Alibaba Security Advisories · February 2022 — Alibaba Security Advisories
12 advisories 11 CVEs 1 EXPLOITED

Alibaba Cloud Linux 2 advisories and cross-source Alibaba/Aliyun CVEs for 2022-02. Mirrored into Vulnetix VDB.

Every advisory below is enriched with the Vulnetix VDB exploit-intelligence chip (hover a CVE ID in the interactive page to see CVSS, EPSS, KEV status, and PoC maturity). 1 is already weaponised in the wild — see the Exploited section.

Advisories

HOTFIX-BA-2022:0002

ALINUX 22022-02-28

HOTFIX-BA-2022:0002: kernel-hotfix bugfix update (Important)

Affected products

ProductStatusVendorPackageEcosystem
kernel-hotfix-7776300-23.al7 affected Alibaba Cloud kernel-hotfix-7776300-23.al7
Upstream advisory

HOTFIX-BA-2022:0003

ALINUX 22022-02-28

HOTFIX-BA-2022:0003: kernel-hotfix bugfix update (Important)

Affected products

ProductStatusVendorPackageEcosystem
kernel-hotfix-7776300-24.1.al7 affected Alibaba Cloud kernel-hotfix-7776300-24.1.al7
Upstream advisory

HOTFIX-BA-2022:0004

ALINUX 22022-02-28

HOTFIX-BA-2022:0004: kernel-hotfix bugfix update (Important)

Affected products

ProductStatusVendorPackageEcosystem
kernel-hotfix-7776300-24.al7 affected Alibaba Cloud kernel-hotfix-7776300-24.al7
Upstream advisory

HOTFIX-BA-2022:0005

ALINUX 22022-02-28

HOTFIX-BA-2022:0005: kernel-hotfix bugfix update (Important)

Affected products

ProductStatusVendorPackageEcosystem
kernel-hotfix-7776300-25.1.al7 affected Alibaba Cloud kernel-hotfix-7776300-25.1.al7
Upstream advisory

HOTFIX-BA-2022:0006

ALINUX 22022-02-28

HOTFIX-BA-2022:0006: kernel-hotfix bugfix update (Important)

Affected products

ProductStatusVendorPackageEcosystem
kernel-hotfix-7776300-22.2.al7 affected Alibaba Cloud kernel-hotfix-7776300-22.2.al7
Upstream advisory

ALINUX2-SA-2022:0012

ALINUX 22022-02-23

ALINUX2-SA-2022:0012: 389-ds-base security and bug fix update (Low)

CVEs:CVE-2021-4091

Affected products

ProductStatusVendorPackageEcosystem
389-ds-base affected Alibaba Cloud 389-ds-base
Upstream advisory

Need live exploit intelligence?

Every CVE above is indexed in the Vulnetix VDB with KEV, EPSS, and PoC maturity. The interactive page surfaces that on hover.