Revision Date: | 2020-12-01 | Version: | 1 |
Title: | Security update for the Linux Kernel (Important) |
Description: |
The SUSE Linux Enterprise 12 SP3 kernel was updated to receive various security and bug fixes.
The following security bugs were fixed:
- CVE-2020-25705: A flaw in the way reply ICMP packets are limited in was found that allowed to quickly scan open UDP ports. This flaw allowed an off-path remote user to effectively bypassing source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software and services that rely on UDP source port randomization (like DNS) are indirectly affected as well. Kernel versions may be vulnerable to this issue (bsc#1175721, bsc#1178782). - CVE-2020-25668: Fixed a use-after-free in con_font_op() (bsc#1178123). - CVE-2020-25656: Fixed a concurrency use-after-free in vt_do_kdgkb_ioctl (bnc#1177766). - CVE-2020-14351: Fixed a race in the perf_mmap_close() function (bsc#1177086). - CVE-2020-8694: Restricted energy meter to root access (bsc#1170415). - CVE-2020-12352: Fixed an information leak when processing certain AMP packets aka 'BleedingTooth' (bsc#1177725). - CVE-2020-25645: Fixed an issue which traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted (bsc#1177511). - CVE-2020-14381: Fixed a use-after-free in the fast user mutex (futex) wait operation, which could have lead to memory corruption and possibly privilege escalation (bsc#1176011). - CVE-2020-25212: Fixed A TOCTOU mismatch in the NFS client code which could have been used by local attackers to corrupt memory (bsc#1176381). - CVE-2020-14390: Fixed an out-of-bounds memory write leading to memory corruption or a denial of service when changing screen size (bnc#1176235). - CVE-2020-25643: Fixed a memory corruption and a read overflow which could have caused by improper input validation in the ppp_cp_parse_cr function (bsc#1177206). - CVE-2020-25641: Fixed a zero-length biovec request issued by the block subsystem could have caused the kernel to enter an infinite loop, causing a denial of service (bsc#1177121). - CVE-2020-26088: Fixed an improper CAP_NET_RAW check in NFC socket creation could have been used by local attackers to create raw sockets, bypassing security mechanisms (bsc#1176990). - CVE-2020-0432: Fixed an out of bounds write due to an integer overflow (bsc#1176721). - CVE-2020-0431: Fixed an out of bounds write due to a missing bounds check (bsc#1176722). - CVE-2020-0427: Fixed an out of bounds read due to a use after free (bsc#1176725). - CVE-2020-0404: Fixed a linked list corruption due to an unusual root cause (bsc#1176423). - CVE-2020-25284: Fixed an incomplete permission checking for access to rbd devices, which could have been leveraged by local attackers to map or unmap rbd block devices (bsc#1176482). - CVE-2019-19063: Fixed two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c, which could have allowed an attacker to cause a denial of service (memory consumption) (bsc#1157298). - CVE-2019-6133: In PolicyKit (aka polkit), the 'start time' protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c (bsc#1121872). - CVE-2017-18204: Fixed a denial of service in the ocfs2_setattr function of fs/ocfs2/file.c (bnc#1083244).
The following non-security bugs were fixed:
- hv: vmbus: Add timeout to vmbus_wait_for_unload (bsc#1177816). - hyperv_fb: disable superfluous VERSION_WIN10_V5 case (bsc#1175306). - hyperv_fb: Update screen_info after removing old framebuffer (bsc#1175306). - mm, numa: fix bad pmd by atomically check for pmd_trans_huge when marking page tables prot_numa (bsc#1176816). - net/packet: fix overflow in tpacket_rcv (bsc#1176069). - ocfs2: give applications more IO opportunities during fstrim (bsc#1175228). - video: hyperv: hyperv_fb: Obtain screen resolution from Hyper-V host (bsc#1175306). - video: hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (bsc#1175306). - video: hyperv: hyperv_fb: Use physical memory for fb on HyperV Gen 1 VMs (bsc#1175306). - x86/kexec: Use up-to-dated screen_info copy to fill boot params (bsc#1175306). - xen/blkback: use lateeoi irq binding (XSA-332 bsc#1177411). - xen-blkfront: switch kcalloc to kvcalloc for large array allocation (bsc#1160917). - xen: do not reschedule in preemption off sections (bsc#1175749). - xen/events: add a new 'late EOI' evtchn framework (XSA-332 bsc#1177411). - xen/events: add a proper barrier to 2-level uevent unmasking (XSA-332 bsc#1177411). - xen/events: avoid removing an event channel while handling it (XSA-331 bsc#1177410). - xen/events: block rogue events for some time (XSA-332 bsc#1177411). - xen/events: defer eoi in case of excessive number of events (XSA-332 bsc#1177411). - xen/events: do not use chip_data for legacy IRQs (XSA-332 bsc#1065600). - xen/events: fix race in evtchn_fifo_unmask() (XSA-332 bsc#1177411). - xen/events: switch user event channels to lateeoi model (XSA-332 bsc#1177411). - xen/events: use a common cpu hotplug hook for event channels (XSA-332 bsc#1177411). - xen/netback: use lateeoi irq binding (XSA-332 bsc#1177411). - xen/pciback: use lateeoi irq binding (XSA-332 bsc#1177411). - xen/scsiback: use lateeoi irq binding (XSA-332 bsc#1177411). - xen uses irqdesc::irq_data_common::handler_data to store a per interrupt XEN data pointer which contains XEN specific information (XSA-332 bsc#1065600).
