<!-- 
RSS generated by JIRA (9.4.14#940014-sha1:734e6822bbf0d45eff9af51f82432957f73aa32c) at Sat Feb 10 03:22:46 UTC 2024

It is possible to restrict the fields that are returned in this document by specifying the 'field' parameter in your request.
For example, to request only the issue key and summary append 'field=key&field=summary' to the URL of your request.
-->
<rss version="0.92" >
<channel>
    <title>Whamcloud Community JIRA</title>
    <link>https://jira.whamcloud.com</link>
    <description>This file is an XML representation of an issue</description>
    <language>en-us</language>    <build-info>
        <version>9.4.14</version>
        <build-number>940014</build-number>
        <build-date>05-12-2023</build-date>
    </build-info>


<item>
            <title>[LU-15960] kernel update [SLES12 SP5 4.12.14-122.121.2]</title>
                <link>https://jira.whamcloud.com/browse/LU-15960</link>
                <project id="10000" key="LU">Lustre</project>
                    <description>&lt;p&gt;   The SUSE Linux Enterprise 12 SP5 kernel was updated to receive various&lt;br/&gt;
   security and bugfixes.&lt;/p&gt;


&lt;p&gt;   The following security bugs were fixed:&lt;/p&gt;

&lt;ul class=&quot;alternate&quot; type=&quot;square&quot;&gt;
	&lt;li&gt;CVE-2022-28748: Fixed memory lead over the network by ax88179_178a&lt;br/&gt;
     devices (bsc#1196018).&lt;/li&gt;
	&lt;li&gt;CVE-2022-28356: Fixed a refcount leak bug found in net/llc/af_llc.c&lt;br/&gt;
     (bnc#1197391).&lt;/li&gt;
	&lt;li&gt;CVE-2022-1516: Fixed null-ptr-deref caused by x25_disconnect&lt;br/&gt;
     (bsc#1199012).&lt;/li&gt;
	&lt;li&gt;CVE-2022-1419: Fixed a concurrency use-after-free in&lt;br/&gt;
     vgem_gem_dumb_create (bsc#1198742).&lt;/li&gt;
	&lt;li&gt;CVE-2022-1353: Fixed access controll to kernel memory in the&lt;br/&gt;
     pfkey_register function in net/key/af_key.c (bnc#1198516).&lt;/li&gt;
	&lt;li&gt;CVE-2022-1280: Fixed a use-after-free vulnerability in drm_lease_held in&lt;br/&gt;
     drivers/gpu/drm/drm_lease.c (bnc#1197914).&lt;/li&gt;
	&lt;li&gt;CVE-2022-1011: Fixed a use-after-free flaw inside the FUSE filesystem in&lt;br/&gt;
     the way a user triggers write(). This flaw allowed a local user to gain&lt;br/&gt;
     unauthorized access to data from the FUSE filesystem, resulting in&lt;br/&gt;
     privilege escalation (bnc#1197343).&lt;/li&gt;
	&lt;li&gt;CVE-2021-43389: Fixed an array-index-out-of-bounds flaw in the&lt;br/&gt;
     detach_capi_ctr function in drivers/isdn/capi/kcapi.c (bnc#1191958).&lt;/li&gt;
	&lt;li&gt;CVE-2021-38208: Fixed a denial of service (NULL pointer dereference and&lt;br/&gt;
     BUG) by making a getsockname call after a certain type of failure of a&lt;br/&gt;
     bind call (bnc#1187055).&lt;/li&gt;
	&lt;li&gt;CVE-2021-20321: Fixed a race condition accessing file object in the&lt;br/&gt;
     OverlayFS subsystem in the way users do rename in specific way with&lt;br/&gt;
     OverlayFS. A local user could have used this flaw to crash the system&lt;br/&gt;
     (bnc#1191647).&lt;/li&gt;
	&lt;li&gt;CVE-2021-20292: Fixed object validation prior to performing operations&lt;br/&gt;
     on the object in nouveau_sgdma_create_ttm in Nouveau DRM subsystem&lt;br/&gt;
     (bnc#1183723).&lt;/li&gt;
	&lt;li&gt;CVE-2019-20811: Fixed issue in rx_queue_add_kobject() and&lt;br/&gt;
     netdev_queue_add_kobject() in net/core/net-sysfs.c, where a reference&lt;br/&gt;
     count is mishandled (bnc#1172456).&lt;/li&gt;
	&lt;li&gt;CVE-2018-7755: Fixed an issue in the fd_locked_ioctl function in&lt;br/&gt;
     drivers/block/floppy.c. The floppy driver will copy a kernel pointer to&lt;br/&gt;
     user memory in response to the FDGETPRM ioctl. An attacker can send the&lt;br/&gt;
     FDGETPRM ioctl and use the obtained kernel pointer to discover the&lt;br/&gt;
     location of kernel code and data and bypass kernel security protections&lt;br/&gt;
     such as KASLR (bnc#1084513).&lt;/li&gt;
&lt;/ul&gt;


