{"affected":[{"ecosystem_specific":{"binaries":[{"kernel-livepatch-5_3_18-24_61-default":"13-150200.2.1"}]},"package":{"ecosystem":"SUSE:Linux Enterprise Live Patching 15 SP2","name":"kernel-livepatch-SLE15-SP2_Update_12","purl":"pkg:rpm/suse/kernel-livepatch-SLE15-SP2_Update_12&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2015%20SP2"},"ranges":[{"events":[{"introduced":"0"},{"fixed":"13-150200.2.1"}],"type":"ECOSYSTEM"}]}],"aliases":[],"details":"This update for the Linux Kernel 5.3.18-24_61 fixes several issues.\n\nThe following security issues were fixed:\n\n- CVE-2022-0492: Fixed a privilege escalation related to cgroups v1 release_agent feature, which allowed bypassing namespace isolation unexpectedly (bsc#1195543).\n- CVE-2022-0487: A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove() in drivers/memstick/host/rtsx_usb_ms.c (bsc#1194516).\n","id":"SUSE-SU-2022:1035-1","modified":"2022-03-30T07:07:08Z","published":"2022-03-30T07:07:08Z","references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2022/suse-su-20221035-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1195908"},{"type":"REPORT","url":"https://bugzilla.suse.com/1195949"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-0487"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2022-0492"}],"related":["CVE-2022-0487","CVE-2022-0492"],"summary":"Security update for the Linux Kernel (Live Patch 12 for SLE 15 SP2)","upstream":["CVE-2022-0487","CVE-2022-0492"]}