Linux kernel and Windows Telephony Service patched for critical vulnerabilities
Security researchers disclosed two separate operating‑system flaws and released patches. AppGate Threat Advisory Services identified CVE‑2022‑0435, a remote stack overflow in the Linux kernel’s TIPC module that could cause denial‑of‑service or code execution on kernels version 4.8 through 5.17‑rc3. A patch was issued on 10 February 2022.
Separately, a privilege‑escalation issue in the Windows Telephony Service (CVE‑2024‑43626) was found to allow arbitrary code execution via an improperly terminated registry value. Microsoft released an official fix, and 0patch supplied micropatches for a wide range of Windows versions, protecting users even on unsupported releases.