Oval Definition:oval:org.opensuse.security:def:60955
Revision Date:2020-12-01Version:1
Title:Security update for the Linux Kernel (Important)
Description:

The SUSE Linux Enterprise 12 SP3 kernel was updated to receive various security and bugfixes.



The following security bugs were fixed:

- CVE-2020-11494: An issue was discovered in slc_bump in drivers/net/can/slcan.c, which allowed attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration lacks CONFIG_INIT_STACK_ALL (bnc#1168424). - CVE-2020-10942: In get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls (bnc#1167629). - CVE-2020-8647: Fixed a use-after-free vulnerability in the vc_do_resize function in drivers/tty/vt/vt.c (bnc#1162929). - CVE-2020-8649: Fixed a use-after-free vulnerability in the vgacon_invert_region function in drivers/video/console/vgacon.c (bnc#1162931). - CVE-2020-9383: Fixed an issue in set_fdc in drivers/block/floppy.c, which leads to a wait_til_ready out-of-bounds read (bnc#1165111). - CVE-2019-9458: In the video driver there was a use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed (bnc#1168295). - CVE-2019-3701: Fixed an issue in can_can_gw_rcv, which could cause a system crash (bnc#1120386). - CVE-2019-19768: Fixed a use-after-free in the __blk_add_trace function in kernel/trace/blktrace.c (bnc#1159285). - CVE-2020-11609: Fixed a NULL pointer dereference in the stv06xx subsystem caused by mishandling invalid descriptors (bnc#1168854). - CVE-2020-10720: Fixed a use-after-free read in napi_gro_frags() (bsc#1170778). - CVE-2020-10690: Fixed the race between the release of ptp_clock and cdev (bsc#1170056). - CVE-2019-9455: Fixed a pointer leak due to a WARN_ON statement in a video driver. This could lead to local information disclosure with System execution privileges needed (bnc#1170345). - CVE-2020-11608: Fixed an issue in drivers/media/usb/gspca/ov519.c caused by a NULL pointer dereferences in ov511_mode_init_regs and ov518_mode_init_regs when there are zero endpoints (bnc#1168829). - CVE-2017-18255: The perf_cpu_time_max_percent_handler function in kernel/events/core.c allowed local users to cause a denial of service (integer overflow) or possibly have unspecified other impact via a large value, as demonstrated by an incorrect sample-rate calculation (bnc#1087813). - CVE-2020-8648: There was a use-after-free vulnerability in the n_tty_receive_buf_common function in drivers/tty/n_tty.c (bnc#1162928). - CVE-2020-2732: A flaw was discovered in the way that the KVM hypervisor handled instruction emulation for an L2 guest when nested virtualisation is enabled. Under some circumstances, an L2 guest may trick the L0 guest into accessing sensitive L1 resources that should be inaccessible to the L2 guest (bnc#1163971). - CVE-2019-5108: Fixed a denial-of-service vulnerability caused by triggering AP to send IAPP location updates for stations before the required authentication process has completed (bnc#1159912). - CVE-2020-8992: ext4_protect_reserved_inode in fs/ext4/block_validity.c allowed attackers to cause a denial of service (soft lockup) via a crafted journal size (bnc#1164069). - CVE-2018-21008: Fixed a use-after-free which could be caused by the function rsi_mac80211_detach in the file drivers/net/wireless/rsi/rsi_91x_mac80211.c (bnc#1149591). - CVE-2019-14896: A heap-based buffer overflow vulnerability was found in Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbs_ibss_join_existing function is called after a STA connects to an AP (bnc#1157157). - CVE-2019-14897: A stack-based buffer overflow was found in Marvell WiFi chip driver. An attacker is able to cause a denial of service (system crash) or, possibly execute arbitrary code, when a STA works in IBSS mode (allows connecting stations together without the use of an AP) and connects to another STA (bnc#1157155). - CVE-2019-18675: Fixed an integer overflow in cpia2_remap_buffer in drivers/media/usb/cpia2/cpia2_core.c because cpia2 has its own mmap implementation. This allowed local users (with /dev/video0 access) to obtain read and write permissions on kernel physical pages, which can possibly result in a privilege escalation (bnc#1157804). - CVE-2019-14615: Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may have allowed an unauthenticated user to potentially enable information disclosure via local access (bnc#1160195, bsc#1165881). - CVE-2019-19965: Fixed a NULL pointer dereference in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection during discovery, related to a PHY down race condition (bnc#1159911). - CVE-2019-20054: Fixed a NULL pointer dereference in drop_sysctl_table() in fs/proc/proc_sysctl.c, related to put_links (bnc#1159910). - CVE-2019-20096: Fixed a memory leak in __feat_register_sp() in net/dccp/feat.c, which may cause denial of service (bnc#1159908). - CVE-2019-19966: Fixed a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that will cause denial of service (bnc#1159841). - CVE-2019-19447: Fixed an issue with mounting a crafted ext4 filesystem image, performing some operations, and unmounting could lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orphan_list in fs/ext4/super.c (bnc#1158819). - CVE-2019-19319: Fixed an issue with a setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access because of an ext4_xattr_set_entry use-after-free in fs/ext4/xattr.c when a large old_size value is used in a memset call (bnc#1158021). - CVE-2019-19767: Fixed mishandling of ext4_expand_extra_isize, as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry, related to fs/ext4/inode.c and fs/ext4/super.c (bnc#1159297). - CVE-2019-11091,CVE-2018-12126,CVE-2018-12130,CVE-2018-12127: Earlier mitigations for the 'MDS' Microarchitectural Data Sampling attacks were not complete. An additional fix was added to the x86_64 fast systemcall path to further mitigate these attacks. (bsc#1164846 bsc#1170847)



