<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 03:04:49 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-13858] kernel update [SLES15 SP1 4.12.14-197.48.1]</title>
                <link>https://jira.whamcloud.com/browse/LU-13858</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;p&gt;The SUSE Linux Enterprise 15 SP1 kernel was updated to receive various security and bugfixes.&lt;/p&gt;

&lt;p&gt;The following security bugs were fixed:&lt;/p&gt;
&lt;ul class=&quot;alternate&quot; type=&quot;square&quot;&gt;
	&lt;li&gt;CVE-2020-15780: A lockdown bypass for loading unsigned modules using&lt;br/&gt;
     ACPI table injection was fixed. (bsc#1173573)&lt;/li&gt;
	&lt;li&gt;CVE-2020-15393: Fixed a memory leak in usbtest_disconnect (bnc#1173514).&lt;/li&gt;
	&lt;li&gt;CVE-2020-12771: An issue was discovered in btree_gc_coalesce in&lt;br/&gt;
     drivers/md/bcache/btree.c has a deadlock if a coalescing operation fails&lt;br/&gt;
     (bnc#1171732).&lt;/li&gt;
	&lt;li&gt;CVE-2020-12888: The VFIO PCI driver mishandled attempts to access&lt;br/&gt;
     disabled memory space (bnc#1171868).&lt;/li&gt;
	&lt;li&gt;CVE-2020-10773: Fixed a memory leak on s390/s390x, in the&lt;br/&gt;
     cmm_timeout_hander in file arch/s390/mm/cmm.c (bnc#1172999).&lt;/li&gt;
	&lt;li&gt;CVE-2020-14416: Fixed a race condition in tty-&amp;gt;disc_data handling in the&lt;br/&gt;
     slip and slcan line discipline could lead to a use-after-free. This&lt;br/&gt;
     affects drivers/net/slip/slip.c and drivers/net/can/slcan.c&lt;br/&gt;
     (bnc#1162002).&lt;/li&gt;
	&lt;li&gt;CVE-2020-10768: Fixed an issue with the prctl() function, where indirect&lt;br/&gt;
     branch speculation could be enabled even though it was diabled before&lt;br/&gt;
     (bnc#1172783).&lt;/li&gt;
	&lt;li&gt;CVE-2020-10766: Fixed an issue which allowed an attacker with a local&lt;br/&gt;
     account to disable SSBD protection (bnc#1172781).&lt;/li&gt;
	&lt;li&gt;CVE-2020-10767: Fixed an issue where Indirect Branch Prediction Barrier&lt;br/&gt;
     was disabled in certain circumstances, leaving the system open to a&lt;br/&gt;
     spectre v2 style attack (bnc#1172782).&lt;/li&gt;
	&lt;li&gt;CVE-2020-13974: Fixed a integer overflow in drivers/tty/vt/keyboard.c,&lt;br/&gt;
     if k_ascii is called several times in a row (bnc#1172775).&lt;/li&gt;
	&lt;li&gt;CVE-2020-0305: Fixed a possible use-after-free due to a race condition&lt;br/&gt;
     incdev_get of char_dev.c. This could lead to local escalation of&lt;br/&gt;
     privilege. User interaction is not needed for exploitation (bnc#1174462).&lt;/li&gt;
	&lt;li&gt;CVE-2020-10769: A buffer over-read flaw was found in&lt;br/&gt;
     crypto_authenc_extractkeys in crypto/authenc.c in the IPsec&lt;br/&gt;
     Cryptographic algorithm&apos;s module, authenc. This flaw allowed a local&lt;br/&gt;
     attacker with user privileges to cause a denial of service (bnc#1173265).&lt;/li&gt;
	&lt;li&gt;CVE-2020-10781: Fixed a denial of service issue in the ZRAM&lt;br/&gt;
     implementation (bnc#1173074).&lt;/li&gt;
	&lt;li&gt;CVE-2019-20908: Fixed incorrect access permissions for the efivar_ssdt&lt;br/&gt;
     ACPI variable, which could be used by attackers to bypass lockdown or&lt;br/&gt;
     secure boot restrictions (bnc#1173567).&lt;/li&gt;
	&lt;li&gt;CVE-2019-20810: Fixed a memory leak in go7007_snd_init in&lt;br/&gt;
     drivers/media/usb/go7007/snd-go7007.c because it did not call&lt;br/&gt;
     snd_card_free for a failure path (bnc#1172458).&lt;/li&gt;
	&lt;li&gt;CVE-2019-16746: Fixed a buffer overflow in net/wireless/nl80211.c,&lt;br/&gt;
     related to invalid length checks for variable elements in a beacon head&lt;br/&gt;
     (bnc#1152107).&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;The following non-security bugs were fixed:&lt;br/&gt;
&lt;a href=&quot;https://lists.suse.com/pipermail/sle-security-updates/2020-August/007216.html&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://lists.suse.com/pipermail/sle-security-updates/2020-August/007216.html&lt;/a&gt;&lt;/p&gt;</description>
                <environment></environment>
        <key id="60280">LU-13858</key>
            <summary>kernel update [SLES15 SP1 4.12.14-197.48.1]</summary>
                <type id="4" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11310&amp;avatarType=issuetype">Improvement</type>
                                            <priority id="4" iconUrl="https://jira.whamcloud.com/images/icons/priorities/minor.svg">Minor</priority>
                        <status id="5" iconUrl="https://jira.whamcloud.com/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="2">Won&apos;t Fix</resolution>
                                        <assignee username="yujian">Jian Yu</assignee>
                                    <reporter username="yujian">Jian Yu</reporter>
                        <labels>
                    </labels>
                <created>Wed, 5 Aug 2020 22:38:51 +0000</created>
                <updated>Mon, 14 Sep 2020 23:29:53 +0000</updated>
                            <resolved>Mon, 14 Sep 2020 23:29:53 +0000</resolved>
                                                                        <due></due>
                            <votes>0</votes>
                                    <watches>1</watches>
                                                                            <comments>
                            <comment id="279570" author="yujian" created="Mon, 14 Sep 2020 23:29:53 +0000"  >&lt;p&gt;A new version is available: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-13962&quot; title=&quot;kernel update [SLES15 SP1 4.12.14-197.56.1]&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-13962&quot;&gt;&lt;del&gt;LU-13962&lt;/del&gt;&lt;/a&gt;&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10011">
                    <name>Related</name>
                                            <outwardlinks description="is related to ">
                                        <issuelink>
            <issuekey id="59519">LU-13658</issuekey>
        </issuelink>
                            </outwardlinks>
                                                                <inwardlinks description="is related to">
                                        <issuelink>
            <issuekey id="60793">LU-13962</issuekey>
        </issuelink>
                            </inwardlinks>
                                    </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                            <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|i01733:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>9223372036854775807</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>