<?xml version="1.0" encoding="UTF-8"?>
<cvrfdoc xmlns:xsd="http://www.w3.org/2001/XMLSchema" xmlns:cpe="http://cpe.mitre.org/language/2.0" xmlns:cvrf="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf" xmlns:cvrf-common="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/common" xmlns:cvssv2="http://scap.nist.gov/schema/cvss-v2/1.0" xmlns:cvssv3="https://www.first.org/cvss/cvss-v3.0.xsd" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:ns0="http://purl.org/dc/elements/1.1/" xmlns:prod="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod" xmlns:scap-core="http://scap.nist.gov/schema/scap-core/1.0" xmlns:sch="http://purl.oclc.org/dsdl/schematron" xmlns:vuln="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/cvrf">
  <DocumentTitle xml:lang="en">Security update for the Linux Kernel</DocumentTitle>
  <DocumentType>SUSE Patch</DocumentType>
  <DocumentPublisher Type="Vendor">
    <ContactDetails>security@suse.de</ContactDetails>
    <IssuingAuthority>SUSE Security Team</IssuingAuthority>
  </DocumentPublisher>
  <DocumentTracking>
    <Identification>
      <ID>openSUSE-SU-2022:1037-1</ID>
    </Identification>
    <Status>Final</Status>
    <Version>1</Version>
    <RevisionHistory>
      <Revision>
        <Number>1</Number>
        <Date>2022-03-30T07:37:00Z</Date>
        <Description>current</Description>
      </Revision>
    </RevisionHistory>
    <InitialReleaseDate>2022-03-30T07:37:00Z</InitialReleaseDate>
    <CurrentReleaseDate>2022-03-30T07:37:00Z</CurrentReleaseDate>
    <Generator>
      <Engine>cve-database/bin/generate-cvrf.pl</Engine>
      <Date>2017-02-24T01:00:00Z</Date>
    </Generator>
  </DocumentTracking>
  <DocumentNotes>
    <Note Title="Topic" Type="Summary" Ordinal="1" xml:lang="en">Security update for the Linux Kernel</Note>
    <Note Title="Details" Type="General" Ordinal="2" xml:lang="en">The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security and bugfixes.


The following security bugs were fixed:

- CVE-2022-25636: Fixed an issue which allowed a local users to gain privileges because of a heap out-of-bounds write in nf_dup_netdev.c, related to nf_tables_offload (bsc#1196299).
- CVE-2022-26490: Fixed a buffer overflow in the st21nfca driver. An attacker with adjacent NFC access could trigger crash the system or corrupt system memory (bsc#1196830).
- CVE-2022-0487: A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove() in drivers/memstick/host/rtsx_usb_ms.c (bsc#1194516).
- CVE-2022-24448: Fixed an issue if an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR should have occured, but the server instead returned uninitialized data in the file descriptor (bsc#1195612).
- CVE-2022-0617: Fixed a null pointer dereference in UDF file system functionality. A local user could crash the system by triggering udf_file_write_iter() via a malicious UDF image. (bsc#1196079)
- CVE-2022-0644: Fixed a denial of service by a local user. A assertion failure could be triggered in kernel_read_file_from_fd(). (bsc#1196155)
- CVE-2022-25258: The USB Gadget subsystem lacked certain validation of interface OS descriptor requests, which could have lead to memory corruption (bsc#1196096).
- CVE-2022-24958: drivers/usb/gadget/legacy/inode.c mishandled dev-&gt;buf release (bsc#1195905).
- CVE-2022-24959: Fixed a memory leak in yam_siocdevprivate() in drivers/net/hamradio/yam.c (bsc#1195897).
- CVE-2021-44879: In gc_data_segment() in fs/f2fs/gc.c, special files were not considered, which lead to a move_data_page NULL pointer dereference (bsc#1195987).
- CVE-2021-0920: Fixed a local privilege escalation due to a use-after-free vulnerability in unix_scm_to_skb of af_unix (bsc#1193731).
- CVE-2021-39657: Fixed an information leak in the Universal Flash Storage subsystem (bsc#1193864).

The following non-security bugs were fixed:

- ALSA: intel_hdmi: Fix reference to PCM buffer address (git-fixes).
- ARM: 9182/1: mmu: fix returns from early_param() and __setup() functions (git-fixes).
- ARM: Fix kgdb breakpoint for Thumb2 (git-fixes).
- ASoC: cs4265: Fix the duplicated control name (git-fixes).
- ASoC: ops: Shift tested values in snd_soc_put_volsw() by +min (git-fixes).
- ASoC: rt5668: do not block workqueue if card is unbound (git-fixes).
- ASoC: rt5682: do not block workqueue if card is unbound (git-fixes).
- Bluetooth: btusb: Add missing Chicony device for Realtek RTL8723BE (bsc#1196779).
