Uploaded image for project: 'Lustre'
  1. Lustre
  2. LU-14220

kernel update [SLES12 SP4 4.12.14-95.65.1]

    XMLWordPrintable

Details

    • Improvement
    • Resolution: Won't Fix
    • Minor
    • None
    • None
    • None
    • 9223372036854775807

    Description

      The SUSE Linux Enterprise 12 SP4 kernel was updated to receive various
      security and bug fixes.

      The following security bugs were fixed:

      • CVE-2020-25705: A flaw in the way reply ICMP packets are limited in was
        found that allowed to quickly scan open UDP ports. This flaw allowed an
        off-path remote user to effectively bypassing source port UDP
        randomization. The highest threat from this vulnerability is to
        confidentiality and possibly integrity, because software and services
        that rely on UDP source port randomization (like DNS) are indirectly
        affected as well. Kernel versions may be vulnerable to this issue
        (bsc#1175721, bsc#1178782).
      • CVE-2020-25704: Fixed a memory leak in perf_event_parse_addr_filter()
        (bsc#1178393).
      • CVE-2020-25668: Fixed a use-after-free in con_font_op() (bnc#1178123).
      • CVE-2020-25656: Fixed a concurrency use-after-free in vt_do_kdgkb_ioctl
        (bnc#1177766).
      • CVE-2020-25285: Fixed a race condition between hugetlb sysctl handlers
        in mm/hugetlb.c (bnc#1176485).
      • CVE-2020-0430: Fixed an OOB read in skb_headlen of
        /include/linux/skbuff.h (bnc#1176723).
      • CVE-2020-14351: Fixed a race in the perf_mmap_close() function
        (bsc#1177086).
      • CVE-2020-16120: Fixed a permissions issue in ovl_path_open()
        (bsc#1177470).
      • CVE-2020-8694: Restricted energy meter to root access (bsc#1170415).
      • CVE-2020-12351: Implemented a kABI workaround for bluetooth l2cap_ops
        filter addition (bsc#1177724).
      • CVE-2020-12352: Fixed an information leak when processing certain AMP
        packets aka "BleedingTooth" (bsc#1177725).
      • CVE-2020-25212: Fixed a TOCTOU mismatch in the NFS client code
        (bnc#1176381).
      • CVE-2020-25645: Fixed an an issue in IPsec that caused traffic between
        two Geneve endpoints to be unencrypted (bnc#1177511).
      • CVE-2020-14381: Fixed a UAF in the fast user mutex (futex) wait
        operation (bsc#1176011).
      • CVE-2020-25643: Fixed an improper input validation in the
        ppp_cp_parse_cr function of the HDLC_PPP module (bnc#1177206).
      • CVE-2020-25641: Fixed a zero-length biovec request issued by the block
        subsystem could have caused the kernel to enter an infinite loop,
        causing a denial of service (bsc#1177121).
      • CVE-2020-26088: Fixed an improper CAP_NET_RAW check in NFC socket
        creation could have been used by local attackers to create raw sockets,
        bypassing security mechanisms (bsc#1176990).
      • CVE-2020-14390: Fixed an out-of-bounds memory write leading to memory
        corruption or a denial of service when changing screen size
        (bnc#1176235).
      • CVE-2020-0432: Fixed an out of bounds write due to an integer overflow
        (bsc#1176721).
      • CVE-2020-0427: Fixed an out of bounds read due to a use after free
        (bsc#1176725).
      • CVE-2020-0431: Fixed an out of bounds write due to a missing bounds
        check (bsc#1176722).
      • CVE-2020-0404: Fixed a linked list corruption due to an unusual root
        cause (bsc#1176423).
      • CVE-2020-25284: Fixed an incomplete permission checking for access to
        rbd devices, which could have been leveraged by local attackers to map
        or unmap rbd block devices (bsc#1176482).
      • CVE-2020-27673: Fixed an issue where rogue guests could have caused
        denial of service of Dom0 via high frequency events (XSA-332 bsc#1177411)
      • CVE-2020-27675: Fixed a race condition in event handler which may crash
        dom0 (XSA-331 bsc#1177410).

      The following non-security bugs were fixed:
      https://lists.suse.com/pipermail/sle-security-updates/2020-November/007878.html

      Attachments

        Issue Links

          Activity

            People

              yujian Jian Yu
              yujian Jian Yu
              Votes:
              0 Vote for this issue
              Watchers:
              2 Start watching this issue

              Dates

                Created:
                Updated:
                Resolved: