<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 03:04:50 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-13860] kernel update [SLES12 SP4 4.12.14-95.57.1]</title>
                <link>https://jira.whamcloud.com/browse/LU-13860</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;p&gt;The following security bugs were fixed:&lt;/p&gt;
&lt;ul class=&quot;alternate&quot; type=&quot;square&quot;&gt;
	&lt;li&gt;CVE-2020-0305: In cdev_get of char_dev.c, there is a possible&lt;br/&gt;
     use-after-free due to a race condition. This could lead to local&lt;br/&gt;
     escalation of privilege with System execution privileges needed. User&lt;br/&gt;
     interaction is not needed for exploitation (bnc#1174462).&lt;/li&gt;
	&lt;li&gt;CVE-2019-20908: An issue was discovered in drivers/firmware/efi/efi.c&lt;br/&gt;
     where incorrect access permissions for the efivar_ssdt ACPI variable&lt;br/&gt;
     could be used by attackers to bypass lockdown or secure boot&lt;br/&gt;
     restrictions, aka CID-1957a85b0032 (bnc#1173567).&lt;/li&gt;
	&lt;li&gt;CVE-2020-15780: An issue was discovered in drivers/acpi/acpi_configfs.c&lt;br/&gt;
     where injection of malicious ACPI tables via configfs could be used by&lt;br/&gt;
     attackers to bypass lockdown and secure boot restrictions, aka&lt;br/&gt;
     CID-75b0cea7bf30 (bnc#1173573).&lt;/li&gt;
	&lt;li&gt;CVE-2020-15393: usbtest_disconnect in drivers/usb/misc/usbtest.c has a&lt;br/&gt;
     memory leak, aka CID-28ebeb8db770 (bnc#1173514).&lt;/li&gt;
	&lt;li&gt;CVE-2020-12771: btree_gc_coalesce in drivers/md/bcache/btree.c had a&lt;br/&gt;
     deadlock if a coalescing operation fails (bnc#1171732).&lt;/li&gt;
	&lt;li&gt;CVE-2019-16746: net/wireless/nl80211.c did not check the length of&lt;br/&gt;
     variable elements in a beacon head, leading to a buffer overflow&lt;br/&gt;
     (bnc#1152107).&lt;/li&gt;
	&lt;li&gt;CVE-2020-12888: The VFIO PCI driver mishandled attempts to access&lt;br/&gt;
     disabled memory space (bnc#1171868).&lt;/li&gt;
	&lt;li&gt;CVE-2020-10769: A buffer over-read flaw was found in&lt;br/&gt;
     crypto_authenc_extractkeys in crypto/authenc.c in the IPsec&lt;br/&gt;
     Cryptographic algorithm&apos;s module, authenc. When a payload longer than 4&lt;br/&gt;
     bytes, and is not following 4-byte alignment boundary guidelines, it&lt;br/&gt;
     causes a buffer over-read threat, leading to a system crash. This flaw&lt;br/&gt;
     allowed a local attacker with user privileges to cause a denial of&lt;br/&gt;
     service (bnc#1173265).&lt;/li&gt;
	&lt;li&gt;CVE-2020-10773: A kernel stack information leak on s390/s390x was fixed&lt;br/&gt;
     (bnc#1172999).&lt;/li&gt;
	&lt;li&gt;CVE-2020-14416: A race condition in tty-&amp;gt;disc_data handling in the slip&lt;br/&gt;
     and slcan line discipline could lead to a use-after-free, aka&lt;br/&gt;
     CID-0ace17d56824. This affects drivers/net/slip/slip.c and&lt;br/&gt;
     drivers/net/can/slcan.c (bnc#1162002).&lt;/li&gt;
	&lt;li&gt;CVE-2020-10768: Indirect branch speculation could have been enabled&lt;br/&gt;
     after it was force-disabled by the PR_SPEC_FORCE_DISABLE prctl command.&lt;br/&gt;
     (bnc#1172783).&lt;/li&gt;
	&lt;li&gt;CVE-2020-10766: Fixed Rogue cross-process SSBD shutdown, where a Linux&lt;br/&gt;
     scheduler logical bug allows an attacker to turn off the SSBD&lt;br/&gt;
     protection. (bnc#1172781).&lt;/li&gt;
	&lt;li&gt;CVE-2020-10767: Indirect Branch Prediction Barrier was force-disabled&lt;br/&gt;
     when STIBP is unavailable or enhanced IBRS is available. (bnc#1172782).&lt;/li&gt;
	&lt;li&gt;CVE-2020-13974: drivers/tty/vt/keyboard.c had an integer overflow if&lt;br/&gt;
     k_ascii is called several times in a row, aka CID-b86dab054059.&lt;br/&gt;
     (bnc#1172775).&lt;/li&gt;
	&lt;li&gt;CVE-2019-20810: go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c&lt;br/&gt;
     in the Linux kernel did not call snd_card_free for a failure path, which&lt;br/&gt;
     causes a memory leak, aka CID-9453264ef586 (bnc#1172458).&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;The following non-security bugs were fixed:&lt;br/&gt;
&lt;a href=&quot;https://lists.suse.com/pipermail/sle-security-updates/2020-August/007220.html&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://lists.suse.com/pipermail/sle-security-updates/2020-August/007220.html&lt;/a&gt;&lt;/p&gt;</description>