- EDAC/altera: Fix deferred probing (bsc#1178134).
- HID: add mapping for KEY_ALL_APPLICATIONS (git-fixes).
- HID: add mapping for KEY_DICTATE (git-fixes).
- Hand over the maintainership to SLE15-SP3 maintainers
- IB/hfi1: Correct guard on eager buffer deallocation (git-fixes).
- IB/hfi1: Fix early init panic (git-fixes).
- IB/hfi1: Fix leak of rcvhdrtail_dummy_kvaddr (git-fixes).
- IB/hfi1: Insure use of smp_processor_id() is preempt disabled (git-fixes).
- IB/rdmavt: Validate remote_addr during loopback atomic tests (git-fixes).
- Input: clear BTN_RIGHT/MIDDLE on buttonpads (git-fixes).
- Input: elan_i2c - fix regulator enable count imbalance after suspend/resume (git-fixes).
- Input: elan_i2c - move regulator_[en|dis]able() out of elan_[en|dis]able_power() (git-fixes).
- RDMA/bnxt_re: Scan the whole bitmap when checking if 'disabling RCFW with pending cmd-bit' (git-fixes).
- RDMA/cma: Do not change route.addr.src_addr outside state checks (bsc#1181147).
- RDMA/cma: Let cma_resolve_ib_dev() continue search even after empty entry (git-fixes).
- RDMA/cma: Remove open coding of overflow checking for private_data_len (git-fixes).
- RDMA/core: Do not infoleak GRH fields (git-fixes).
- RDMA/core: Let ib_find_gid() continue search even after empty entry (git-fixes).
- RDMA/cxgb4: Set queue pair state when being queried (git-fixes).
- RDMA/hns: Validate the pkey index (git-fixes).
- RDMA/ib_srp: Fix a deadlock (git-fixes).
- RDMA/mlx4: Do not continue event handler after memory allocation failure (git-fixes).
- RDMA/rtrs-clt: Fix possible double free in error case (jsc#SLE-15176).
- RDMA/rxe: Fix a typo in opcode name (git-fixes).
- RDMA/siw: Fix broken RDMA Read Fence/Resume logic (git-fixes).
- RDMA/uverbs: Check for null return of kmalloc_array (git-fixes).
- RDMA/uverbs: Remove the unnecessary assignment (git-fixes).
- Revert 'USB: serial: ch341: add new Product ID for CH341A' (git-fixes).
- SUNRPC: avoid race between mod_timer() and del_timer_sync() (bnc#1195403).
- USB: gadget: validate endpoint index for xilinx udc (git-fixes).
- USB: gadget: validate interface OS descriptor requests (git-fixes).
- USB: hub: Clean up use of port initialization schemes and retries (git-fixes).
- USB: serial: option: add Telit LE910R1 compositions (git-fixes).
- USB: serial: option: add support for DW5829e (git-fixes).
- USB: zaurus: support another broken Zaurus (git-fixes).
- arm64: dts: rockchip: Switch RK3399-Gru DP to SPDIF output (git-fixes).
- asix: fix uninit-value in asix_mdio_read() (git-fixes).
- ata: pata_hpt37x: disable primary channel on HPT371 (git-fixes).
- batman-adv: Do not expect inter-netns unique iflink indices (git-fixes).
- batman-adv: Request iflink once in batadv-on-batadv check (git-fixes).
- batman-adv: Request iflink once in batadv_get_real_netdevice (git-fixes).
- blk-mq: do not free tags if the tag_set is used by other device in queue initialztion (bsc#1193787).
- bnxt_en: Fix active FEC reporting to ethtool (jsc#SLE-16649).
- bnxt_en: Fix incorrect multicast rx mask setting when not requested (git-fixes).
- bnxt_en: Fix occasional ethtool -t loopback test failures (git-fixes).
- bnxt_en: Fix offline ethtool selftest with RDMA enabled (git-fixes).
- bonding: force carrier update when releasing slave (git-fixes).
- can: gs_usb: change active_channels's type from atomic_t to u8 (git-fixes).
- cgroup-v1: Correct privileges check in release_agent writes (bsc#1196723).
- cgroup/cpuset: Fix 'suspicious RCU usage' lockdep warning (bsc#1196868).
- clk: jz4725b: fix mmc0 clock gating (git-fixes).
- cpufreq: schedutil: Use kobject release() method to free (git-fixes)
- cpuset: Fix the bug that subpart_cpus updated wrongly in update_cpumask() (bsc#1196866).
- cputime, cpuacct: Include guest time in user time in (git-fixes)
- dma-direct: Fix potential NULL pointer dereference (bsc#1196472 ltc#192278).
- dma-mapping: Allow mixing bypass and mapped DMA operation (bsc#1196472 ltc#192278).
