Database/Kernel, userspace & hypervisor
util-linux (chfn/chsh): Partial disclosure of arbitrary files via libreadline in setuid chfn/chsh
CVSS 5.5CVE-2022-0563Kernel, userspace & hypervisorcurated
Impact
Partial disclosure of arbitrary files via libreadline in setuid chfn/chsh
Who can reach it
Local user
What to do
Package update; no reboot
References
Related entries
- KVM: NULL pointer dereference in kvm_irq_delivery_to_apic_fast() - guest crashes the hostCVE-2022-2153 · KVMMedium
- Linux kernel (mm anon_vma): Use-after-free from leaf anon_vma double reuse - memory corruption / privesc primitiveCVE-2022-42703 · Linux kernel (mm anon_vma)Medium
- Linux kernel (KASLR): EntryBleed: prefetch side channel defeats KASLR even with KPTICVE-2022-4543 · Linux kernel (KASLR)Medium
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A NULL pointer dereference in the amdkfd (KFD computeCVE-2022-49055 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Medium
- Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd): A race condition or locking defect in the amdkfd (KFDCVE-2022-49133 · Linux kernel amdkfd (KFD compute driver, /dev/kfd) (drm/amdkfd)Medium
- Linux kernel (drivers/vfio/pci): Whoever holds the VFIO device fd for a passed-through PCI function can make the hostCVE-2022-49219 · Linux kernel (drivers/vfio/pci)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.