AVG-2680 - log back

AVG-2680 edited at 15 Apr 2022 15:49:24
Advisory qualified
- Yes
+ No
AVG-2680 edited at 15 Apr 2022 15:14:37
Severity
- Unknown
+ Medium
AVG-2680 created at 15 Apr 2022 15:12:36
Packages
+ linux
Issues
+ CVE-2022-0001
+ CVE-2022-0002
Status
+ Fixed
Severity
+ Unknown
Affected
+ 5.16.13.arch1-1
Fixed
+ 5.16.14.arch1-1
Ticket
Advisory qualified
+ Yes
References
+ https://github.com/archlinux/svntogit-packages/commit/161a75ed5bf2639b85cf6bba2acad6ac8e9b2cb5
+ https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00598.html
+ https://www.intel.com/content/www/us/en/developer/articles/technical/software-security-guidance/technical-documentation/branch-history-injection.html
+ https://www.openwall.com/lists/oss-security/2022/03/18/2
Notes
+ haven't yet checked what other "managed runtimes in privileged modes" the SA might be refering to