| Revision Date: | 2021-02-11 | Version: | 1 |
| Title: | Security update for the Linux Kernel (Important) |
| Description: |
The SUSE Linux Enterprise 12 SP2 kernel was updated to receive various security and bugfixes.
The following security bugs were fixed:
- CVE-2021-3347: A use-after-free was discovered in the PI futexes during fault handling, allowing local users to execute code in the kernel (bnc#1181349). - CVE-2020-29569: Fixed a potential privilege escalation and information leaks related to the PV block backend, as used by Xen (bnc#1179509). - CVE-2020-29568: Fixed a denial of service issue, related to processing watch events (bnc#1179508). - CVE-2020-25211: Fixed a flaw where a local attacker was able to inject conntrack netlink configuration that could cause a denial of service or trigger the use of incorrect protocol numbers in ctnetlink_parse_tuple_filter (bnc#1176395). - CVE-2020-0444: Fixed a bad kfree due to a logic error in audit_data_to_entry (bnc#1180027). - CVE-2020-0465: Fixed multiple missing bounds checks in hid-multitouch.c that could have led to local privilege escalation (bnc#1180029). - CVE-2020-0466: Fixed a use-after-free due to a logic error in do_epoll_ctl and ep_loop_check_proc of eventpoll.c (bnc#1180031). - CVE-2020-15436: Fixed a use after free vulnerability in fs/block_dev.c which could have allowed local users to gain privileges or cause a denial of service (bsc#1179141). - CVE-2020-27068: Fixed an out-of-bounds read due to a missing bounds check in the nl80211_policy policy of nl80211.c (bnc#1180086). - CVE-2020-27777: Fixed a privilege escalation in the Run-Time Abstraction Services (RTAS) interface, affecting guests running on top of PowerVM or KVM hypervisors (bnc#1179107). - CVE-2020-27786: Fixed an out-of-bounds write in the MIDI implementation (bnc#1179601). - CVE-2020-27825: Fixed a race in the trace_open and buffer resize calls (bsc#1179960). - CVE-2020-29660: Fixed a locking inconsistency in the tty subsystem that may have allowed a read-after-free attack against TIOCGSID (bnc#1179745). - CVE-2020-29661: Fixed a locking issue in the tty subsystem that allowed a use-after-free attack against TIOCSPGRP (bsc#1179745). - CVE-2020-28974: Fixed a slab-out-of-bounds read in fbcon which could have been used by local attackers to read privileged information or potentially crash the kernel (bsc#1178589). - CVE-2020-28915: Fixed a buffer over-read in the fbcon code which could have been used by local attackers to read kernel memory (bsc#1178886). - CVE-2020-25669: Fixed a use-after-free read in sunkbd_reinit() (bsc#1178182). - CVE-2020-25285: A race condition between hugetlb sysctl handlers in mm/hugetlb.c could be used by local attackers to corrupt memory, cause a NULL pointer dereference, or possibly have unspecified other impact (bnc#1176485 ). - CVE-2020-15437: Fixed a null pointer dereference which could have allowed local users to cause a denial of service (bsc#1179140). - CVE-2020-36158: Fixed a potential remote code execution in the Marvell mwifiex driver (bsc#1180559). - CVE-2020-11668: Fixed the mishandling of invalid descriptors in the Xirlink camera USB driver (bnc#1168952). - CVE-2020-25668: Fixed a use-after-free in con_font_op() (bsc#1178123). - CVE-2020-27673: Fixed an issue where rogue guests could have caused denial of service of Dom0 via high frequency events (XSA-332 bsc#1177411) - CVE-2019-20934: Fixed a use-after-free in show_numa_stats() because NUMA fault statistics were inappropriately freed (bsc#1179663). - CVE-2019-19063: Fixed two memory leaks in the rtl_usb_probe() which could eventually have allowed attackers to cause a denial of service (memory consumption) (bnc#1157298 ). - CVE-2019-6133: Fixed an issue where the 'start time' protection mechanism could have been bypassed and therefore authorization decisions are improperly cached (bsc#1128172).