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1046856 1055857 1059893 1065600 1070500 1077330 1083244 1094290 1094291 1108818 1111331 1117951 1118159 1120657 1120943 1121232 1121233 1121234 1121235 1121826 1121872 1122053 1122825 1124170 1128382 1128453 1128783 1129729 1132549 1132654 1132664 1132852 1133719 1134495 1134589 1134598 1135273 1136085 1136569 1137377 1137817 1138124 1138187 1138489 1138967 1139750 1140512 1140663 1142032 1142521 1142686 1143310 1155787 1157298 1158809 1159646 1159723 1159729 1160163 1160305 1160498 1160770 1160917 1164825 1170415 1171475 1171847 1171928 1172105 1172116 1172121 1175228 1175306 1175721 1175749 1176011 1176069 1176235 1176253 1176278 1176381 1176382 1176410 1176423 1176482 1176721 1176722 1176725 1176816 1176896 1176990 1177027 1177086 1177121 1177143 1177158 1177165 1177206 1177226 1177410 1177411 1177511 1177513 1177725 1177766 1177816 1178123 1178622 1178782 CVE-2012-5784 CVE-2014-3596 CVE-2015-3448 CVE-2016-6328 CVE-2017-1000083 CVE-2017-17051 CVE-2017-18204 CVE-2017-2518 CVE-2017-7544 CVE-2018-0739 CVE-2018-12126 CVE-2018-12127 CVE-2018-12130 CVE-2018-20030 CVE-2019-0221 CVE-2019-11091 CVE-2019-11234 CVE-2019-11235 CVE-2019-12418 CVE-2019-1551 CVE-2019-17015 CVE-2019-17016 CVE-2019-17017 CVE-2019-17021 CVE-2019-17022 CVE-2019-17024 CVE-2019-17026 CVE-2019-17563 CVE-2019-17569 CVE-2019-17571 CVE-2019-19063 CVE-2019-5717 CVE-2019-5718 CVE-2019-5719 CVE-2019-5721 CVE-2019-6133 CVE-2019-9278 CVE-2019-9735 CVE-2020-0093 CVE-2020-0404 CVE-2020-0427 CVE-2020-0431 CVE-2020-0432 CVE-2020-12352 CVE-2020-12767 CVE-2020-13112 CVE-2020-13113 CVE-2020-13114 CVE-2020-14351 CVE-2020-14355 CVE-2020-14381 CVE-2020-14390 CVE-2020-25212 CVE-2020-25219 CVE-2020-25284 CVE-2020-25641 CVE-2020-25643 CVE-2020-25645 CVE-2020-25656 CVE-2020-25668 CVE-2020-25705 CVE-2020-26088 CVE-2020-26154 CVE-2020-8694 CVE-2020-9484 SUSE-SU-2017:2390-1 SUSE-SU-2018:2158-1 SUSE-SU-2019:1547-1 SUSE-SU-2019:2219-1 SUSE-SU-2019:3050-1 SUSE-SU-2020:0068-1 SUSE-SU-2020:0474-1 SUSE-SU-2020:1498-1 SUSE-SU-2020:1534-1 SUSE-SU-2020:2900-1 SUSE-SU-2020:3084-1 SUSE-SU-2020:3503-1
|
Platform(s): | openSUSE Leap 15.1 openSUSE Leap 15.2 SUSE Linux Enterprise Server 12 SP3 SUSE Linux Enterprise Server 12 SP3-BCL SUSE Linux Enterprise Server 12 SP3-ESPOS SUSE Linux Enterprise Server 12 SP3-LTSS SUSE Linux Enterprise Server 12 SP3-TERADATA SUSE Linux Enterprise Server 12 SP4 SUSE OpenStack Cloud 8 SUSE OpenStack Cloud 9 SUSE OpenStack Cloud Crowbar 8
| Product(s): | |
Definition Synopsis |
openSUSE Leap 15.1 is installed AND Package Information
strongswan-5.6.0-lp151.4.3 is installed
OR strongswan-doc-5.6.0-lp151.4.3 is installed
OR strongswan-hmac-5.6.0-lp151.4.3 is installed
OR strongswan-ipsec-5.6.0-lp151.4.3 is installed
OR strongswan-libs0-5.6.0-lp151.4.3 is installed
OR strongswan-mysql-5.6.0-lp151.4.3 is installed
OR strongswan-nm-5.6.0-lp151.4.3 is installed
OR strongswan-sqlite-5.6.0-lp151.4.3 is installed
|
Definition Synopsis |