- dmaengine: shdma: Fix runtime PM imbalance on error (git-fixes).
- drm/amdgpu: disable MMHUB PG for Picasso (git-fixes).
- drm/edid: Always set RGB444 (git-fixes).
- drm/i915/dg1: Wait for pcode/uncore handshake at startup (bsc#1195211).
- drm/i915/gen11+: Only load DRAM information from pcode (bsc#1195211).
- drm/i915: Nuke not needed members of dram_info (bsc#1195211).
- drm/i915: Remove memory frequency calculation (bsc#1195211).
- drm/i915: Rename is_16gb_dimm to wm_lv_0_adjust_needed (bsc#1195211).
- efivars: Respect 'block' flag in efivar_entry_set_safe() (git-fixes).
- exfat: fix i_blocks for files truncated over 4 GiB (git-fixes).
- exfat: fix incorrect loading of i_blocks for large files (git-fixes).
- firmware: arm_scmi: Remove space in MODULE_ALIAS name (git-fixes).
- gpio: rockchip: Reset int_bothedge when changing trigger (git-fixes).
- gpio: tegra186: Fix chip_data type confusion (git-fixes).
- gtp: remove useless rcu_read_lock() (git-fixes).
- hamradio: fix macro redefine warning (git-fixes).
- i2c: bcm2835: Avoid clock stretching timeouts (git-fixes).
- iavf: Fix missing check for running netdev (git-fixes).
- ice: initialize local variable 'tlv' (jsc#SLE-12878).
- igc: igc_read_phy_reg_gpy: drop premature return (git-fixes).
- igc: igc_write_phy_reg_gpy: drop premature return (git-fixes).
- iio: Fix error handling for PM (git-fixes).
- iio: adc: ad7124: fix mask used for setting AIN_BUFP &amp; AIN_BUFM bits (git-fixes).
- iio: adc: men_z188_adc: Fix a resource leak in an error handling path (git-fixes).
- ixgbe: xsk: change !netif_carrier_ok() handling in ixgbe_xmit_zc() (git-fixes).
- mac80211: fix forwarded mesh frames AC &amp; queue selection (git-fixes).
- mac80211_hwsim: initialize ieee80211_tx_info at hw_scan_work (git-fixes).
- mac80211_hwsim: report NOACK frames in tx_status (git-fixes).
- mask out added spinlock in rndis_params (git-fixes).
- net/mlx5: Fix possible deadlock on rule deletion (git-fixes).
- net/mlx5: Fix wrong limitation of metadata match on ecpf (git-fixes).
- net/mlx5: Update the list of the PCI supported devices (git-fixes).
- net/mlx5: Update the list of the PCI supported devices (git-fixes).
- net/mlx5e: Fix modify header actions memory leak (git-fixes).
- net/mlx5e: Fix page DMA map/unmap attributes (bsc#1196468).
- net/mlx5e: Fix wrong return value on ioctl EEPROM query failure (git-fixes).
- net/mlx5e: TC, Reject rules with drop and modify hdr action (git-fixes).
- net/mlx5e: TC, Reject rules with forward and drop actions (git-fixes).
- net/mlx5e: kTLS, Use CHECKSUM_UNNECESSARY for device-offloaded packets (jsc#SLE-15172).
- net/sched: act_ct: Fix flow table lookup after ct clear or switching zones (jsc#SLE-15172).
- net: dsa: mv88e6xxx: MV88E6097 does not support jumbo configuration (git-fixes).
- net: ethernet: ti: cpsw: disable PTPv1 hw timestamping advertisement (git-fixes).
- net: fix up skbs delta_truesize in UDP GRO frag_list (bsc#1176447).
- net: hns3: Clear the CMDQ registers before unmapping BAR region (git-fixes).
- net: sfc: Replace in_interrupt() usage (git-fixes).
- net: tipc: validate domain record count on input (bsc#1195254).
- net: usb: cdc_mbim: avoid altsetting toggling for Telit FN990 (git-fixes).
- netfilter: nf_tables: fix memory leak during stateful obj update (bsc#1176447).
- netsec: ignore 'phy-mode' device property on ACPI systems (git-fixes).
- nfp: flower: Fix a potential leak in nfp_tunnel_add_shared_mac() (git-fixes).
- nl80211: Handle nla_memdup failures in handle_nan_filter (git-fixes).
- ntb: intel: fix port config status offset for SPR (git-fixes).
- nvme-multipath: use vmalloc for ANA log buffer (bsc#1193787).
- nvme-rdma: fix possible use-after-free in transport error_recovery work (git-fixes).
- nvme-tcp: fix possible use-after-free in transport error_recovery work (git-fixes).
- nvme: fix a possible use-after-free in controller reset during load (git-fixes).
