[LU-14774] kernel update [SLES15 SP2 5.3.18-24.67.3] Created: 19/Jun/21  Updated: 06/Sep/21  Resolved: 06/Sep/21

Status: Resolved
Project: Lustre
Component/s: None
Affects Version/s: None
Fix Version/s: None

Type: Improvement Priority: Minor
Reporter: Jian Yu Assignee: Jian Yu
Resolution: Won't Fix Votes: 0
Labels: None

Issue Links:
Related
is related to LU-14722 kernel update [SLES15 SP2 5.3.18-24.6... Resolved
is related to LU-14873 kernel update [SLES15 SP2 5.3.18-24.7... Resolved
Rank (Obsolete): 9223372036854775807

 Description   

The SUSE Linux Enterprise 15 SP2 kernel was updated to receive various
security and bugfixes.

The following security bugs were fixed:

  • CVE-2021-33200: Enforcing incorrect limits for pointer arithmetic
    operations by the BPF verifier could be abused to perform out-of-bounds
    reads and writes in kernel memory (bsc#1186484).
  • CVE-2021-33034: Fixed a use-after-free when destroying an hci_chan. This
    could lead to writing an arbitrary values. (bsc#1186111)
  • CVE-2020-26139: Fixed a denial-of-service when an Access Point (AP)
    forwards EAPOL frames to other clients even though the sender has not
    yet successfully authenticated to the AP. (bnc#1186062)
  • CVE-2021-23134: A Use After Free vulnerability in nfc sockets allowed
    local attackers to elevate their privileges. (bnc#1186060)
  • CVE-2021-3491: Fixed a potential heap overflow in mem_rw(). This
    vulnerability is related to the PROVIDE_BUFFERS operation, which allowed
    the MAX_RW_COUNT limit to be bypassed (bsc#1185642).
  • CVE-2021-32399: Fixed a race condition when removing the HCI controller
    (bnc#1184611).
  • CVE-2020-24586: The 802.11 standard that underpins Wi-Fi Protected
    Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't
    require that received fragments be cleared from memory after
    (re)connecting to a network. Under the right circumstances this can be
    abused to inject arbitrary network packets and/or exfiltrate user data
    (bnc#1185859).
  • CVE-2020-24587: The 802.11 standard that underpins Wi-Fi Protected
    Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't
    require that all fragments of a frame are encrypted under the same key.
    An adversary can abuse this to decrypt selected fragments when another
    device sends fragmented frames and the WEP, CCMP, or GCMP encryption key
    is periodically renewed (bnc#1185859 bnc#1185862).
  • CVE-2020-26147: The WEP, WPA, WPA2, and WPA3 implementations reassemble
    fragments, even though some of them were sent in plaintext. This
    vulnerability can be abused to inject packets and/or exfiltrate selected
    fragments when another device sends fragmented frames and the WEP, CCMP,
    or GCMP data-confidentiality protocol is used (bnc#1185859).
  • CVE-2020-24588: The 802.11 standard that underpins Wi-Fi Protected
    Access (WPA, WPA2, and WPA3) and Wired Equivalent Privacy (WEP) doesn't
    require that the A-MSDU flag in the plaintext QoS header field is
    authenticated. Against devices that support receiving non-SSP A-MSDU
    frames (which is mandatory as part of 802.11n), an adversary can abuse
    this to inject arbitrary network packets. (bnc#1185861)
  • CVE-2020-26145: An issue was discovered with Samsung Galaxy S3 i9305
    4.4.4 devices. The WEP, WPA, WPA2, and WPA3 implementations accept
    second (or subsequent) broadcast fragments even when sent in plaintext
    and process them as full unfragmented frames. An adversary can abuse
    this to inject arbitrary network packets independent of the network
    configuration. (bnc#1185860)
  • CVE-2020-26141: An issue was discovered in the ALFA driver for AWUS036H,
    where the Message Integrity Check (authenticity) of fragmented TKIP
    frames was not verified. An adversary can abuse this to inject and
    possibly decrypt packets in WPA or WPA2 networks that support the TKIP
    data-confidentiality protocol. (bnc#1185987)

The following non-security bugs were fixed:
https://lists.suse.com/pipermail/sle-security-updates/2021-June/008947.html



 Comments   
Comment by Gerrit Updater [ 19/Jun/21 ]

Jian Yu (yujian@whamcloud.com) uploaded a new patch: https://review.whamcloud.com/44036
Subject: LU-14774 kernel: kernel update SLES15 SP2 [5.3.18-24.67.3]
Project: fs/lustre-release
Branch: master
Current Patch Set: 1
Commit: 9268d38b219be1ecf1aafeae18822097887969a3

Comment by Jian Yu [ 06/Sep/21 ]

A new version is in https://review.whamcloud.com/44849

Generated at Sat Feb 10 03:12:40 UTC 2024 using Jira 9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c.