The following non-security bugs were fixed:
- HID: Fix slab-out-of-bounds read in hid_field_extract (bsc#1180052). - epoll: Keep a reference on files added to the check list (bsc#1180031). - fix regression in 'epoll: Keep a reference on files added to the check list' (bsc#1180031, git-fixes). - futex,rt_mutex: Fix rt_mutex_cleanup_proxy_lock() (bsc#969755). - futex,rt_mutex: Introduce rt_mutex_init_waiter() (bsc#969755). - futex,rt_mutex: Provide futex specific rt_mutex API (bsc#969755). - futex,rt_mutex: Restructure rt_mutex_finish_proxy_lock() (bsc#969755). - futex: Avoid freeing an active timer (bsc#969755). - futex: Avoid violating the 10th rule of futex (bsc#969755). - futex: Change locking rules (bsc#969755). - futex: Do not enable IRQs unconditionally in put_pi_state() (bsc#969755). - futex: Drop hb->lock before enqueueing on the rtmutex (bsc#969755). - futex: Fix OWNER_DEAD fixup (bsc#969755). - futex: Fix incorrect should_fail_futex() handling (bsc#969755). - futex: Fix more put_pi_state() vs. exit_pi_state_list() races (bsc#969755). - futex: Fix pi_state->owner serialization (bsc#969755). - futex: Fix small (and harmless looking) inconsistencies (bsc#969755). - futex: Futex_unlock_pi() determinism (bsc#969755). - futex: Handle early deadlock return correctly (bsc#969755). - futex: Handle transient 'ownerless' rtmutex state correctly (bsc#969755). - futex: Pull rt_mutex_futex_unlock() out from under hb->lock (bsc#969755). - futex: Rework futex_lock_pi() to use rt_mutex_*_proxy_lock() (bsc#969755). - futex: Rework inconsistent rt_mutex/futex_q state (bsc#969755). - locking/futex: Allow low-level atomic operations to return -EAGAIN (bsc#969755). - mm/userfaultfd: do not access vma->vm_mm after calling handle_userfault() (bsc#1179204).
|
| Family: | unix | Class: | patch |
| Status: | | Reference(s): | 1019649 1021803 1023078 1023079 1025029 1025035 1025084 1025985 1032509 1034570 1034571 1034572 1034574 1039042 1047536 1069496 1069702 1070805 1070943 1084521 1084524 1084532 1121826 1121872 1124847 1131945 1132160 1141093 1157298 1168952 1173942 1176395 1176485 1177411 1178123 1178182 1178589 1178622 1178886 1179107 1179140 1179141 1179204 1179419 1179508 1179509 1179601 1179616 1179663 1179666 1179745 1179877 1179960 1179961 1180008 1180027 1180028 1180029 1180030 1180031 1180032 1180052 1180086 1180559 1180562 1181349 814241 843509 858831 879138 952099 953516 953521 957812 961642 961645 969755 CVE-2013-2003 CVE-2013-2061 CVE-2014-9756 CVE-2015-3195 CVE-2015-3294 CVE-2015-7805 CVE-2015-8899 CVE-2016-0777 CVE-2016-0778 CVE-2016-10324 CVE-2016-10325 CVE-2016-10326 CVE-2016-9577 CVE-2016-9578 CVE-2017-1000405 CVE-2017-16939 CVE-2017-2624 CVE-2017-7853 CVE-2018-1000120 CVE-2018-1000121 CVE-2018-1000122 CVE-2019-10894 CVE-2019-10895 CVE-2019-10896 CVE-2019-10899 CVE-2019-10901 CVE-2019-10903 CVE-2019-11068 CVE-2019-13050 CVE-2019-19063 CVE-2019-20934 CVE-2019-6133 CVE-2020-0444 CVE-2020-0465 CVE-2020-0466 CVE-2020-11668 CVE-2020-15436 CVE-2020-15437 CVE-2020-25211 CVE-2020-25285 CVE-2020-25668 CVE-2020-25669 CVE-2020-27068 CVE-2020-27673 CVE-2020-27777 CVE-2020-27786 CVE-2020-27825 CVE-2020-28915 CVE-2020-28974 CVE-2020-29568 CVE-2020-29569 CVE-2020-29660 CVE-2020-29661 CVE-2020-36158 CVE-2021-3347 SUSE-SU-2015:1979-1 SUSE-SU-2015:2275-1 SUSE-SU-2016:0120-1 SUSE-SU-2017:0392-1 SUSE-SU-2017:1187-1 SUSE-SU-2017:1675-1 SUSE-SU-2017:2744-1 SUSE-SU-2017:3225-1 SUSE-SU-2018:0769-1 SUSE-SU-2019:1038-1 SUSE-SU-2019:1232-1 SUSE-SU-2019:2480-1 SUSE-SU-2021:0437-1
|