- powerpc/dma: Fallback to dma_ops when persistent memory present (bsc#1196472 ltc#192278). Update config files.
- powerpc/fadump: register for fadump as early as possible (bsc#1179439 ltc#190038).
- powerpc/mm: Remove dcache flush from memory remove (bsc#1196433 ltc#196449).
- powerpc/powernv/memtrace: Fix dcache flushing (bsc#1196433 ltc#196449).
- powerpc/pseries/iommu: Fix window size for direct mapping with pmem (bsc#1196472 ltc#192278).
- sched/core: Mitigate race (git-fixes)
- scsi: bnx2fc: Flush destroy_work queue before calling bnx2fc_interface_put() (git-fixes).
- scsi: bnx2fc: Make bnx2fc_recv_frame() mp safe (git-fixes).
- scsi: lpfc: Terminate string in lpfc_debugfs_nvmeio_trc_write() (git-fixes).
- scsi: nsp_cs: Check of ioremap return value (git-fixes).
- scsi: qedf: Fix potential dereference of NULL pointer (git-fixes).
- scsi: smartpqi: Add PCI IDs (bsc#1196627).
- scsi: ufs: Fix race conditions related to driver data (git-fixes).
- selftests: mlxsw: tc_police_scale: Make test more robust (bsc#1176774).
- soc: fsl: Correct MAINTAINERS database (QUICC ENGINE LIBRARY) (git-fixes).
- soc: fsl: Correct MAINTAINERS database (SOC) (git-fixes).
- soc: fsl: qe: Check of ioremap return value (git-fixes).
- spi: spi-zynq-qspi: Fix a NULL pointer dereference in zynq_qspi_exec_mem_op() (git-fixes).
- sr9700: sanity check for packet length (bsc#1196836).
- tracing: Fix return value of __setup handlers (git-fixes).
- tty: n_gsm: fix encoding of control signal octet bit DV (git-fixes).
- tty: n_gsm: fix proper link termination after failed open (git-fixes).
- usb: dwc2: use well defined macros for power_down (git-fixes).
- usb: dwc3: gadget: Let the interrupt handler disable bottom halves (git-fixes).
- usb: dwc3: pci: Fix Bay Trail phy GPIO mappings (git-fixes).
- usb: gadget: rndis: add spinlock for rndis response list (git-fixes).
- usb: hub: Fix usb enumeration issue due to address0 race (git-fixes).
- vrf: Fix fast path output packet handling with async Netfilter rules (git-fixes).
- xhci: Prevent futile URB re-submissions due to incorrect return value (git-fixes).
- xhci: re-initialize the HC during resume if HCE was set (git-fixes).
</Note>
    <Note Title="Terms of Use" Type="Legal Disclaimer" Ordinal="3" xml:lang="en">The CVRF data is provided by SUSE under the Creative Commons License 4.0 with Attribution (CC-BY-4.0).</Note>
    <Note Title="Patchnames" Type="Details" Ordinal="4" xml:lang="en">openSUSE-SLE-15.3-2022-1037</Note>
  </DocumentNotes>
  <DocumentDistribution xml:lang="en">Copyright SUSE LLC under the Creative Commons License 4.0 with Attribution (CC-BY-4.0)</DocumentDistribution>
  <DocumentReferences>
    <Reference Type="Self">
      <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/</URL>
      <Description>E-Mail link for openSUSE-SU-2022:1037-1</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/support/security/rating/</URL>
      <Description>SUSE Security Ratings</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1176447</URL>
      <Description>SUSE Bug 1176447</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1176774</URL>
      <Description>SUSE Bug 1176774</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1178134</URL>
      <Description>SUSE Bug 1178134</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1179439</URL>
      <Description>SUSE Bug 1179439</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1181147</URL>
      <Description>SUSE Bug 1181147</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1191428</URL>
      <Description>SUSE Bug 1191428</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1192273</URL>
      <Description>SUSE Bug 1192273</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1193731</URL>
      <Description>SUSE Bug 1193731</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1193787</URL>
      <Description>SUSE Bug 1193787</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1193864</URL>
      <Description>SUSE Bug 1193864</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1194463</URL>
      <Description>SUSE Bug 1194463</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1194516</URL>
      <Description>SUSE Bug 1194516</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1195211</URL>
      <Description>SUSE Bug 1195211</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1195254</URL>
      <Description>SUSE Bug 1195254</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1195403</URL>
      <Description>SUSE Bug 1195403</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1195612</URL>
      <Description>SUSE Bug 1195612</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1195897</URL>
      <Description>SUSE Bug 1195897</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1195905</URL>
      <Description>SUSE Bug 1195905</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1195939</URL>
      <Description>SUSE Bug 1195939</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1195949</URL>
      <Description>SUSE Bug 1195949</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1195987</URL>
      <Description>SUSE Bug 1195987</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196079</URL>
      <Description>SUSE Bug 1196079</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196095</URL>
      <Description>SUSE Bug 1196095</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196132</URL>
      <Description>SUSE Bug 1196132</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196155</URL>
      <Description>SUSE Bug 1196155</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196299</URL>
      <Description>SUSE Bug 1196299</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196301</URL>
      <Description>SUSE Bug 1196301</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196433</URL>
      <Description>SUSE Bug 1196433</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196468</URL>
      <Description>SUSE Bug 1196468</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196472</URL>
      <Description>SUSE Bug 1196472</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196627</URL>
      <Description>SUSE Bug 1196627</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196723</URL>
      <Description>SUSE Bug 1196723</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196779</URL>
      <Description>SUSE Bug 1196779</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196830</URL>
      <Description>SUSE Bug 1196830</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196836</URL>
      <Description>SUSE Bug 1196836</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196866</URL>
      <Description>SUSE Bug 1196866</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://bugzilla.suse.com/1196868</URL>
