Uploaded image for project: 'Lustre'
  1. Lustre
  2. LU-10847

kernel update [SLES12 SP2 4.4.120-92.70]

Details

    • 3
    • 9223372036854775807

    Description

      The SUSE Linux Enterprise 12 SP2 kernel was updated to 4.4.120 to receive various security and bugfixes.

      The following security bugs were fixed:

      • CVE-2017-13166: An elevation of privilege vulnerability in the v4l2 video driver was fixed. (bnc#1072865).
      • CVE-2017-15951: The KEYS subsystem did not correctly synchronize the actions of updating versus finding a key in the "negative" state to avoid a race condition, which allowed local users to cause a denial of service or possibly have unspecified other impact via crafted system calls (bnc#1062840 bnc#1065615).
      • CVE-2017-16644: The hdpvr_probe function in drivers/media/usb/hdpvr/hdpvr-core.c allowed local users to cause a denial of service (improper error handling and system crash) or possibly have unspecified other impact via a crafted USB device (bnc#1067118).
      • CVE-2017-16912: The "get_pipe()" function (drivers/usb/usbip/stub_rx.c) allowed attackers to cause a denial of service (out-of-bounds read) via a specially crafted USB over IP packet (bnc#1078673).
      • CVE-2017-16913: The "stub_recv_cmd_submit()" function (drivers/usb/usbip/stub_rx.c) when handling CMD_SUBMIT packets allowed attackers to cause a denial of service (arbitrary memory allocation) via a specially crafted USB over IP packet (bnc#1078672).
      • CVE-2017-17975: Use-after-free in the usbtv_probe function in drivers/media/usb/usbtv/usbtv-core.c allowed attackers to cause a denial of service (system crash) or possibly have unspecified other impact by triggering failure of audio registration, because a kfree of the usbtv data structure occurs during a usbtv_video_free call, but the usbtv_video_fail label's code attempts to both access and free this data structure (bnc#1074426).
      • CVE-2017-18208: The madvise_willneed function in mm/madvise.c allowed local users to cause a denial of service (infinite loop) by triggering use of MADVISE_WILLNEED for a DAX mapping (bnc#1083494).
      • CVE-2018-8087: Memory leak in the hwsim_new_radio_nl function in drivers/net/wireless/mac80211_hwsim.c allowed local users to cause a denial of service (memory consumption) by triggering an out-of-array error case (bnc#1085053).
      • CVE-2018-1000026: A insufficient input validation vulnerability in the bnx2x network card driver could result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2x card. This can be done from an untrusted guest VM. (bnc#1079384).
      • CVE-2018-1068: Insufficient user provided offset checking in the ebtables compat code allowed local attackers to overwrite kernel memory and potentially execute code. (bsc#1085107)

      Attachments

        Issue Links

          Activity

            [LU-10847] kernel update [SLES12 SP2 4.4.120-92.70]

            Oleg Drokin (oleg.drokin@intel.com) merged in patch https://review.whamcloud.com/32003/
            Subject: LU-10847 doc: fix broken ChangeLog
            Project: fs/lustre-release
            Branch: master
            Current Patch Set:
            Commit: abe156eecf0faf4a3d423b15185befe9f5fd7e27

            gerrit Gerrit Updater added a comment - Oleg Drokin (oleg.drokin@intel.com) merged in patch https://review.whamcloud.com/32003/ Subject: LU-10847 doc: fix broken ChangeLog Project: fs/lustre-release Branch: master Current Patch Set: Commit: abe156eecf0faf4a3d423b15185befe9f5fd7e27

            Bob Glossman (bob.glossman@intel.com) uploaded a new patch: https://review.whamcloud.com/32003
            Subject: LU-10847 doc: fix broken ChangeLog
            Project: fs/lustre-release
            Branch: master
            Current Patch Set: 1
            Commit: 6eec0aad0f3aefe8976c504cfee565088d59b0c6

            gerrit Gerrit Updater added a comment - Bob Glossman (bob.glossman@intel.com) uploaded a new patch: https://review.whamcloud.com/32003 Subject: LU-10847 doc: fix broken ChangeLog Project: fs/lustre-release Branch: master Current Patch Set: 1 Commit: 6eec0aad0f3aefe8976c504cfee565088d59b0c6
            pjones Peter Jones added a comment -

            Landed for 2.12

            pjones Peter Jones added a comment - Landed for 2.12

            Oleg Drokin (oleg.drokin@intel.com) merged in patch https://review.whamcloud.com/31764/
            Subject: LU-10847 kernel update [SLES12 SP2 4.4.120-92.70]
            Project: fs/lustre-release
            Branch: master
            Current Patch Set:
            Commit: e2aa51c7f88d0db6e40a99d75f9d5161bb762c8c

            gerrit Gerrit Updater added a comment - Oleg Drokin (oleg.drokin@intel.com) merged in patch https://review.whamcloud.com/31764/ Subject: LU-10847 kernel update [SLES12 SP2 4.4.120-92.70] Project: fs/lustre-release Branch: master Current Patch Set: Commit: e2aa51c7f88d0db6e40a99d75f9d5161bb762c8c

            John L. Hammond (john.hammond@intel.com) merged in patch https://review.whamcloud.com/31765/
            Subject: LU-10847 kernel update [SLES12 SP2 4.4.120-92.70]
            Project: fs/lustre-release
            Branch: b2_10
            Current Patch Set:
            Commit: 63df2d4c9690fddae1d5d5acfd86345ef8243e17

            gerrit Gerrit Updater added a comment - John L. Hammond (john.hammond@intel.com) merged in patch https://review.whamcloud.com/31765/ Subject: LU-10847 kernel update [SLES12 SP2 4.4.120-92.70] Project: fs/lustre-release Branch: b2_10 Current Patch Set: Commit: 63df2d4c9690fddae1d5d5acfd86345ef8243e17

            Bob Glossman (bob.glossman@intel.com) uploaded a new patch: https://review.whamcloud.com/31765
            Subject: LU-10847 kernel update [SLES12 SP2 4.4.120-92.70]
            Project: fs/lustre-release
            Branch: b2_10
            Current Patch Set: 1
            Commit: bd729f9347c191bfb30e8664f329651d6efca8d0

            gerrit Gerrit Updater added a comment - Bob Glossman (bob.glossman@intel.com) uploaded a new patch: https://review.whamcloud.com/31765 Subject: LU-10847 kernel update [SLES12 SP2 4.4.120-92.70] Project: fs/lustre-release Branch: b2_10 Current Patch Set: 1 Commit: bd729f9347c191bfb30e8664f329651d6efca8d0

            People

              bogl Bob Glossman (Inactive)
              bogl Bob Glossman (Inactive)
              Votes:
              0 Vote for this issue
              Watchers:
              4 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: