<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 03:14:00 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-14931] kernel update [SLES15 SP1 4.12.14-197.99.1]</title>
                <link>https://jira.whamcloud.com/browse/LU-14931</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;p&gt;   The following security bugs were fixed:&lt;/p&gt;

&lt;ul class=&quot;alternate&quot; type=&quot;square&quot;&gt;
	&lt;li&gt;CVE-2021-22555: Fixed an heap out-of-bounds write in&lt;br/&gt;
     net/netfilter/x_tables.c that could allow local provilege escalation.&lt;br/&gt;
     (bsc#1188116)&lt;/li&gt;
	&lt;li&gt;CVE-2021-33624: Fixed a bug which allows unprivileged BPF program to&lt;br/&gt;
     leak the contents of arbitrary kernel memory (and therefore, of all&lt;br/&gt;
     physical memory) via a side-channel. (bsc#1187554)&lt;/li&gt;
	&lt;li&gt;CVE-2021-0605: Fixed an out-of-bounds read which could lead to local&lt;br/&gt;
     information disclosure in the kernel with System execution privileges&lt;br/&gt;
     needed. (bsc#1187601)&lt;/li&gt;
	&lt;li&gt;CVE-2021-0512: Fixed a possible out-of-bounds write which could lead to&lt;br/&gt;
     local escalation of privilege with no additional execution privileges&lt;br/&gt;
     needed. (bsc#1187595)&lt;/li&gt;
	&lt;li&gt;CVE-2020-26558: Fixed a flaw in the Bluetooth LE and BR/EDR secure&lt;br/&gt;
     pairing that could permit a nearby man-in-the-middle attacker to&lt;br/&gt;
     identify the Passkey used during pairing. (bnc#1179610)&lt;/li&gt;
	&lt;li&gt;CVE-2021-34693: Fixed a bug in net/can/bcm.c which could allow local&lt;br/&gt;
     users to obtain sensitive information from kernel stack memory because&lt;br/&gt;
     parts of a data structure are uninitialized. (bsc#1187452)&lt;/li&gt;
	&lt;li&gt;CVE-2021-0129: Fixed an improper access control in BlueZ that may have&lt;br/&gt;
     allowed an authenticated user to potentially enable information&lt;br/&gt;
     disclosure via adjacent access. (bnc#1186463)&lt;/li&gt;
	&lt;li&gt;CVE-2020-36386: Fixed an out-of-bounds read in&lt;br/&gt;
     hci_extended_inquiry_result_evt. (bsc#1187038)&lt;/li&gt;
	&lt;li&gt;CVE-2020-24588: Fixed a bug that could allow an adversary to abuse&lt;br/&gt;
     devices that support receiving non-SSP A-MSDU frames to inject arbitrary&lt;br/&gt;
     network packets. (bsc#1185861 bsc#1185863)&lt;/li&gt;
	&lt;li&gt;CVE-2021-33909: Fixed an out-of-bounds write in the filesystem layer&lt;br/&gt;
     that allows to andobtain full root privileges. (bsc#1188062)&lt;/li&gt;
	&lt;li&gt;CVE-2021-3609: Fixed a race condition in the CAN BCM networking protocol&lt;br/&gt;
     which allows for local privilege escalation. (bsc#1187215)&lt;/li&gt;
	&lt;li&gt;CVE-2020-36385: Fixed a use-after-free flaw in ucma.c which allows for&lt;br/&gt;
     local privilege escalation. (bsc#1187050)&lt;/li&gt;
	&lt;li&gt;CVE-2021-33200: Fix leakage of uninitialized bpf stack under&lt;br/&gt;
     speculation. (bsc#1186484)&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;   The following non-security bugs were fixed:&lt;/p&gt;

&lt;ul class=&quot;alternate&quot; type=&quot;square&quot;&gt;
	&lt;li&gt;af_packet: fix the tx skb protocol in raw sockets with ETH_P_ALL&lt;br/&gt;
     (bsc#1176081).&lt;/li&gt;
	&lt;li&gt;kabi: preserve struct header_ops after bsc#1176081 fix (bsc#1176081).&lt;/li&gt;
	&lt;li&gt;net: Do not set transport offset to invalid value (bsc#1176081).&lt;/li&gt;
	&lt;li&gt;net: Introduce parse_protocol header_ops callback (bsc#1176081).&lt;/li&gt;
	&lt;li&gt;net/ethernet: Add parse_protocol header_ops support (bsc#1176081).&lt;/li&gt;
	&lt;li&gt;net/mlx5e: Remove the wrong assumption about transport offset&lt;br/&gt;
     (bsc#1176081).&lt;/li&gt;
	&lt;li&gt;net/mlx5e: Trust kernel regarding transport offset (bsc#1176081).&lt;/li&gt;
	&lt;li&gt;net/packet: Ask driver for protocol if not provided by user&lt;br/&gt;
     (bsc#1176081).&lt;/li&gt;
	&lt;li&gt;net/packet: Remove redundant skb-&amp;gt;protocol set (bsc#1176081).&lt;/li&gt;
	&lt;li&gt;resource: Fix find_next_iomem_res() iteration issue (bsc#1181193).&lt;/li&gt;