      <Description>SUSE Bug 1196868</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-0920/</URL>
      <Description>SUSE CVE CVE-2021-0920 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-39657/</URL>
      <Description>SUSE CVE CVE-2021-39657 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2021-44879/</URL>
      <Description>SUSE CVE CVE-2021-44879 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-0487/</URL>
      <Description>SUSE CVE CVE-2022-0487 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-0617/</URL>
      <Description>SUSE CVE CVE-2022-0617 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-0644/</URL>
      <Description>SUSE CVE CVE-2022-0644 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-24448/</URL>
      <Description>SUSE CVE CVE-2022-24448 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-24958/</URL>
      <Description>SUSE CVE CVE-2022-24958 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-24959/</URL>
      <Description>SUSE CVE CVE-2022-24959 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-25258/</URL>
      <Description>SUSE CVE CVE-2022-25258 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-25636/</URL>
      <Description>SUSE CVE CVE-2022-25636 page</Description>
    </Reference>
    <Reference Type="Self">
      <URL>https://www.suse.com/security/cve/CVE-2022-26490/</URL>
      <Description>SUSE CVE CVE-2022-26490 page</Description>
    </Reference>
  </DocumentReferences>
  <ProductTree xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/prod">
    <Branch Type="Product Family" Name="openSUSE Leap 15.3">
      <Branch Type="Product Name" Name="openSUSE Leap 15.3">
        <FullProductName ProductID="openSUSE Leap 15.3" CPE="cpe:/o:opensuse:leap:15.3">openSUSE Leap 15.3</FullProductName>
      </Branch>
    </Branch>
    <Branch Type="Product Version" Name="cluster-md-kmp-azure-5.3.18-150300.38.50.1">
      <FullProductName ProductID="cluster-md-kmp-azure-5.3.18-150300.38.50.1">cluster-md-kmp-azure-5.3.18-150300.38.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="dlm-kmp-azure-5.3.18-150300.38.50.1">
      <FullProductName ProductID="dlm-kmp-azure-5.3.18-150300.38.50.1">dlm-kmp-azure-5.3.18-150300.38.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="gfs2-kmp-azure-5.3.18-150300.38.50.1">
      <FullProductName ProductID="gfs2-kmp-azure-5.3.18-150300.38.50.1">gfs2-kmp-azure-5.3.18-150300.38.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-azure-5.3.18-150300.38.50.1">
      <FullProductName ProductID="kernel-azure-5.3.18-150300.38.50.1">kernel-azure-5.3.18-150300.38.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-azure-devel-5.3.18-150300.38.50.1">
      <FullProductName ProductID="kernel-azure-devel-5.3.18-150300.38.50.1">kernel-azure-devel-5.3.18-150300.38.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-azure-extra-5.3.18-150300.38.50.1">
      <FullProductName ProductID="kernel-azure-extra-5.3.18-150300.38.50.1">kernel-azure-extra-5.3.18-150300.38.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-azure-livepatch-devel-5.3.18-150300.38.50.1">
      <FullProductName ProductID="kernel-azure-livepatch-devel-5.3.18-150300.38.50.1">kernel-azure-livepatch-devel-5.3.18-150300.38.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-azure-optional-5.3.18-150300.38.50.1">
      <FullProductName ProductID="kernel-azure-optional-5.3.18-150300.38.50.1">kernel-azure-optional-5.3.18-150300.38.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-devel-azure-5.3.18-150300.38.50.1">
      <FullProductName ProductID="kernel-devel-azure-5.3.18-150300.38.50.1">kernel-devel-azure-5.3.18-150300.38.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-source-azure-5.3.18-150300.38.50.1">
      <FullProductName ProductID="kernel-source-azure-5.3.18-150300.38.50.1">kernel-source-azure-5.3.18-150300.38.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kernel-syms-azure-5.3.18-150300.38.50.1">
      <FullProductName ProductID="kernel-syms-azure-5.3.18-150300.38.50.1">kernel-syms-azure-5.3.18-150300.38.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="kselftests-kmp-azure-5.3.18-150300.38.50.1">
      <FullProductName ProductID="kselftests-kmp-azure-5.3.18-150300.38.50.1">kselftests-kmp-azure-5.3.18-150300.38.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="ocfs2-kmp-azure-5.3.18-150300.38.50.1">
      <FullProductName ProductID="ocfs2-kmp-azure-5.3.18-150300.38.50.1">ocfs2-kmp-azure-5.3.18-150300.38.50.1</FullProductName>
    </Branch>
    <Branch Type="Product Version" Name="reiserfs-kmp-azure-5.3.18-150300.38.50.1">
      <FullProductName ProductID="reiserfs-kmp-azure-5.3.18-150300.38.50.1">reiserfs-kmp-azure-5.3.18-150300.38.50.1</FullProductName>
    </Branch>
    <Relationship ProductReference="cluster-md-kmp-azure-5.3.18-150300.38.50.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:cluster-md-kmp-azure-5.3.18-150300.38.50.1">cluster-md-kmp-azure-5.3.18-150300.38.50.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="dlm-kmp-azure-5.3.18-150300.38.50.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:dlm-kmp-azure-5.3.18-150300.38.50.1">dlm-kmp-azure-5.3.18-150300.38.50.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="gfs2-kmp-azure-5.3.18-150300.38.50.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:gfs2-kmp-azure-5.3.18-150300.38.50.1">gfs2-kmp-azure-5.3.18-150300.38.50.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-azure-5.3.18-150300.38.50.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:kernel-azure-5.3.18-150300.38.50.1">kernel-azure-5.3.18-150300.38.50.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-azure-devel-5.3.18-150300.38.50.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:kernel-azure-devel-5.3.18-150300.38.50.1">kernel-azure-devel-5.3.18-150300.38.50.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-azure-extra-5.3.18-150300.38.50.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:kernel-azure-extra-5.3.18-150300.38.50.1">kernel-azure-extra-5.3.18-150300.38.50.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-azure-livepatch-devel-5.3.18-150300.38.50.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:kernel-azure-livepatch-devel-5.3.18-150300.38.50.1">kernel-azure-livepatch-devel-5.3.18-150300.38.50.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-azure-optional-5.3.18-150300.38.50.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:kernel-azure-optional-5.3.18-150300.38.50.1">kernel-azure-optional-5.3.18-150300.38.50.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-devel-azure-5.3.18-150300.38.50.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:kernel-devel-azure-5.3.18-150300.38.50.1">kernel-devel-azure-5.3.18-150300.38.50.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-source-azure-5.3.18-150300.38.50.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:kernel-source-azure-5.3.18-150300.38.50.1">kernel-source-azure-5.3.18-150300.38.50.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kernel-syms-azure-5.3.18-150300.38.50.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:kernel-syms-azure-5.3.18-150300.38.50.1">kernel-syms-azure-5.3.18-150300.38.50.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="kselftests-kmp-azure-5.3.18-150300.38.50.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:kselftests-kmp-azure-5.3.18-150300.38.50.1">kselftests-kmp-azure-5.3.18-150300.38.50.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="ocfs2-kmp-azure-5.3.18-150300.38.50.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:ocfs2-kmp-azure-5.3.18-150300.38.50.1">ocfs2-kmp-azure-5.3.18-150300.38.50.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
