[LU-14220] kernel update [SLES12 SP4 4.12.14-95.65.1] Created: 15/Dec/20  Updated: 18/Dec/20  Resolved: 18/Dec/20

Status: Resolved
Project: Lustre
Component/s: None
Affects Version/s: None
Fix Version/s: None

Type: Improvement Priority: Minor
Reporter: Jian Yu Assignee: Jian Yu
Resolution: Won't Fix Votes: 0
Labels: None

Issue Links:
Related
is related to LU-13860 kernel update [SLES12 SP4 4.12.14-95.... Resolved
Rank (Obsolete): 9223372036854775807

 Description   

The SUSE Linux Enterprise 12 SP4 kernel was updated to receive various
security and bug fixes.

The following security bugs were fixed:

  • CVE-2020-25705: A flaw in the way reply ICMP packets are limited in was
    found that allowed to quickly scan open UDP ports. This flaw allowed an
    off-path remote user to effectively bypassing source port UDP
    randomization. The highest threat from this vulnerability is to
    confidentiality and possibly integrity, because software and services
    that rely on UDP source port randomization (like DNS) are indirectly
    affected as well. Kernel versions may be vulnerable to this issue
    (bsc#1175721, bsc#1178782).
  • CVE-2020-25704: Fixed a memory leak in perf_event_parse_addr_filter()
    (bsc#1178393).
  • CVE-2020-25668: Fixed a use-after-free in con_font_op() (bnc#1178123).
  • CVE-2020-25656: Fixed a concurrency use-after-free in vt_do_kdgkb_ioctl
    (bnc#1177766).
  • CVE-2020-25285: Fixed a race condition between hugetlb sysctl handlers
    in mm/hugetlb.c (bnc#1176485).
  • CVE-2020-0430: Fixed an OOB read in skb_headlen of
    /include/linux/skbuff.h (bnc#1176723).
  • CVE-2020-14351: Fixed a race in the perf_mmap_close() function
    (bsc#1177086).
  • CVE-2020-16120: Fixed a permissions issue in ovl_path_open()
    (bsc#1177470).
  • CVE-2020-8694: Restricted energy meter to root access (bsc#1170415).
  • CVE-2020-12351: Implemented a kABI workaround for bluetooth l2cap_ops
    filter addition (bsc#1177724).
  • CVE-2020-12352: Fixed an information leak when processing certain AMP
    packets aka "BleedingTooth" (bsc#1177725).
  • CVE-2020-25212: Fixed a TOCTOU mismatch in the NFS client code
    (bnc#1176381).
  • CVE-2020-25645: Fixed an an issue in IPsec that caused traffic between
    two Geneve endpoints to be unencrypted (bnc#1177511).
  • CVE-2020-14381: Fixed a UAF in the fast user mutex (futex) wait
    operation (bsc#1176011).
  • CVE-2020-25643: Fixed an improper input validation in the
    ppp_cp_parse_cr function of the HDLC_PPP module (bnc#1177206).
  • CVE-2020-25641: Fixed a zero-length biovec request issued by the block
    subsystem could have caused the kernel to enter an infinite loop,
    causing a denial of service (bsc#1177121).
  • CVE-2020-26088: Fixed an improper CAP_NET_RAW check in NFC socket
    creation could have been used by local attackers to create raw sockets,
    bypassing security mechanisms (bsc#1176990).
  • CVE-2020-14390: Fixed an out-of-bounds memory write leading to memory
    corruption or a denial of service when changing screen size
    (bnc#1176235).
  • CVE-2020-0432: Fixed an out of bounds write due to an integer overflow
    (bsc#1176721).
  • CVE-2020-0427: Fixed an out of bounds read due to a use after free
    (bsc#1176725).
  • CVE-2020-0431: Fixed an out of bounds write due to a missing bounds
    check (bsc#1176722).
  • CVE-2020-0404: Fixed a linked list corruption due to an unusual root
    cause (bsc#1176423).
  • CVE-2020-25284: Fixed an incomplete permission checking for access to
    rbd devices, which could have been leveraged by local attackers to map
    or unmap rbd block devices (bsc#1176482).
  • CVE-2020-27673: Fixed an issue where rogue guests could have caused
    denial of service of Dom0 via high frequency events (XSA-332 bsc#1177411)
  • CVE-2020-27675: Fixed a race condition in event handler which may crash
    dom0 (XSA-331 bsc#1177410).

The following non-security bugs were fixed:
https://lists.suse.com/pipermail/sle-security-updates/2020-November/007878.html



 Comments   
Comment by Gerrit Updater [ 17/Dec/20 ]

Jian Yu (yujian@whamcloud.com) uploaded a new patch: https://review.whamcloud.com/41035
Subject: LU-14220 kernel: kernel update SLES12 SP4 [4.12.14-95.65.1]
Project: fs/lustre-release
Branch: master
Current Patch Set: 1
Commit: 699bd4673c205fb6ccffc4a66d9fb4c20a2bc3e5

Comment by Gerrit Updater [ 17/Dec/20 ]

Jian Yu (yujian@whamcloud.com) uploaded a new patch: https://review.whamcloud.com/41036
Subject: LU-14220 kernel: kernel update SLES12 SP4 [4.12.14-95.65.1]
Project: fs/lustre-release
Branch: b2_12
Current Patch Set: 1
Commit: c534c3ef64b45266f8e5c43d585d7adc599912ce

Generated at Sat Feb 10 03:07:53 UTC 2024 using Jira 9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c.