Uploaded image for project: 'Lustre'
  1. Lustre
  2. LU-10164

kernel update [SLES12 SP3 4.4.92-6.18]

Details

    • 3
    • 9223372036854775807

    Description

      The SUSE Linux Enterprise 12 SP3 kernel was updated to 4.4.92 to receive various security and bugfixes.

      The following security bugs were fixed:

      • CVE-2017-1000252: The KVM subsystem in the Linux kernel allowed guest OS users to cause a denial of service (assertion failure, and hypervisor hang or crash) via an out-of bounds guest_irq value, related to arch/x86/kvm/vmx.c and virt/kvm/eventfd.c (bnc#1058038).
      • CVE-2017-11472: The acpi_ns_terminate() function in drivers/acpi/acpica/nsutils.c in the Linux kernel did not flush the operand cache and causes a kernel stack dump, which allowed local users to obtain sensitive information from kernel memory and bypass the KASLR protection mechanism (in the kernel through 4.9) via a crafted ACPI table (bnc#1049580).
      • CVE-2017-12134: The xen_biovec_phys_mergeable function in drivers/xen/biomerge.c in Xen might allow local OS guest users to corrupt block device data streams and consequently obtain sensitive memory information, cause a denial of service, or gain host OS privileges by leveraging incorrect block IO merge-ability calculation (bnc#1051790 bsc#1053919).
      • CVE-2017-12153: A security flaw was discovered in the nl80211_set_rekey_data() function in net/wireless/nl80211.c in the Linux kernel This function did not check whether the required attributes are present in a Netlink request. This request can be issued by a user with the CAP_NET_ADMIN capability and may result in a NULL pointer dereference and system crash (bnc#1058410).
      • CVE-2017-12154: The prepare_vmcs02 function in arch/x86/kvm/vmx.c in the Linux kernel did not ensure that the "CR8-load exiting" and "CR8-store exiting" L0 vmcs02 controls exist in cases where L1 omits the "use TPR shadow" vmcs12 control, which allowed KVM L2 guest OS users to obtain read and write access to the hardware CR8 register (bnc#1058507).
      • CVE-2017-13080: Wi-Fi Protected Access (WPA and WPA2) allowed reinstallation of the Group Temporal Key (GTK) during the group key handshake, allowing an attacker within radio range to replay frames from access points to clients (bnc#1056061 1063479 1063667 1063671).
      • CVE-2017-14051: An integer overflow in the qla2x00_sysfs_write_optrom_ctl function in drivers/scsi/qla2xxx/qla_attr.c in the Linux kernel allowed local users to cause a denial of service (memory corruption and system crash) by leveraging root access (bnc#1056588).
      • CVE-2017-14106: The tcp_disconnect function in net/ipv4/tcp.c in the Linux kernel allowed local users to cause a denial of service (__tcp_select_window divide-by-zero error and system crash) by triggering a disconnect within a certain tcp_recvmsg code path (bnc#1056982).
      • CVE-2017-14489: The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel allowed local users to cause a denial of service (panic) by leveraging incorrect length validation (bnc#1059051).
      • CVE-2017-15265: Use-after-free vulnerability in the Linux kernel before 4.14-rc5 allowed local users to have unspecified impact via vectors related to /dev/snd/seq (bnc#1062520).
      • CVE-2017-15649: net/packet/af_packet.c in the Linux kernel allowed local users to gain privileges via crafted system calls that trigger mishandling of packet_fanout data structures, because of a race condition (involving fanout_add and packet_do_bind) that leads to a use-after-free, a different vulnerability than CVE-2017-6346 (bnc#1064388).

      Attachments

        Issue Links

          Activity

            [LU-10164] kernel update [SLES12 SP3 4.4.92-6.18]
            bogl Bob Glossman (Inactive) made changes -
            Link New: This issue is related to LU-10339 [ LU-10339 ]
            mdiep Minh Diep made changes -
            Labels Original: LTS
            pjones Peter Jones made changes -
            Labels New: LTS
            pjones Peter Jones made changes -
            Fix Version/s New: Lustre 2.11.0 [ 13091 ]
            Resolution New: Fixed [ 1 ]
            Status Original: Open [ 1 ] New: Resolved [ 5 ]
            pjones Peter Jones added a comment -

            Landed for 2.11

            pjones Peter Jones added a comment - Landed for 2.11

            Oleg Drokin (oleg.drokin@intel.com) merged in patch https://review.whamcloud.com/29793/
            Subject: LU-10164 kernel: kernel update [SLES12 SP3 4.4.92-6.18]
            Project: fs/lustre-release
            Branch: master
            Current Patch Set:
            Commit: 88a6260068d4fd110c8f56018c2222fb4d245ea0

            gerrit Gerrit Updater added a comment - Oleg Drokin (oleg.drokin@intel.com) merged in patch https://review.whamcloud.com/29793/ Subject: LU-10164 kernel: kernel update [SLES12 SP3 4.4.92-6.18] Project: fs/lustre-release Branch: master Current Patch Set: Commit: 88a6260068d4fd110c8f56018c2222fb4d245ea0
            pjones Peter Jones made changes -
            Fix Version/s New: Lustre 2.10.2 [ 13494 ]

            John L. Hammond (john.hammond@intel.com) merged in patch https://review.whamcloud.com/29825/
            Subject: LU-10164 kernel: kernel update [SLES12 SP3 4.4.92-6.18]
            Project: fs/lustre-release
            Branch: b2_10
            Current Patch Set:
            Commit: 5a3708e38f78d8f3bf853b24b1746891c771ae15

            gerrit Gerrit Updater added a comment - John L. Hammond (john.hammond@intel.com) merged in patch https://review.whamcloud.com/29825/ Subject: LU-10164 kernel: kernel update [SLES12 SP3 4.4.92-6.18] Project: fs/lustre-release Branch: b2_10 Current Patch Set: Commit: 5a3708e38f78d8f3bf853b24b1746891c771ae15

            Bob Glossman (bob.glossman@intel.com) uploaded a new patch: https://review.whamcloud.com/29825
            Subject: LU-10164 kernel: kernel update [SLES12 SP3 4.4.92-6.18]
            Project: fs/lustre-release
            Branch: b2_10
            Current Patch Set: 1
            Commit: 5b7e76d7748d274e3822728ce92f7261dc1edb44

            gerrit Gerrit Updater added a comment - Bob Glossman (bob.glossman@intel.com) uploaded a new patch: https://review.whamcloud.com/29825 Subject: LU-10164 kernel: kernel update [SLES12 SP3 4.4.92-6.18] Project: fs/lustre-release Branch: b2_10 Current Patch Set: 1 Commit: 5b7e76d7748d274e3822728ce92f7261dc1edb44

            Bob Glossman (bob.glossman@intel.com) uploaded a new patch: https://review.whamcloud.com/29793
            Subject: LU-10164 kernel: kernel update [SLES12 SP3 4.4.92-6.18]
            Project: fs/lustre-release
            Branch: master
            Current Patch Set: 1
            Commit: 880dc5e117ba65b392f9d54d4ca53b90e76a1d89

            gerrit Gerrit Updater added a comment - Bob Glossman (bob.glossman@intel.com) uploaded a new patch: https://review.whamcloud.com/29793 Subject: LU-10164 kernel: kernel update [SLES12 SP3 4.4.92-6.18] Project: fs/lustre-release Branch: master Current Patch Set: 1 Commit: 880dc5e117ba65b392f9d54d4ca53b90e76a1d89

            People

              bogl Bob Glossman (Inactive)
              bogl Bob Glossman (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              3 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: