当前位置:网站首页>Cloud security daily 220630: the IBM data protection platform has found an arbitrary code execution vulnerability, which needs to be upgraded as soon as possible
Cloud security daily 220630: the IBM data protection platform has found an arbitrary code execution vulnerability, which needs to be upgraded as soon as possible
2022-07-01 00:04:00 【TechWeb】
IBM Spectrum Protect Plus Is the U.S. IBM A set of data protection platform of the company . The platform provides a single point of control and management for enterprises , And support the virtual of all scales 、 Physical and cloud environments for backup and recovery .
6 month 29 Japan ,IBM An emergency security update has been released , Repair the IBM Spectrum Protect Plus Some important vulnerabilities found in the data protection platform . Here are the details of the vulnerability :
Vulnerability Details
source :https://www.ibm.com/support/pages/node/6596971
1.CVE-2021-4154 CVSS score :8.8 severity : serious
Linux The kernel may allow local authenticated attackers to gain elevated privileges on the system , This is due to the kernel/cgroup/cgroup-v1.c Medium cgroup1_parse_param Found in the use-after-free Caused by vulnerability . By using fsconfig syscall Parameters , An attacker can exploit this vulnerability to elevate privileges .
2.CVE-2021-44733 CVSS score :8.4 severity : serious
Linux Kernel It may allow local attackers to execute arbitrary code on the system , This is from TEE In the subsystem drivers/tee/tee_shm.c Medium use-after-free Defects caused by . By performing a special procedure , An attacker can use this vulnerability to execute arbitrary code or cause a denial of service condition on the system .
3.CVE-2021-44733 CVSS score :8.4 severity : serious
Linux Kernel It may allow local attackers to execute arbitrary code on the system , This is from kernel/bpf/stackmap.c Medium prealloc_elems_and_freelist Function eBPF Multiplicative integer overflow . By sending a special request , An attacker can exploit this vulnerability to execute arbitrary code on the system .
4.CVE-2021-44733 CVSS score :8.4 severity : serious
Linux Kernel It may allow local attackers to execute arbitrary code on the system , This is from drivers/infiniband/core/ucma.c Medium use-after-free Defects caused by . By sending a special request , An attacker can use this vulnerability to execute arbitrary code or cause a denial of service condition on the system .
5.CVE-2022-0847 CVSS score :7.8 severity : important
because copy_page_to_iter_pipe and push_pipe Improper function initialization ,Linux The kernel may allow local authenticated attackers to gain elevated privileges on the system . By writing pages in the page cache supported by read-only files , An authenticated attacker can use this vulnerability to gain elevated privileges .
6.CVE-2022-0492 CVSS score :7.8 severity : important
Linux Kernel It may allow an attacker with local authentication to gain elevated privileges on the system , This is from cgroups v1 release_agent Caused by defects in the function . By sending a special request , An authenticated attacker can use this vulnerability to gain elevated privileges and accidentally bypass namespace isolation .
7.CVE-2022-1011 CVSS score :7.8 severity : important
Linux Kernel It may allow an attacker with local authentication to gain elevated privileges on the system , This is from FUSE In the file system use-after-free Defects caused by . By using write() Function to send a special request , An authenticated attacker can exploit this vulnerability to gain unauthorized access FUSE Some data in the file system , So as to obtain the elevated permission .
8.CVE-2021-4157 CVSS score :7.8 severity : important
Linux The kernel may allow local authenticated attackers to gain elevated privileges on the system , This is from NFS Caused by an out of Bounds Write defect in the subsystem . By sending a special request , An authenticated attacker can use this vulnerability to gain elevated privileges or crash the system .
9.CVE-2022-0185 CVSS score :7.8 severity : important
Linux The kernel is vulnerable to heap based buffer overflows , This is from fs/fs_context.c in legacy_parse_param Function caused by integer underflow . By sending a special request , An authenticated local attacker can overflow the buffer and root Permission to execute arbitrary code on the system .
Affected products and versions
IBM Spectrum Protect Plus 10.1.0-10.1.10.2 edition
Solution
about Linux and Windows platform :
upgrade Spectrum Protect Plus to 10.1.11 Version repairable
View more vulnerability information And upgrade, please visit the official website :
https://www.ibm.com/blogs/psirt/
边栏推荐
- How to open a stock account? Is it safe to open a mobile account
- 2022-06-30:以下golang代码输出什么?A:0;B:2;C:运行错误。 package main import “fmt“ func main()
- E-commerce seckill system
- Techo youth 2022 academic year college open class: behind the live broadcast of Lianmai, explore how to apply audio and video technology
- BeanUtils. Copyproperties() vs. mapstruct
- CTFSHOW权限维持篇
- [leetcode] [SQL] notes
- New trend of embedded software development: Devops
- Red Hat将在Project Atomic上运用容器负载服务器
- Dell r720 server installation network card Broadcom 5720 driver
猜你喜欢

Which is better, server rental or hosting services in the United States?

Analysis of 8253a register

Bridge emqx cloud data to AWS IOT through the public network

New trends of China's national tide development in 2022

Prospects of world digitalization and machine intelligence in the next decade

QQmlApplicationEngine failed to load component qrc:/main. qml:-1 No such file or directory

How to use dataant to monitor Apache APIs IX

MaxPool2d详解--在数组和图像中的应用

5g smart building solution 2021

When is it appropriate to replace a virtual machine with a virtual machine?
随机推荐
Rust controls Dajiang programmable UAV Tello
Red hat will apply container load server on project atomic
Advanced mathematical modeling
Error when starting PHP: [pool www] cannot get uid for user '@php_ fpm_ [email protected]’
[NLP] [textcnn] text classification
lvm-snapshot:基于LVM快照的备份之准备工作
Rust book materials - yazhijia Library
5G智慧建筑解决方案2021
E-commerce seckill system
Quick start of wechat applet -- project introduction
Vmware16 installing win11 virtual machine (the most complete step + stepping on the pit)
SSM integration process (integration configuration, function module development, interface test)
Summer Challenge [FFH] harmonyos mobile phone remote control Dayu development board camera
BeanUtils. Copyproperties() vs. mapstruct
Never use redis expired monitoring to implement scheduled tasks!
C# /platform:anycpu32bitpreferred 只能与 /t:exe、/t:winexe 和 /t:appcontainerexe 一起使用
leetcode 474. Ones and zeroes (medium)
2022-06-30: what does the following golang code output? A:0; B:2; C: Running error. package main import “fmt“ func main()
HP 惠普笔记本电脑 禁用触摸板 在插入鼠标后
NATs cluster deployment