ALAS2LIVEPATCH-2022-075

Related Vulnerabilities: CVE-2021-4155  

A data leak flaw was found in the way XFS_IOC_ALLOCSP IOCTL in the XFS filesystem allowed for size increase of files with unaligned size. A local attacker could use this flaw to leak data on the XFS filesystem otherwise not accessible to them. (CVE-2021-4155)

ALAS2LIVEPATCH-2022-075


Amazon Linux 2 Security Advisory: ALASLIVEPATCH-2022-075
Advisory Release Date: 2022-03-01 17:51 Pacific
Advisory Updated Date: 2022-03-03 02:22 Pacific
Severity: Important
References: CVE-2021-4155 

Issue Overview:

A data leak flaw was found in the way XFS_IOC_ALLOCSP IOCTL in the XFS filesystem allowed for size increase of files with unaligned size. A local attacker could use this flaw to leak data on the XFS filesystem otherwise not accessible to them. (CVE-2021-4155)


Affected Packages:

kernel-livepatch-4.14.256-197.484


Issue Correction:
Please ensure you have live patching enabled.
Run yum update kernel-livepatch-4.14.256-197.484 to update your system.

New Packages:
src:
    kernel-livepatch-4.14.256-197.484-1.0-2.amzn2.src

x86_64:
    kernel-livepatch-4.14.256-197.484-1.0-2.amzn2.x86_64
    kernel-livepatch-4.14.256-197.484-debuginfo-1.0-2.amzn2.x86_64