[LU-12660] kernel update [SLES12 SP4 4.12.14-95.29.1] Created: 12/Aug/19  Updated: 20/Sep/19  Resolved: 21/Aug/19

Status: Resolved
Project: Lustre
Component/s: None
Affects Version/s: None
Fix Version/s: Lustre 2.13.0, Lustre 2.12.3

Type: Bug Priority: Minor
Reporter: Jian Yu Assignee: Jian Yu
Resolution: Fixed Votes: 0
Labels: None

Issue Links:
Related
is related to LU-12556 kernel update [SLES12 SP4 4.12.14-95.... Resolved
is related to LU-12793 kernel update [SLES12 SP4 4.12.14-95.... Resolved
Severity: 3
Rank (Obsolete): 9223372036854775807

 Description   

The SUSE Linux Enterprise 12 kernel was updated to receive various security and bugfixes.

The following security bugs were fixed:

  • CVE-2018-20855: An issue was discovered in the Linux kernel In
    create_qp_common in drivers/infiniband/hw/mlx5/qp.c,
    mlx5_ib_create_qp_resp was never initialized, resulting in a leak of
    stack memory to userspace(bsc#1143045).
  • CVE-2019-1125: Exclude ATOMs from speculation through SWAPGS
    (bsc#1139358).
  • CVE-2019-14283: In the Linux kernel, set_geometry in
    drivers/block/floppy.c did not validate the sect and head fields, as
    demonstrated by an integer overflow and out-of-bounds read. It could be
    triggered by an unprivileged local user when a floppy disk was inserted.
    NOTE: QEMU creates the floppy device by default. (bnc#1143191)
  • CVE-2019-11810: An issue was discovered in the Linux kernel A NULL
    pointer dereference could occur when megasas_create_frame_pool() failed
    in megasas_alloc_cmds() in drivers/scsi/megaraid/megaraid_sas_base.c.
    This caused a Denial of Service, related to a use-after-free
    (bnc#1134399).
  • CVE-2019-13648: In the Linux kernel on the powerpc platform, when
    hardware transactional memory was disabled, a local user could cause a
    denial of service (TM Bad Thing exception and system crash) via a
    sigreturn() system call that sent a crafted signal frame. (bnc#1142254)
  • CVE-2019-13631: In parse_hid_report_descriptor in
    drivers/input/tablet/gtco.c in the Linux kernel, a malicious USB device
    could send an HID report that triggered an out-of-bounds write during
    generation of debugging messages. (bnc#1142023)

The following non-security bugs were fixed:
http://lists.suse.com/pipermail/sle-security-updates/2019-August/005794.html



 Comments   
Comment by Gerrit Updater [ 12/Aug/19 ]

Jian Yu (yujian@whamcloud.com) uploaded a new patch: https://review.whamcloud.com/35774
Subject: LU-12660 kernel: kernel update SLES12 SP4 [4.12.14-95.29.1]
Project: fs/lustre-release
Branch: master
Current Patch Set: 1
Commit: c558746514d85d9d3d32af16352272d3e9c76fca

Comment by Gerrit Updater [ 12/Aug/19 ]

Jian Yu (yujian@whamcloud.com) uploaded a new patch: https://review.whamcloud.com/35775
Subject: LU-12660 kernel: kernel update SLES12 SP4 [4.12.14-95.29.1]
Project: fs/lustre-release
Branch: b2_12
Current Patch Set: 1
Commit: b332e69f3fd954d0c7eeba591182b25ccb4a85ea

Comment by Gerrit Updater [ 21/Aug/19 ]

Oleg Drokin (green@whamcloud.com) merged in patch https://review.whamcloud.com/35774/
Subject: LU-12660 kernel: kernel update SLES12 SP4 [4.12.14-95.29.1]
Project: fs/lustre-release
Branch: master
Current Patch Set:
Commit: c0f366b114750828d70431f10fa8545f8a840caa

Comment by Peter Jones [ 21/Aug/19 ]

Landed for 2.13

Comment by Gerrit Updater [ 04/Sep/19 ]

Oleg Drokin (green@whamcloud.com) merged in patch https://review.whamcloud.com/35775/
Subject: LU-12660 kernel: kernel update SLES12 SP4 [4.12.14-95.29.1]
Project: fs/lustre-release
Branch: b2_12
Current Patch Set:
Commit: b47444a649f4ee96d32c77c7b9fe472a1f2ba0e0

Generated at Sat Feb 10 02:54:32 UTC 2024 using Jira 9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c.