ALINUX2-SA-2024%3A0024
Package updates are available for Alibaba Cloud Linux 2.1903 that fix the following vulnerabilities: CVE-2022-27635: Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access. CVE-2022-36351: Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an unauthenticated user to potentially enable denial of service via adjacent access. CVE-2022-38076: Improper input validation in some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow an authenticated user to potentially enable escalation of privilege via local access. CVE-2022-40964: Improper access control for some Intel(R) PROSet/Wireless WiFi and Killer(TM) WiFi software may allow a privileged user to potentially enable escalation of privilege via local access. CVE-2022-46329: Protection mechanism failure for some Intel(R) PROSet/Wireless WiFi software may allow a privileged user to potentially enable escalation of privilege via local access.
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | linux-firmware |
Timeline
- Aug 7, 2024 CVE Published
- Aug 7, 2024 CVE Updated
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-36351 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-46329 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-38076 advisory
- ALINUX2-SA-2024:0024: linux-firmware security update (Important) advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-27635 advisory
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2022-40964 advisory