                <environment></environment>
        <key id="60282">LU-13860</key>
            <summary>kernel update [SLES12 SP4 4.12.14-95.57.1]</summary>
                <type id="4" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11310&amp;avatarType=issuetype">Improvement</type>
                                            <priority id="4" iconUrl="https://jira.whamcloud.com/images/icons/priorities/minor.svg">Minor</priority>
                        <status id="5" iconUrl="https://jira.whamcloud.com/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="2">Won&apos;t Fix</resolution>
                                        <assignee username="yujian">Jian Yu</assignee>
                                    <reporter username="yujian">Jian Yu</reporter>
                        <labels>
                    </labels>
                <created>Wed, 5 Aug 2020 22:47:24 +0000</created>
                <updated>Thu, 17 Dec 2020 19:45:18 +0000</updated>
                            <resolved>Thu, 17 Dec 2020 19:45:18 +0000</resolved>
                                                                        <due></due>
                            <votes>0</votes>
                                    <watches>2</watches>
                                                                            <comments>
                            <comment id="284987" author="gerrit" created="Thu, 12 Nov 2020 00:33:56 +0000"  >&lt;p&gt;Jian Yu (yujian@whamcloud.com) uploaded a new patch: &lt;a href=&quot;https://review.whamcloud.com/40619&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/40619&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-13860&quot; title=&quot;kernel update [SLES12 SP4 4.12.14-95.57.1]&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-13860&quot;&gt;&lt;del&gt;LU-13860&lt;/del&gt;&lt;/a&gt; kernel: kernel update SLES12 SP4 &lt;span class=&quot;error&quot;&gt;&amp;#91;4.12.14-95.57.1&amp;#93;&lt;/span&gt;&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: master&lt;br/&gt;
Current Patch Set: 1&lt;br/&gt;
Commit: 3f9b0df86ae4accddfd890b45177e934571a0a15&lt;/p&gt;</comment>
                            <comment id="284988" author="gerrit" created="Thu, 12 Nov 2020 00:37:26 +0000"  >&lt;p&gt;Jian Yu (yujian@whamcloud.com) uploaded a new patch: &lt;a href=&quot;https://review.whamcloud.com/40620&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/40620&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-13860&quot; title=&quot;kernel update [SLES12 SP4 4.12.14-95.57.1]&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-13860&quot;&gt;&lt;del&gt;LU-13860&lt;/del&gt;&lt;/a&gt; kernel: kernel update SLES12 SP4 &lt;span class=&quot;error&quot;&gt;&amp;#91;4.12.14-95.57.1&amp;#93;&lt;/span&gt;&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: b2_12&lt;br/&gt;
Current Patch Set: 1&lt;br/&gt;
Commit: 9ace959d61b9c86e15f8e69803ca6d237af39177&lt;/p&gt;</comment>
                            <comment id="287934" author="yujian" created="Thu, 17 Dec 2020 19:45:18 +0000"  >&lt;p&gt;A new version is available: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-14220&quot; title=&quot;kernel update [SLES12 SP4 4.12.14-95.65.1]&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-14220&quot;&gt;&lt;del&gt;LU-14220&lt;/del&gt;&lt;/a&gt;&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10011">
                    <name>Related</name>
                                            <outwardlinks description="is related to ">
                                        <issuelink>
            <issuekey id="59521">LU-13659</issuekey>
        </issuelink>
                            </outwardlinks>
                                                                <inwardlinks description="is related to">
                                        <issuelink>
            <issuekey id="62003">LU-14220</issuekey>
        </issuelink>
                            </inwardlinks>
                                    </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                            <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|i0173j:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>9223372036854775807</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>