| Platform(s): | openSUSE Leap 15.0 openSUSE Leap 15.1 SUSE Linux Enterprise Desktop 11 SP2 SUSE Linux Enterprise Desktop 11 SP3 SUSE Linux Enterprise Desktop 11 SP4 SUSE Linux Enterprise Desktop 12 SP2 SUSE Linux Enterprise Desktop 12 SP3 SUSE Linux Enterprise Desktop 12 SP4 SUSE Linux Enterprise Server 12 SP1 SUSE Linux Enterprise Server 12 SP1-LTSS SUSE Linux Enterprise Server 12 SP2 SUSE Linux Enterprise Server 12 SP2-BCL SUSE Linux Enterprise Server 12 SP2-ESPOS SUSE Linux Enterprise Server 12 SP2-LTSS SUSE Linux Enterprise Server 12 SP3 SUSE Linux Enterprise Server 12 SP3-BCL SUSE Linux Enterprise Server 12 SP3-ESPOS SUSE Linux Enterprise Server 12 SP3-LTSS SUSE Linux Enterprise Server 12 SP3-TERADATA SUSE Linux Enterprise Server 12 SP4 SUSE OpenStack Cloud 6 SUSE OpenStack Cloud 7 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud Crowbar 8
| Product(s): | |
| Definition Synopsis |
| openSUSE Leap 15.0 is installed AND enscript-1.6.6-lp150.1 is installed
|
| Definition Synopsis |
| openSUSE Leap 15.1 is installed
AND Package Information
MozillaThunderbird-60.7.2-lp151.2.7 is installed
OR MozillaThunderbird-buildsymbols-60.7.2-lp151.2.7 is installed
OR MozillaThunderbird-translations-common-60.7.2-lp151.2.7 is installed
OR MozillaThunderbird-translations-other-60.7.2-lp151.2.7 is installed
|
| Definition Synopsis |
| SUSE Linux Enterprise Desktop 11 SP2 is installed
AND Package Information
kernel-default-3.0.101-0.7.17 is installed
OR kernel-default-base-3.0.101-0.7.17 is installed
OR kernel-default-devel-3.0.101-0.7.17 is installed
OR kernel-default-extra-3.0.101-0.7.17 is installed
OR kernel-pae-3.0.101-0.7.17 is installed
OR kernel-pae-base-3.0.101-0.7.17 is installed
OR kernel-pae-devel-3.0.101-0.7.17 is installed
OR kernel-pae-extra-3.0.101-0.7.17 is installed
OR kernel-source-3.0.101-0.7.17 is installed
OR kernel-syms-3.0.101-0.7.17 is installed
OR kernel-trace-3.0.101-0.7.17 is installed
OR kernel-trace-base-3.0.101-0.7.17 is installed
OR kernel-trace-devel-3.0.101-0.7.17 is installed
OR kernel-trace-extra-3.0.101-0.7.17 is installed
OR kernel-xen-3.0.101-0.7.17 is installed
OR kernel-xen-base-3.0.101-0.7.17 is installed
OR kernel-xen-devel-3.0.101-0.7.17 is installed
OR kernel-xen-extra-3.0.101-0.7.17 is installed
OR xen-kmp-default-4.1.6_04_3.0.101_0.7.17-0.5 is installed
OR xen-kmp-pae-4.1.6_04_3.0.101_0.7.17-0.5 is installed
OR xen-kmp-trace-4.1.6_04_3.0.101_0.7.17-0.5 is installed
|
| Definition Synopsis |
| SUSE Linux Enterprise Desktop 11 SP3 is installed
AND openvpn-2.0.9-143.40 is installed
|
| Definition Synopsis |
| SUSE Linux Enterprise Desktop 11 SP4 is installed
AND Package Information
libsndfile-1.0.20-2.10 is installed
OR libsndfile-32bit-1.0.20-2.10 is installed
|
| Definition Synopsis |
| SUSE Linux Enterprise Desktop 12 SP2 is installed
AND Package Information
xorg-x11-server-7.6_1.18.3-71 is installed
OR xorg-x11-server-extra-7.6_1.18.3-71 is installed
|
| Definition Synopsis |
| SUSE Linux Enterprise Desktop 12 SP3 is installed
AND dnsmasq-2.76-17 is installed
|
| Definition Synopsis |
| SUSE Linux Enterprise Desktop 12 SP4 is installed
AND Package Information
libxslt-1.1.28-17.3 is installed
OR libxslt-tools-1.1.28-17.3 is installed
OR libxslt1-1.1.28-17.3 is installed
OR libxslt1-32bit-1.1.28-17.3 is installed
|
| Definition Synopsis |
| SUSE Linux Enterprise Server 12 SP1 is installed
AND Package Information
libgssglue1-0.4-3 is installed
OR libgssglue1-32bit-0.4-3 is installed
|
| Definition Synopsis |
| SUSE Linux Enterprise Server 12 SP1-LTSS is installed
AND Package Information
openvpn-2.3.8-16.17 is installed
OR openvpn-auth-pam-plugin-2.3.8-16.17 is installed
|
| Definition Synopsis |
| SUSE Linux Enterprise Server 12 SP2 is installed
AND Package Information
cpio-2.11-29 is installed
OR cpio-lang-2.11-29 is installed
|
| Definition Synopsis |
| SUSE Linux Enterprise Server 12 SP2-BCL is installed