    <Relationship ProductReference="reiserfs-kmp-azure-5.3.18-150300.38.50.1" RelationType="Default Component Of" RelatesToProductReference="openSUSE Leap 15.3">
      <FullProductName ProductID="openSUSE Leap 15.3:reiserfs-kmp-azure-5.3.18-150300.38.50.1">reiserfs-kmp-azure-5.3.18-150300.38.50.1 as a component of openSUSE Leap 15.3</FullProductName>
    </Relationship>
  </ProductTree>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="1">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In unix_scm_to_skb of af_unix.c, there is a possible use after free bug due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-196926917References: Upstream kernel</Note>
    </Notes>
    <CVE>CVE-2021-0920</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:cluster-md-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:dlm-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-extra-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-livepatch-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-optional-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-devel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-source-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-syms-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kselftests-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ocfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:reiserfs-kmp-azure-5.3.18-150300.38.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.9</BaseScoreV2>
        <VectorV2>AV:L/AC:M/Au:N/C:C/I:C/A:C</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>7.8</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-0920.html</URL>
        <Description>CVE-2021-0920</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1193731</URL>
        <Description>SUSE Bug 1193731</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1194463</URL>
        <Description>SUSE Bug 1194463</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1195939</URL>
        <Description>SUSE Bug 1195939</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1199255</URL>
        <Description>SUSE Bug 1199255</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1200084</URL>
        <Description>SUSE Bug 1200084</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="2">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-194696049References: Upstream kernel</Note>
    </Notes>
    <CVE>CVE-2021-39657</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:cluster-md-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:dlm-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-extra-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-livepatch-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-optional-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-devel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-source-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-syms-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kselftests-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ocfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:reiserfs-kmp-azure-5.3.18-150300.38.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>low</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>2.1</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:P/I:N/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>3.3</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-39657.html</URL>
        <Description>CVE-2021-39657</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1193864</URL>
        <Description>SUSE Bug 1193864</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="3">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">In gc_data_segment in fs/f2fs/gc.c in the Linux kernel before 5.16.3, special files are not considered, leading to a move_data_page NULL pointer dereference.</Note>
    </Notes>
    <CVE>CVE-2021-44879</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:cluster-md-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:dlm-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-extra-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-livepatch-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-optional-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-devel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-source-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-syms-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kselftests-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ocfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:reiserfs-kmp-azure-5.3.18-150300.38.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.3</BaseScoreV2>
        <VectorV2>AV:N/AC:M/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2021-44879.html</URL>
        <Description>CVE-2021-44879</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1195987</URL>
        <Description>SUSE Bug 1195987</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="4">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A use-after-free vulnerability was found in rtsx_usb_ms_drv_remove in drivers/memstick/host/rtsx_usb_ms.c in memstick in the Linux kernel. In this flaw, a local attacker with a user privilege may impact system Confidentiality. This flaw affects kernel versions prior to 5.14 rc1.</Note>
    </Notes>
    <CVE>CVE-2022-0487</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:cluster-md-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:dlm-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-extra-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-livepatch-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-optional-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-devel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-source-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-syms-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kselftests-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ocfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:reiserfs-kmp-azure-5.3.18-150300.38.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>2.1</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:P/I:N/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>7</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-0487.html</URL>