openSUSE Leap 15.2 is installed
AND Package Information
inn-2.6.2-lp152.2.3 is installed
OR inn-devel-2.6.2-lp152.2.3 is installed
OR mininews-2.6.2-lp152.2.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3 is installed
AND Package Information
evince-3.20.1-6.16 is installed
OR evince-browser-plugin-3.20.1-6.16 is installed
OR evince-lang-3.20.1-6.16 is installed
OR evince-plugin-djvudocument-3.20.1-6.16 is installed
OR evince-plugin-dvidocument-3.20.1-6.16 is installed
OR evince-plugin-pdfdocument-3.20.1-6.16 is installed
OR evince-plugin-psdocument-3.20.1-6.16 is installed
OR evince-plugin-tiffdocument-3.20.1-6.16 is installed
OR evince-plugin-xpsdocument-3.20.1-6.16 is installed
OR libevdocument3-4-3.20.1-6.16 is installed
OR libevview3-3-3.20.1-6.16 is installed
OR nautilus-evince-3.20.1-6.16 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-BCL is installed
AND Package Information
libspice-server1-0.12.8-15 is installed
OR spice-0.12.8-15 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
AND log4j-1.2.15-126.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-LTSS is installed
AND Package Information
libexif-0.6.22-8.9 is installed
OR libexif12-0.6.22-8.9 is installed
OR libexif12-32bit-0.6.22-8.9 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
AND Package Information
freeradius-server-3.0.15-2.11 is installed
OR freeradius-server-doc-3.0.15-2.11 is installed
OR freeradius-server-krb5-3.0.15-2.11 is installed
OR freeradius-server-ldap-3.0.15-2.11 is installed
OR freeradius-server-libs-3.0.15-2.11 is installed
OR freeradius-server-mysql-3.0.15-2.11 is installed
OR freeradius-server-perl-3.0.15-2.11 is installed
OR freeradius-server-postgresql-3.0.15-2.11 is installed
OR freeradius-server-python-3.0.15-2.11 is installed
OR freeradius-server-sqlite-3.0.15-2.11 is installed
OR freeradius-server-utils-3.0.15-2.11 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP4 is installed
AND Package Information
kernel-firmware-20180525-3 is installed
OR ucode-amd-20180525-3 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud 8 is installed
AND Package Information
kernel-default-4.4.180-94.135 is installed
OR kernel-default-base-4.4.180-94.135 is installed
OR kernel-default-devel-4.4.180-94.135 is installed
OR kernel-default-kgraft-4.4.180-94.135 is installed
OR kernel-devel-4.4.180-94.135 is installed
OR kernel-macros-4.4.180-94.135 is installed
OR kernel-source-4.4.180-94.135 is installed
OR kernel-syms-4.4.180-94.135 is installed
OR kgraft-patch-4_4_180-94_135-default-1-4.5 is installed
OR kgraft-patch-SLE12-SP3_Update_36-1-4.5 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud 9 is installed
AND Package Information
MozillaFirefox-78.1.0-112.8 is installed
OR MozillaFirefox-devel-78.1.0-112.8 is installed
OR MozillaFirefox-translations-common-78.1.0-112.8 is installed
|
Definition Synopsis |
SUSE OpenStack Cloud Crowbar 8 is installed
AND Package Information
caasp-openstack-heat-templates-1.0+git.1560518045.ad7dc6d-4.15 is installed
