<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 02:49:59 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-12138] kernel update [SLES12 SP4 4.12.14-95.13.1]</title>
                <link>https://jira.whamcloud.com/browse/LU-12138</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;p&gt;The SUSE Linux Enterprise 12 SP4 kernel was updated to receive various security and bugfixes.&lt;/p&gt;

&lt;p&gt;The following security bugs were fixed:&lt;/p&gt;

&lt;ul class=&quot;alternate&quot; type=&quot;square&quot;&gt;
	&lt;li&gt;CVE-2018-20669: Missing access control checks in ioctl of gpu/drm/i915&lt;br/&gt;
     driver were fixed which might have lead to information leaks.&lt;br/&gt;
     (bnc#1122971).&lt;/li&gt;
	&lt;li&gt;CVE-2019-3459, CVE-2019-3460: The Bluetooth stack suffered from two&lt;br/&gt;
     remote information leak vulnerabilities in the code that handles&lt;br/&gt;
     incoming L2cap configuration packets (bsc#1120758).&lt;/li&gt;
	&lt;li&gt;CVE-2019-3819: A flaw was found in the function hid_debug_events_read()&lt;br/&gt;
     in drivers/hid/hid-debug.c file which may enter an infinite loop with&lt;br/&gt;
     certain parameters passed from a userspace. A local privileged user&lt;br/&gt;
     (&quot;root&quot;) can cause a system lock up and a denial of service.&lt;br/&gt;
     (bnc#1123161).&lt;/li&gt;
	&lt;li&gt;CVE-2019-6974: kvm_ioctl_create_device in virt/kvm/kvm_main.c mishandled&lt;br/&gt;
     reference counting because of a race condition, leading to a&lt;br/&gt;
     use-after-free (bnc#1124728 ).&lt;/li&gt;
	&lt;li&gt;CVE-2019-7221: Fixed a use-after-free vulnerability in the KVM&lt;br/&gt;
     hypervisor related to the emulation of a preemption timer, allowing an&lt;br/&gt;
     guest user/process to crash the host kernel. (bsc#1124732).&lt;/li&gt;
	&lt;li&gt;CVE-2019-7222: Fixed an information leakage in the KVM hypervisor&lt;br/&gt;
     related to handling page fault exceptions, which allowed a guest&lt;br/&gt;
     user/process to use this flaw to leak the host&apos;s stack memory contents&lt;br/&gt;
     to a guest (bsc#1124735).&lt;/li&gt;
	&lt;li&gt;CVE-2019-7308: kernel/bpf/verifier.c performed undesirable out-of-bounds&lt;br/&gt;
     speculation on pointer arithmetic in various cases, including cases of&lt;br/&gt;
     different branches with different state or limits to sanitize, leading&lt;br/&gt;
     to side-channel attacks (bnc#1124055).&lt;/li&gt;
	&lt;li&gt;CVE-2019-8912: af_alg_release() in crypto/af_alg.c neglects to set a&lt;br/&gt;
     NULL value for a certain structure member, which leads to a&lt;br/&gt;
     use-after-free in sockfs_setattr (bnc#1125907).&lt;/li&gt;
	&lt;li&gt;CVE-2019-8980: A memory leak in the kernel_read_file function in&lt;br/&gt;
     fs/exec.c allowed attackers to cause a denial of service (memory&lt;br/&gt;
     consumption) by triggering vfs_read failures (bnc#1126209).&lt;/li&gt;
	&lt;li&gt;CVE-2019-9213: expand_downwards in mm/mmap.c lacked a check for the mmap&lt;br/&gt;
     minimum address, which made it easier for attackers to exploit kernel&lt;br/&gt;
     NULL pointer dereferences on non-SMAP platforms. This is related to a&lt;br/&gt;
     capability check for the wrong task (bnc#1128166).&lt;/li&gt;
	&lt;li&gt;CVE-2019-2024: A use-after-free when disconnecting a source was fixed&lt;br/&gt;
     which could lead to crashes. bnc#1129179).&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;For non-security bugs fixed, please refer to:&lt;br/&gt;
&lt;a href=&quot;http://lists.suse.com/pipermail/sle-security-updates/2019-March/005240.html&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;http://lists.suse.com/pipermail/sle-security-updates/2019-March/005240.html&lt;/a&gt;&lt;/p&gt;</description>
                <environment></environment>
        <key id="55312">LU-12138</key>
            <summary>kernel update [SLES12 SP4 4.12.14-95.13.1]</summary>
                <type id="1" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11303&amp;avatarType=issuetype">Bug</type>
                                            <priority id="4" iconUrl="https://jira.whamcloud.com/images/icons/priorities/minor.svg">Minor</priority>
                        <status id="5" iconUrl="https://jira.whamcloud.com/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="1">Fixed</resolution>
                                        <assignee username="yujian">Jian Yu</assignee>
                                    <reporter username="yujian">Jian Yu</reporter>
                        <labels>
                    </labels>
                <created>Mon, 1 Apr 2019 11:12:47 +0000</created>
                <updated>Thu, 16 May 2019 07:15:27 +0000</updated>
                            <resolved>Tue, 30 Apr 2019 13:15:16 +0000</resolved>
                                                    <fixVersion>Lustre 2.13.0</fixVersion>
                    <fixVersion>Lustre 2.12.1</fixVersion>
