Admin
Posts: 33223
Joined: 2009/09/24 10:40:56
Location: Brighton, UK

Re: CVE-2022-3564

Post by TrevorH » 2023/08/25 12:35:02

Sounds like a problem with the security scanner then.
The future appears to be RHEL or Debian. I think I'm going Debian.
Info for USB installs on http://wiki.centos.org/HowTos/InstallFromUSBkey
CentOS 5 and 6 are deadest, do not use them.
Use the FAQ Luke

Post Reply