OR crowbar-core-5.0+git.1565280360.01fed6905-3.26 is installed
OR crowbar-core-branding-upstream-5.0+git.1565280360.01fed6905-3.26 is installed
OR crowbar-ha-5.0+git.1562069707.e2de18c-3.20 is installed
OR crowbar-openstack-5.0+git.1565270683.ea6e63d87-4.28 is installed
OR crowbar-ui-1.2.0+git.1563181545.65360af5-3.9 is installed
OR documentation-suse-openstack-cloud-deployment-8.20190805-1.20 is installed
OR documentation-suse-openstack-cloud-supplement-8.20190805-1.20 is installed
OR documentation-suse-openstack-cloud-upstream-admin-8.20190805-1.20 is installed
OR documentation-suse-openstack-cloud-upstream-user-8.20190805-1.20 is installed
OR galera-python-clustercheck-0.0+git.1562242499.36b8b64-4.6 is installed
OR grafana-monasca-ui-drilldown-1.8.1~dev39-3.9 is installed
OR openstack-cinder-11.2.3~dev7-3.18 is installed
OR openstack-cinder-api-11.2.3~dev7-3.18 is installed
OR openstack-cinder-backup-11.2.3~dev7-3.18 is installed
OR openstack-cinder-doc-11.2.3~dev7-3.18 is installed
OR openstack-cinder-scheduler-11.2.3~dev7-3.18 is installed
OR openstack-cinder-volume-11.2.3~dev7-3.18 is installed
OR openstack-glance-15.0.3~dev2-3.9 is installed
OR openstack-glance-api-15.0.3~dev2-3.9 is installed
OR openstack-glance-doc-15.0.3~dev2-3.9 is installed
OR openstack-glance-registry-15.0.3~dev2-3.9 is installed
OR openstack-heat-9.0.8~dev11-3.21 is installed
OR openstack-heat-api-9.0.8~dev11-3.21 is installed
OR openstack-heat-api-cfn-9.0.8~dev11-3.21 is installed
OR openstack-heat-api-cloudwatch-9.0.8~dev11-3.21 is installed
OR openstack-heat-doc-9.0.8~dev11-3.21 is installed
OR openstack-heat-engine-9.0.8~dev11-3.21 is installed
OR openstack-heat-plugin-heat_docker-9.0.8~dev11-3.21 is installed
OR openstack-heat-test-9.0.8~dev11-3.21 is installed
OR openstack-horizon-plugin-monasca-ui-1.8.1~dev39-3.9 is installed
OR openstack-horizon-plugin-neutron-fwaas-ui-1.0.1~dev9-4.6 is installed
OR openstack-ironic-9.1.8~dev7-3.21 is installed
OR openstack-ironic-api-9.1.8~dev7-3.21 is installed
OR openstack-ironic-conductor-9.1.8~dev7-3.21 is installed
OR openstack-ironic-doc-9.1.8~dev7-3.21 is installed
OR openstack-keystone-12.0.4~dev2-5.22 is installed
OR openstack-keystone-doc-12.0.4~dev2-5.22 is installed
OR openstack-manila-5.1.1~dev2-3.18 is installed
OR openstack-manila-api-5.1.1~dev2-3.18 is installed
OR openstack-manila-data-5.1.1~dev2-3.18 is installed
OR openstack-manila-doc-5.1.1~dev2-3.18 is installed
OR openstack-manila-scheduler-5.1.1~dev2-3.18 is installed
OR openstack-manila-share-5.1.1~dev2-3.18 is installed
OR openstack-monasca-agent-2.2.5~dev5-3.12 is installed
OR openstack-monasca-api-2.2.2~dev1-3.15 is installed
OR openstack-monasca-persister-1.7.1~dev10-3.9 is installed
OR openstack-monasca-persister-java-1.7.1~a0~dev2-3.3 is installed
OR openstack-murano-4.0.2~dev2-3.9 is installed
OR openstack-murano-api-4.0.2~dev2-3.9 is installed
OR openstack-murano-doc-4.0.2~dev2-3.9 is installed