AND Package Information
ghostscript-9.25-23.13 is installed
OR ghostscript-x11-9.25-23.13 is installed
|
| Definition Synopsis |
| SUSE Linux Enterprise Server 12 SP2-ESPOS is installed
AND Package Information
kgraft-patch-4_4_121-92_73-default-8-2 is installed
OR kgraft-patch-SLE12-SP2_Update_21-8-2 is installed
|
| Definition Synopsis |
| SUSE Linux Enterprise Server 12 SP2-LTSS is installed
AND Package Information
kernel-default-4.4.121-92.149.1 is installed
OR kernel-default-base-4.4.121-92.149.1 is installed
OR kernel-default-devel-4.4.121-92.149.1 is installed
OR kernel-default-man-4.4.121-92.149.1 is installed
OR kernel-devel-4.4.121-92.149.1 is installed
OR kernel-macros-4.4.121-92.149.1 is installed
OR kernel-source-4.4.121-92.149.1 is installed
OR kernel-syms-4.4.121-92.149.1 is installed
OR kgraft-patch-4_4_121-92_149-default-1-3.3.1 is installed
|
| Definition Synopsis |
| SUSE Linux Enterprise Server 12 SP3 is installed
AND Package Information
kernel-default-4.4.114-94.11 is installed
OR kernel-default-base-4.4.114-94.11 is installed
OR kernel-default-devel-4.4.114-94.11 is installed
OR kernel-default-man-4.4.114-94.11 is installed
OR kernel-devel-4.4.114-94.11 is installed
OR kernel-macros-4.4.114-94.11 is installed
OR kernel-source-4.4.114-94.11 is installed
OR kernel-syms-4.4.114-94.11 is installed
|
| Definition Synopsis |
| SUSE Linux Enterprise Server 12 SP3-BCL is installed
AND Package Information
libssh2-1-1.4.3-20.9 is installed
OR libssh2-1-32bit-1.4.3-20.9 is installed
OR libssh2_org-1.4.3-20.9 is installed
|
| Definition Synopsis |
| SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
AND Package Information
libsqlite3-0-3.8.10.2-9.15 is installed
OR libsqlite3-0-32bit-3.8.10.2-9.15 is installed
OR sqlite3-3.8.10.2-9.15 is installed
|
| Definition Synopsis |
| SUSE Linux Enterprise Server 12 SP3-LTSS is installed
AND Package Information
kgraft-patch-4_4_140-94_42-default-10-2 is installed
OR kgraft-patch-SLE12-SP3_Update_15-10-2 is installed
|
| Definition Synopsis |
| SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
AND Package Information
libIlmImf-Imf_2_1-21-2.1.0-6.13 is installed
OR openexr-2.1.0-6.13 is installed
|
| Definition Synopsis |
| SUSE Linux Enterprise Server 12 SP4 is installed
AND Package Information
bzip2-1.0.6-29 is installed
OR bzip2-doc-1.0.6-29 is installed
OR libbz2-1-1.0.6-29 is installed
OR libbz2-1-32bit-1.0.6-29 is installed
|
| Definition Synopsis |
| SUSE OpenStack Cloud 6 is installed
AND mongodb-2.4.14-1 is installed
|
| Definition Synopsis |
| SUSE OpenStack Cloud 7 is installed
AND Package Information
libjavascriptcoregtk-4_0-18-2.22.5-2.32 is installed
OR libwebkit2gtk-4_0-37-2.22.5-2.32 is installed
OR libwebkit2gtk3-lang-2.22.5-2.32 is installed
OR typelib-1_0-JavaScriptCore-4_0-2.22.5-2.32 is installed
OR typelib-1_0-WebKit2-4_0-2.22.5-2.32 is installed
OR typelib-1_0-WebKit2WebExtension-4_0-2.22.5-2.32 is installed
OR webkit2gtk-4_0-injected-bundles-2.22.5-2.32 is installed
OR webkit2gtk3-2.22.5-2.32 is installed
OR webkit2gtk3-devel-2.22.5-2.32 is installed
|
| Definition Synopsis |
| SUSE OpenStack Cloud 8 is installed
AND Package Information
java-1_8_0-ibm-1.8.0_sr5.40-30.54 is installed
OR java-1_8_0-ibm-alsa-1.8.0_sr5.40-30.54 is installed
OR java-1_8_0-ibm-plugin-1.8.0_sr5.40-30.54 is installed
|
| Definition Synopsis |
| SUSE OpenStack Cloud Crowbar 8 is installed
AND Package Information
libjpeg-turbo-1.5.3-31.19 is installed
OR libjpeg62-62.2.0-31.19 is installed
OR libjpeg62-32bit-62.2.0-31.19 is installed
OR libjpeg62-turbo-1.5.3-31.19 is installed
OR libjpeg8-8.1.2-31.19 is installed
OR libjpeg8-32bit-8.1.2-31.19 is installed
OR libturbojpeg0-8.1.2-31.19 is installed
|