&lt;p&gt;   The following non-security bugs were fixed:&lt;br/&gt;
   &lt;a href=&quot;https://lists.suse.com/pipermail/sle-security-updates/2022-May/011035.html&quot; class=&quot;external-link&quot; target=&quot;_blank&quot; rel=&quot;nofollow noopener&quot;&gt;https://lists.suse.com/pipermail/sle-security-updates/2022-May/011035.html&lt;/a&gt;&lt;/p&gt;</description>
                <environment></environment>
        <key id="70807">LU-15960</key>
            <summary>kernel update [SLES12 SP5 4.12.14-122.121.2]</summary>
                <type id="4" iconUrl="https://jira.whamcloud.com/secure/viewavatar?size=xsmall&amp;avatarId=11310&amp;avatarType=issuetype">Improvement</type>
                                            <priority id="4" iconUrl="https://jira.whamcloud.com/images/icons/priorities/minor.svg">Minor</priority>
                        <status id="5" iconUrl="https://jira.whamcloud.com/images/icons/statuses/resolved.png" description="A resolution has been taken, and it is awaiting verification by reporter. From here issues are either reopened, or are closed.">Resolved</status>
                    <statusCategory id="3" key="done" colorName="success"/>
                                    <resolution id="2">Won&apos;t Fix</resolution>
                                        <assignee username="yujian">Jian Yu</assignee>
                                    <reporter username="yujian">Jian Yu</reporter>
                        <labels>
                    </labels>
                <created>Sat, 18 Jun 2022 00:15:41 +0000</created>
                <updated>Thu, 11 Aug 2022 17:53:58 +0000</updated>
                            <resolved>Thu, 11 Aug 2022 17:53:58 +0000</resolved>
                                                                        <due></due>
                            <votes>0</votes>
                                    <watches>2</watches>
                                                                            <comments>
                            <comment id="343395" author="yujian" created="Thu, 11 Aug 2022 17:53:58 +0000"  >&lt;p&gt;A new version is available in &lt;a href=&quot;https://jira.whamcloud.com/browse/LU-16093&quot; title=&quot;kernel update [SLES12 SP5 4.12.14-122.130.1]&quot; class=&quot;issue-link&quot; data-issue-key=&quot;LU-16093&quot;&gt;&lt;del&gt;LU-16093&lt;/del&gt;&lt;/a&gt;.&lt;/p&gt;</comment>
                    </comments>
                <issuelinks>
                            <issuelinktype id="10011">
                    <name>Related</name>
                                            <outwardlinks description="is related to ">
                                        <issuelink>
            <issuekey id="69855">LU-15773</issuekey>
        </issuelink>
                            </outwardlinks>
                                                                <inwardlinks description="is related to">
                                        <issuelink>
            <issuekey id="71841">LU-16093</issuekey>
        </issuelink>
                            </inwardlinks>
                                    </issuelinktype>
                    </issuelinks>
                <attachments>
                    </attachments>
                <subtasks>
                    </subtasks>
                <customfields>
                                                                                                                                                                                            <customfield id="customfield_10890" key="com.atlassian.jira.plugins.jira-development-integration-plugin:devsummary">
                        <customfieldname>Development</customfieldname>
                        <customfieldvalues>
                            
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                        <customfield id="customfield_10390" key="com.pyxis.greenhopper.jira:gh-lexo-rank">
                        <customfieldname>Rank</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>1|i02sif:</customfieldvalue>

                        </customfieldvalues>
                    </customfield>
                                                                <customfield id="customfield_10090" key="com.pyxis.greenhopper.jira:gh-global-rank">
                        <customfieldname>Rank (Obsolete)</customfieldname>
                        <customfieldvalues>
                            <customfieldvalue>9223372036854775807</customfieldvalue>
                        </customfieldvalues>
                    </customfield>
                                                                                                                                                                                                                                                                                                                                                                                                                </customfields>
    </item>
</channel>
</rss>