OR openstack-murano-engine-4.0.2~dev2-3.9 is installed
OR openstack-neutron-11.0.9~dev42-3.21 is installed
OR openstack-neutron-dhcp-agent-11.0.9~dev42-3.21 is installed
OR openstack-neutron-doc-11.0.9~dev42-3.21 is installed
OR openstack-neutron-gbp-7.3.1~dev45-3.6 is installed
OR openstack-neutron-ha-tool-11.0.9~dev42-3.21 is installed
OR openstack-neutron-l3-agent-11.0.9~dev42-3.21 is installed
OR openstack-neutron-lbaas-11.0.4~dev6-3.12 is installed
OR openstack-neutron-lbaas-agent-11.0.4~dev6-3.12 is installed
OR openstack-neutron-lbaas-doc-11.0.4~dev6-3.12 is installed
OR openstack-neutron-linuxbridge-agent-11.0.9~dev42-3.21 is installed
OR openstack-neutron-macvtap-agent-11.0.9~dev42-3.21 is installed
OR openstack-neutron-metadata-agent-11.0.9~dev42-3.21 is installed
OR openstack-neutron-metering-agent-11.0.9~dev42-3.21 is installed
OR openstack-neutron-openvswitch-agent-11.0.9~dev42-3.21 is installed
OR openstack-neutron-server-11.0.9~dev42-3.21 is installed
OR openstack-nova-16.1.9~dev4-3.26 is installed
OR openstack-nova-api-16.1.9~dev4-3.26 is installed
OR openstack-nova-cells-16.1.9~dev4-3.26 is installed
OR openstack-nova-compute-16.1.9~dev4-3.26 is installed
OR openstack-nova-conductor-16.1.9~dev4-3.26 is installed
OR openstack-nova-console-16.1.9~dev4-3.26 is installed
OR openstack-nova-consoleauth-16.1.9~dev4-3.26 is installed
OR openstack-nova-doc-16.1.9~dev4-3.26 is installed
OR openstack-nova-novncproxy-16.1.9~dev4-3.26 is installed
OR openstack-nova-placement-api-16.1.9~dev4-3.26 is installed
OR openstack-nova-scheduler-16.1.9~dev4-3.26 is installed
OR openstack-nova-serialproxy-16.1.9~dev4-3.26 is installed
OR openstack-nova-vncproxy-16.1.9~dev4-3.26 is installed
OR openstack-octavia-1.0.6~dev2-4.18 is installed
OR openstack-octavia-amphora-agent-1.0.6~dev2-4.18 is installed
OR openstack-octavia-api-1.0.6~dev2-4.18 is installed
OR openstack-octavia-health-manager-1.0.6~dev2-4.18 is installed
OR openstack-octavia-housekeeping-1.0.6~dev2-4.18 is installed
OR openstack-octavia-worker-1.0.6~dev2-4.18 is installed
OR python-cinder-11.2.3~dev7-3.18 is installed
OR python-glance-15.0.3~dev2-3.9 is installed
OR python-heat-9.0.8~dev11-3.21 is installed
OR python-horizon-plugin-monasca-ui-1.8.1~dev39-3.9 is installed
OR python-horizon-plugin-neutron-fwaas-ui-1.0.1~dev9-4.6 is installed
OR python-ironic-9.1.8~dev7-3.21 is installed
OR python-keystone-12.0.4~dev2-5.22 is installed
OR python-manila-5.1.1~dev2-3.18 is installed
OR python-monasca-agent-2.2.5~dev5-3.12 is installed
OR python-monasca-api-2.2.2~dev1-3.15 is installed
OR python-monasca-persister-1.7.1~dev10-3.9 is installed
OR python-murano-4.0.2~dev2-3.9 is installed
OR python-neutron-11.0.9~dev42-3.21 is installed
OR python-neutron-gbp-7.3.1~dev45-3.6 is installed
OR python-neutron-lbaas-11.0.4~dev6-3.12 is installed
OR python-nova-16.1.9~dev4-3.26 is installed
OR python-octavia-1.0.6~dev2-4.18 is installed
OR python-oslo.db-4.25.2-3.6 is installed
OR python-osprofiler-1.11.1-3.3 is installed
|