        <Description>CVE-2022-0487</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1194516</URL>
        <Description>SUSE Bug 1194516</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1195949</URL>
        <Description>SUSE Bug 1195949</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1198615</URL>
        <Description>SUSE Bug 1198615</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="5">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">A flaw null pointer dereference in the Linux kernel UDF file system functionality was found in the way user triggers udf_file_write_iter function for the malicious UDF image. A local user could use this flaw to crash the system. Actual from Linux kernel 4.2-rc1 till 5.17-rc2.</Note>
    </Notes>
    <CVE>CVE-2022-0617</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:cluster-md-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:dlm-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-extra-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-livepatch-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-optional-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-devel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-source-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-syms-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kselftests-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ocfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:reiserfs-kmp-azure-5.3.18-150300.38.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.9</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:N/I:N/A:C</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-0617.html</URL>
        <Description>CVE-2022-0617</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1196079</URL>
        <Description>SUSE Bug 1196079</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="6">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.</Note>
    </Notes>
    <CVE>CVE-2022-0644</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:cluster-md-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:dlm-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-extra-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-livepatch-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-optional-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-devel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-source-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-syms-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kselftests-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ocfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:reiserfs-kmp-azure-5.3.18-150300.38.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-0644.html</URL>
        <Description>CVE-2022-0644</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1196155</URL>
        <Description>SUSE Bug 1196155</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="7">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in fs/nfs/dir.c in the Linux kernel before 5.16.5. If an application sets the O_DIRECTORY flag, and tries to open a regular file, nfs_atomic_open() performs a regular lookup. If a regular file is found, ENOTDIR should occur, but the server instead returns uninitialized data in the file descriptor.</Note>
    </Notes>
    <CVE>CVE-2022-24448</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:cluster-md-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:dlm-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-extra-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-livepatch-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-optional-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-devel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-source-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-syms-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kselftests-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ocfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:reiserfs-kmp-azure-5.3.18-150300.38.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>1.9</BaseScoreV2>
        <VectorV2>AV:L/AC:M/Au:N/C:P/I:N/A:N</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-24448.html</URL>
        <Description>CVE-2022-24448</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1195612</URL>
        <Description>SUSE Bug 1195612</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="8">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">drivers/usb/gadget/legacy/inode.c in the Linux kernel through 5.16.8 mishandles dev-&gt;buf release.</Note>
    </Notes>
    <CVE>CVE-2022-24958</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:cluster-md-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:dlm-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-extra-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-livepatch-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-optional-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-devel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-source-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-syms-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kselftests-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ocfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:reiserfs-kmp-azure-5.3.18-150300.38.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.6</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-24958.html</URL>
        <Description>CVE-2022-24958</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1195905</URL>
        <Description>SUSE Bug 1195905</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="9">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in the Linux kernel before 5.16.5. There is a memory leak in yam_siocdevprivate in drivers/net/hamradio/yam.c.</Note>
    </Notes>