	&lt;li&gt;scsi: scsi_dh_alua: Retry RTPG on a different path after failure&lt;br/&gt;
     (bsc#1174978 bsc#1185701).&lt;/li&gt;
	&lt;li&gt;SUNRPC in case of backlog, hand free slots directly to waiting task&lt;br/&gt;
     (bsc#1185428).&lt;/li&gt;
	&lt;li&gt;SUNRPC: More fixes for backlog congestion (bsc#1185428).&lt;/li&gt;
	&lt;li&gt;x86/crash: Add e820 reserved ranges to kdump kernel&apos;s e820 table&lt;br/&gt;
     (bsc#1181193).&lt;/li&gt;
	&lt;li&gt;x86/debug: Extend the lower bound of crash kernel low reservations&lt;br/&gt;
     (bsc#1153720).&lt;/li&gt;
	&lt;li&gt;x86/e820, ioport: Add a new I/O resource descriptor IORES_DESC_RESERVED&lt;br/&gt;
     (bsc#1181193).&lt;/li&gt;
	&lt;li&gt;x86/mm: Rework ioremap resource mapping determination (bsc#1181193).&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;&lt;a href=&quot;https://lists.suse.com/pipermail/sle-security-updates/2021-July/009190.html&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://lists.suse.com/pipermail/sle-security-updates/2021-July/009190.html&lt;/a&gt;&lt;/p&gt;</description>
                <environment></environment>
        <key id="65609">LU-14931</key>
            <summary>kernel update [SLES15 SP1 4.12.14-197.99.1]</summary>
                <type id="4" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11310&amp;avatarType=issuetype">Improvement</type>
                                            <priority id="4" iconUrl="https://jira.whamcloud.com/images/icons/priorities/minor.svg">Minor</priority>
                        <status id="6" iconUrl="https://jira.whamcloud.com/images/icons/statuses/closed.png" description="The issue is considered finished, the resolution is correct. Issues which are closed can be reopened.">Closed</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="2">Won&apos;t Fix</resolution>
                                        <assignee username="yujian">Jian Yu</assignee>
                                    <reporter username="yujian">Jian Yu</reporter>
                        <labels>
                    </labels>
                <created>Wed, 11 Aug 2021 19:52:59 +0000</created>
                <updated>Thu, 28 Oct 2021 17:11:58 +0000</updated>
                            <resolved>Thu, 28 Oct 2021 17:11:58 +0000</resolved>
                                                                        <due></due>
                            <votes>0</votes>
                                    <watches>2</watches>
                                                                            <comments>
                            <comment id="312130" author="gerrit" created="Mon, 6 Sep 2021 01:38:13 +0000"  >&lt;p&gt;&quot;Jian Yu &amp;lt;yujian@whamcloud.com&amp;gt;&quot; uploaded a new patch: &lt;a href=&quot;https://review.whamcloud.com/44847&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://review.whamcloud.com/44847&lt;/a&gt;&lt;br/&gt;
Subject: &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-14931&quot; title=&quot;kernel update [SLES15 SP1 4.12.14-197.99.1]&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-14931&quot;&gt;&lt;del&gt;LU-14931&lt;/del&gt;&lt;/a&gt; kernel: kernel update SLES15 SP1 &lt;span class=&quot;error&quot;&gt;&amp;#91;4.12.14-197.99.1&amp;#93;&lt;/span&gt;&lt;br/&gt;
Project: fs/lustre-release&lt;br/&gt;
Branch: master&lt;br/&gt;
Current Patch Set: 1&lt;br/&gt;
Commit: 1deb88e9ea325f5fa57dbf0d96c0bc8b5fced479&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10011">
                    <name>Related</name>
                                            <outwardlinks description="is related to ">
                                        <issuelink>
            <issuekey id="65317">LU-14872</issuekey>
        </issuelink>
                            </outwardlinks>
                                                        </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                            <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|i021jj:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>9223372036854775807</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>