                                        <due></due>
                            <votes>0</votes>
                                    <watches>2</watches>
                                                                            <comments>
                            <comment id="245446" author="gerrit" created="Mon, 8 Apr 2019 20:09:33 +0000"  >&lt;p&gt;Jian Yu (yujian@whamcloud.com) uploaded a new patch: &lt;a href=&quot;https://review.whamcloud.com/34619&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/34619&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-12138&quot; title=&quot;kernel update [SLES12 SP4 4.12.14-95.13.1]&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-12138&quot;&gt;&lt;del&gt;LU-12138&lt;/del&gt;&lt;/a&gt; kernel: kernel update SLES12 SP4 &lt;span class=&quot;error&quot;&gt;&amp;#91;4.12.14-95.13.1&amp;#93;&lt;/span&gt;&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: master&lt;br/&gt;
Current Patch Set: 1&lt;br/&gt;
Commit: db31dac335181c62ca85988b6aeb903fbc6a336d&lt;/p&gt;</comment>
                            <comment id="245452" author="gerrit" created="Mon, 8 Apr 2019 23:59:23 +0000"  >&lt;p&gt;Jian Yu (yujian@whamcloud.com) uploaded a new patch: &lt;a href=&quot;https://review.whamcloud.com/34621&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/34621&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-12138&quot; title=&quot;kernel update [SLES12 SP4 4.12.14-95.13.1]&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-12138&quot;&gt;&lt;del&gt;LU-12138&lt;/del&gt;&lt;/a&gt; kernel: kernel update SLES12 SP4 &lt;span class=&quot;error&quot;&gt;&amp;#91;4.12.14-95.13.1&amp;#93;&lt;/span&gt;&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: b2_12&lt;br/&gt;
Current Patch Set: 1&lt;br/&gt;
Commit: 1d3158b18037126aac6c6ec47f28b9022b2a7bb2&lt;/p&gt;</comment>
                            <comment id="245777" author="gerrit" created="Mon, 15 Apr 2019 16:16:06 +0000"  >&lt;p&gt;Oleg Drokin (green@whamcloud.com) merged in patch &lt;a href=&quot;https://review.whamcloud.com/34621/&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/34621/&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-12138&quot; title=&quot;kernel update [SLES12 SP4 4.12.14-95.13.1]&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-12138&quot;&gt;&lt;del&gt;LU-12138&lt;/del&gt;&lt;/a&gt; kernel: kernel update SLES12 SP4 &lt;span class=&quot;error&quot;&gt;&amp;#91;4.12.14-95.13.1&amp;#93;&lt;/span&gt;&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: b2_12&lt;br/&gt;
Current Patch Set: &lt;br/&gt;
Commit: 1642e29885ac2853003d4329a1c86a69b6d306f9&lt;/p&gt;</comment>
                            <comment id="246505" author="gerrit" created="Tue, 30 Apr 2019 04:52:05 +0000"  >&lt;p&gt;Oleg Drokin (green@whamcloud.com) merged in patch &lt;a href=&quot;https://review.whamcloud.com/34619/&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/34619/&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-12138&quot; title=&quot;kernel update [SLES12 SP4 4.12.14-95.13.1]&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-12138&quot;&gt;&lt;del&gt;LU-12138&lt;/del&gt;&lt;/a&gt; kernel: kernel update SLES12 SP4 &lt;span class=&quot;error&quot;&gt;&amp;#91;4.12.14-95.13.1&amp;#93;&lt;/span&gt;&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: master&lt;br/&gt;
Current Patch Set: &lt;br/&gt;
Commit: 9593f12ca571be67c53802ea6defe33d1c9c08ae&lt;/p&gt;</comment>
                            <comment id="246536" author="pjones" created="Tue, 30 Apr 2019 13:15:16 +0000"  >&lt;p&gt;Landed for 2.13&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10011">
                    <name>Related</name>
                                            <outwardlinks description="is related to ">
                                        <issuelink>
            <issuekey id="54780">LU-11927</issuekey>
        </issuelink>
                            </outwardlinks>
                                                                <inwardlinks description="is related to">
                                        <issuelink>
            <issuekey id="55656">LU-12308</issuekey>
        </issuelink>
                            </inwardlinks>
                                    </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                            <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|i00e9j:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>9223372036854775807</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                            <customfield id="customfield_10060" key="com.atlassian.jira.plugin.system.customfieldtypes:select">
                        <customfieldname>Severity</customfieldname>
                        <customfieldvalues>
                                <customfieldvalue key="10022"><![CDATA[3]]></customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        </customfields>
    </item>
</channel>
</rss>