[LU-16718] kernel update [SLES15 SP4 5.14.21-150400.24.55.2] Created: 06/Apr/23  Updated: 12/Sep/23

Status: Open
Project: Lustre
Component/s: None
Affects Version/s: Lustre 2.16.0, Lustre 2.15.3
Fix Version/s: None

Type: Improvement Priority: Minor
Reporter: Jian Yu Assignee: Jian Yu
Resolution: Unresolved Votes: 0
Labels: None

Issue Links:
Related
is related to LU-16601 kernel update [SLES15 SP4 5.14.21-150... Resolved
is related to LU-17113 kernel update [SLES15 SP4 5.14.21-150... Resolved
Rank (Obsolete): 9223372036854775807

 Description   

The SUSE Linux Enterprise 15 SP4 kernel was updated to receive various security
and bugfixes.

  • CVE-2022-3523: Fixed a use after free related to device private page
    handling (bsc#1204363).
  • CVE-2022-36280: Fixed out-of-bounds memory access vulnerability found in
    vmwgfx driver (bsc#1203332).
  • CVE-2022-38096: Fixed NULL-ptr deref in vmw_cmd_dx_define_query()
    (bsc#1203331).
  • CVE-2023-0045: Fixed missing Flush IBP in ib_prctl_set (bsc#1207773).
  • CVE-2023-0461: Fixed use-after-free in icsk_ulp_data (bsc#1208787).
  • CVE-2023-0597: Fixed lack of randomization of per-cpu entry area in x86/mm
    (bsc#1207845).
  • CVE-2023-1075: Fixed a type confusion in tls_is_tx_ready (bsc#1208598).
  • CVE-2023-1076: Fixed incorrect UID assigned to tun/tap sockets
    (bsc#1208599).
  • CVE-2023-1078: Fixed a heap out-of-bounds write in rds_rm_zerocopy_callback
    (bsc#1208601).
  • CVE-2023-1095: Fixed a NULL pointer dereference in nf_tables due to zeroed
    list head (bsc#1208777).
  • CVE-2023-1118: Fixed a use-after-free bugs caused by ene_tx_irqsim() in
    media/rc (bsc#1208837).
  • CVE-2023-22995: Fixed lacks of certain platform_device_put and kfree in
    drivers/usb/dwc3/dwc3-qcom.c (bsc#1208741).
  • CVE-2023-22998: Fixed NULL vs IS_ERR checking in
    virtio_gpu_object_shmem_init (bsc#1208776).
  • CVE-2023-23000: Fixed return value of tegra_xusb_find_port_node function
    phy/tegra (bsc#1208816).
  • CVE-2023-23004: Fixed misinterpretation of get_sg_table return value
    (bsc#1208843).
  • CVE-2023-23559: Fixed integer overflow in rndis_wlan that leads to a buffer
    overflow (bsc#1207051).
  • CVE-2023-25012: Fixed a use-after-free in bigben_set_led() (bsc#1207560).
  • CVE-2023-26545: Fixed double free in net/mpls/af_mpls.c upon an allocation
    failure (bsc#1208700).
  • CVE-2023-28328: Fixed a denial of service issue in az6027 driver in
    drivers/media/usb/dev-usb/az6027.c (bsc#1209291).

The following non-security bugs were fixed:
https://lists.suse.com/pipermail/sle-security-updates/2023-March/014289.html



 Comments   
Comment by Gerrit Updater [ 06/Apr/23 ]

"Jian Yu <yujian@whamcloud.com>" uploaded a new patch: https://review.whamcloud.com/c/fs/lustre-release/+/50562
Subject: LU-16718 kernel: update SLES15 SP4 [5.14.21-150400.24.55.2]
Project: fs/lustre-release
Branch: master
Current Patch Set: 1
Commit: 08f31e349cc5bda09567d7b1c01b2ee2b1494b4b

Generated at Sat Feb 10 03:29:25 UTC 2024 using Jira 9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c.