[LU-16304] kernel update [RHEL8.7 4.18.0-425.3.1.el8] Created: 08/Nov/22  Updated: 18/Jan/23  Resolved: 29/Nov/22

Status: Resolved
Project: Lustre
Component/s: None
Affects Version/s: None
Fix Version/s: Lustre 2.16.0, Lustre 2.15.2

Type: Improvement Priority: Minor
Reporter: Jian Yu Assignee: Jian Yu
Resolution: Fixed Votes: 0
Labels: llnl

Issue Links:
Duplicate
is duplicated by LU-16312 rhel 8.7 kernel-4.18.0-425.3.1.el8.x8... Resolved
Related
is related to LU-16222 RHEL 8.7 support Resolved
is related to LU-16486 kernel update [RHEL8.7 4.18.0-425.10.... Resolved
Rank (Obsolete): 9223372036854775807

 Description   

Security Fix(es):

  • off-path attacker may inject data or terminate victim's TCP session (CVE-2020-36516)
  • race condition in VT_RESIZEX ioctl when vc_cons[i].d is already NULL leading to NULL pointer dereference (CVE-2020-36558)
  • use-after-free vulnerability in function sco_sock_sendmsg() (CVE-2021-3640)
  • memory leak for large arguments in video_usercopy function in drivers/media/v4l2-core/v4l2-ioctl.c (CVE-2021-30002)
  • smb2_ioctl_query_info NULL Pointer Dereference (CVE-2022-0168)
  • NULL pointer dereference in udf_expand_file_adinicbdue() during writeback (CVE-2022-0617)
  • swiotlb information leak with DMA_FROM_DEVICE (CVE-2022-0854)
  • uninitialized registers on stack in nft_do_chain can cause kernel pointer leakage to UM (CVE-2022-1016)
  • race condition in snd_pcm_hw_free leading to use-after-free (CVE-2022-1048)
  • use-after-free in tc_new_tfilter() in net/sched/cls_api.c (CVE-2022-1055)
  • use-after-free and memory errors in ext4 when mounting and operating on a corrupted image (CVE-2022-1184)
  • NULL pointer dereference in x86_emulate_insn may lead to DoS (CVE-2022-1852)
  • buffer overflow in nft_set_desc_concat_parse() (CVE-2022-2078)
  • nf_tables cross-table potential use-after-free may lead to local privilege escalation (CVE-2022-2586)
  • openvswitch: integer underflow leads to out-of-bounds write in reserve_sfa_size() (CVE-2022-2639)
  • use-after-free when psi trigger is destroyed while being polled (CVE-2022-2938)
  • net/packet: slab-out-of-bounds access in packet_recvmsg() (CVE-2022-20368)
  • possible to use the debugger to write zero into a location of choice (CVE-2022-21499)
  • Spectre-BHB (CVE-2022-23960)
  • Post-barrier Return Stack Buffer Predictions (CVE-2022-26373)
  • memory leak in drivers/hid/hid-elo.c (CVE-2022-27950)
  • double free in ems_usb_start_xmit in drivers/net/can/usb/ems_usb.c (CVE-2022-28390)
  • use after free in SUNRPC subsystem (CVE-2022-28893)
  • use-after-free due to improper update of reference count in net/sched/cls_u32.c (CVE-2022-29581)
  • DoS in nfqnl_mangle in net/netfilter/nfnetlink_queue.c (CVE-2022-36946)
  • nfs_atomic_open() returns uninitialized data instead of ENOTDIR (CVE-2022-24448)

https://access.redhat.com/errata/RHSA-2022:7683?sc_cid=701600000006NHXAA2



 Comments   
Comment by Gerrit Updater [ 09/Nov/22 ]

"Jian Yu <yujian@whamcloud.com>" uploaded a new patch: https://review.whamcloud.com/c/fs/lustre-release/+/49080
Subject: LU-16304 kernel: kernel update RHEL8.7 [4.18.0-425.3.1.el8]
Project: fs/lustre-release
Branch: master
Current Patch Set: 1
Commit: 60bb9208c05a161d0bd3abe1c600d5411344f081

Comment by Gerrit Updater [ 15/Nov/22 ]

"Jian Yu <yujian@whamcloud.com>" uploaded a new patch: https://review.whamcloud.com/c/fs/lustre-release/+/49156
Subject: LU-16304 kernel: kernel update RHEL8.7 [4.18.0-425.3.1.el8]
Project: fs/lustre-release
Branch: b2_15
Current Patch Set: 1
Commit: 2b62233f84ace7efb05d6c264cfa6ee61209acc1

Comment by Gerrit Updater [ 16/Nov/22 ]

"Jian Yu <yujian@whamcloud.com>" uploaded a new patch: https://review.whamcloud.com/c/fs/lustre-release/+/49171
Subject: LU-16304 kernel: kernel update RHEL8.7 [4.18.0-425.3.1.el8]
Project: fs/lustre-release
Branch: b2_12
Current Patch Set: 1
Commit: 893fa11365266605d79dedca805ea3c83dfcd7f5

Comment by Gerrit Updater [ 22/Nov/22 ]

"Oleg Drokin <green@whamcloud.com>" merged in patch https://review.whamcloud.com/c/fs/lustre-release/+/49156/
Subject: LU-16304 kernel: kernel update RHEL8.7 [4.18.0-425.3.1.el8]
Project: fs/lustre-release
Branch: b2_15
Current Patch Set:
Commit: d20d7d80de3a5564ebb939c68b6641b8c0d9a910

Comment by Gerrit Updater [ 29/Nov/22 ]

"Oleg Drokin <green@whamcloud.com>" merged in patch https://review.whamcloud.com/c/fs/lustre-release/+/49080/
Subject: LU-16304 kernel: kernel update RHEL8.7 [4.18.0-425.3.1.el8]
Project: fs/lustre-release
Branch: master
Current Patch Set:
Commit: d6591a041ab6fa46cc2046b8486f0bc1fb6bf40a

Comment by Peter Jones [ 29/Nov/22 ]

Landed for 2.16

Generated at Sat Feb 10 03:25:49 UTC 2024 using Jira 9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c.