    <CVE>CVE-2022-24959</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:cluster-md-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:dlm-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-extra-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-livepatch-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-optional-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-devel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-source-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-syms-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kselftests-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ocfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:reiserfs-kmp-azure-5.3.18-150300.38.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>moderate</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>2.1</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:N/I:N/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>5.5</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-24959.html</URL>
        <Description>CVE-2022-24959</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1195897</URL>
        <Description>SUSE Bug 1195897</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="10">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">An issue was discovered in drivers/usb/gadget/composite.c in the Linux kernel before 5.16.10. The USB Gadget subsystem lacks certain validation of interface OS descriptor requests (ones with a large array index and ones associated with NULL function pointer retrieval). Memory corruption might occur.</Note>
    </Notes>
    <CVE>CVE-2022-25258</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:cluster-md-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:dlm-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-extra-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-livepatch-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-optional-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-devel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-source-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-syms-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kselftests-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ocfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:reiserfs-kmp-azure-5.3.18-150300.38.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.9</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:N/I:N/A:C</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>7.8</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-25258.html</URL>
        <Description>CVE-2022-25258</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1196095</URL>
        <Description>SUSE Bug 1196095</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1196132</URL>
        <Description>SUSE Bug 1196132</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="11">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">net/netfilter/nf_dup_netdev.c in the Linux kernel 5.4 through 5.6.10 allows local users to gain privileges because of a heap out-of-bounds write. This is related to nf_tables_offload.</Note>
    </Notes>
    <CVE>CVE-2022-25636</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:cluster-md-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:dlm-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-extra-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-livepatch-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-optional-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-devel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-source-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-syms-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kselftests-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ocfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:reiserfs-kmp-azure-5.3.18-150300.38.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>6.9</BaseScoreV2>
        <VectorV2>AV:L/AC:M/Au:N/C:C/I:C/A:C</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>7.8</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-25636.html</URL>
        <Description>CVE-2022-25636</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1196299</URL>
        <Description>SUSE Bug 1196299</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1196301</URL>
        <Description>SUSE Bug 1196301</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
  <vuln:Vulnerability xmlns="http://docs.oasis-open.org/csaf/ns/csaf-cvrf/v1.2/vuln" Ordinal="12">
    <Notes>
      <Note Title="Vulnerability Description" Type="General" Ordinal="1" xml:lang="en">st21nfca_connectivity_event_received in drivers/nfc/st21nfca/se.c in the Linux kernel through 5.16.12 has EVT_TRANSACTION buffer overflows because of untrusted length parameters.</Note>
    </Notes>
    <CVE>CVE-2022-26490</CVE>
    <ProductStatuses>
      <Status Type="Fixed">
        <ProductID>openSUSE Leap 15.3:cluster-md-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:dlm-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:gfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-extra-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-livepatch-devel-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-azure-optional-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-devel-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-source-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kernel-syms-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:kselftests-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:ocfs2-kmp-azure-5.3.18-150300.38.50.1</ProductID>
        <ProductID>openSUSE Leap 15.3:reiserfs-kmp-azure-5.3.18-150300.38.50.1</ProductID>
      </Status>
    </ProductStatuses>
    <Threats>
      <Threat Type="Impact">
        <Description>important</Description>
      </Threat>
    </Threats>
    <CVSSScoreSets>
      <ScoreSetV2>
        <BaseScoreV2>4.6</BaseScoreV2>
        <VectorV2>AV:L/AC:L/Au:N/C:P/I:P/A:P</VectorV2>
      </ScoreSetV2>
      <ScoreSetV3>
        <BaseScoreV3>7.8</BaseScoreV3>
        <VectorV3>CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H</VectorV3>
      </ScoreSetV3>
    </CVSSScoreSets>
    <Remediations>
      <Remediation Type="Vendor Fix">
        <Description xml:lang="en">To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".
</Description>
        <URL>https://lists.opensuse.org/archives/list/security-announce@lists.opensuse.org/thread/YVOKHN5NCU57OGTEBU36WJRTWHRBUST7/</URL>
      </Remediation>
    </Remediations>
    <References>
      <Reference>
        <URL>https://www.suse.com/security/cve/CVE-2022-26490.html</URL>
        <Description>CVE-2022-26490</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1196830</URL>
        <Description>SUSE Bug 1196830</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1201656</URL>
        <Description>SUSE Bug 1201656</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1201969</URL>
        <Description>SUSE Bug 1201969</Description>
      </Reference>
      <Reference>
        <URL>https://bugzilla.suse.com/1211495</URL>
        <Description>SUSE Bug 1211495</Description>
      </Reference>
    </References>
  </vuln:Vulnerability>
</cvrfdoc>