The following non-security bugs were fixed:

- blk: Fix kabi due to blk_trace_mutex addition (bsc#1159285). - blktrace: fix dereference after null check (bsc#1159285). - blktrace: fix trace mutex deadlock (bsc#1159285). - btrfs: fix btrfs_wait_ordered_range() so that it waits for all ordered extents (bsc#1163508). - btrfs: fix panic during relocation after ENOSPC before writeback happens (bsc#1163508). - btrfs: qgroup: Fix root item corruption when multiple same source snapshots are created with quota enabled (bsc#1158642) - btrfs: relocation: fix reloc_root lifespan and access (bsc#1164009). - enic: prevent waking up stopped tx queues over watchdog reset (bsc#1133147). - fix PageHeadHuge() race with THP split (VM Functionality, bsc#1165311). - fs/xfs: fix f_ffree value for statfs when project quota is set (bsc#1165985). - ibmvnic: Bound waits for device queries (bsc#1155689 ltc#182047). - ibmvnic: Fix completion structure initialization (bsc#1155689 ltc#182047). - ibmvnic: Serialize device queries (bsc#1155689 ltc#182047). - ibmvnic: Terminate waiting device threads after loss of service (bsc#1155689 ltc#182047). - input: add safety guards to input_set_keycode() (bsc#1168075). - ipv4: correct gso_size for UFO (bsc#1154844). - ipv6: fix memory accounting during ipv6 queue expire (bsc#1162227) (bsc#1162227). - ipvlan: do not add hardware address of master to its unicast filter list (bsc#1137325). - md: add mddev->pers to avoid potential NULL pointer dereference (bsc#1056134). - md/bitmap: do not read page from device with Bitmap_sync (bsc#1056134). - md: change the initialization value for a spare device spot to MD_DISK_ROLE_SPARE (bsc#1056134). - md: Delete gendisk before cleaning up the request queue (bsc#1056134). - md: do not call bitmap_create() while array is quiesced (bsc#1056134). - md: do not set In_sync if array is frozen (bsc#1056134). - md: fix a potential deadlock of raid5/raid10 reshape (bsc#1056134). - md: md.c: Return -ENODEV when mddev is NULL in rdev_attr_show (bsc#1056134). - md: notify about new spare disk in the container (bsc#1056134). - md/raid0: Fix buffer overflow at debug print (bsc#1164051). - md/raid10: end bio when the device faulty (bsc#1056134). - md/raid10: Fix raid10 replace hang when new added disk faulty (bsc#1056134). - md/raid1,raid10: silence warning about wait-within-wait (bsc#1056134). - md: return -ENODEV if rdev has no mddev assigned (bsc#1056134). - media: ov519: add missing endpoint sanity checks (bsc#1168829). - media: stv06xx: add missing descriptor sanity checks (bsc#1168854). - net: ena: Add PCI shutdown handler to allow safe kexec (bsc#1167421, bsc#1167423). - netfilter: conntrack: sctp: use distinct states for new SCTP connections (bsc#1159199). - net/ibmvnic: Fix typo in retry check (bsc#1155689 ltc#182047). - rpm/kernel-binary.spec.in: Replace Novell with SUSE - sched/fair: Scale bandwidth quota and period without losing quota/period ratio precision (bsc#1161586). - scsi: core: avoid repetitive logging of device offline messages (bsc#1145929). - scsi: core: kABI fix already_offline (bsc#1145929). - tcp: clear tp->packets_out when purging write queue (bsc#1154118). - x86/mitigations: Clear CPU buffers on the SYSCALL fast path (bsc#1164846 bsc#1170847). - xfs: also remove cached ACLs when removing the underlying attr (bsc#1165873). - xfs: bulkstat should copy lastip whenever userspace supplies one (bsc#1165984).
Family:unixClass:patch
Status:Reference(s):1004995
1012382
1015342
1015343
1017967
1019695
1019699
1020412
1021121
1022604
1024361
1024365
1024376
1027968
1029102
1029516
1030552
1031492
1032029
1033238
1033962
1036873
1037120
1038865
1040153
1040258
1040614
1040942
1040968
1042286
1043758
1043900
1045290
1046750
1048317
1050431
1053685
1054413
1055014
1056134
1056596
1057974
1062604
1063646
1064232
1064990
1065364
1066223
1068032
1068075
1068588
1069138
1071224
1071311
1073879
1075801
1077925
1078921
1080157
1083663
1085042
1085536
1085539
1086457
1087092
1087813
1088004
1088009
1089066
1090888
1091171
1091860
1096254
1096748
1097105
1098253
1098822
1099590
1099597
1099810
1099811
1099813
1099832
1099844
1099845
1099846
1099849
1099863
1099864
1099922
1099999
1100000
1100001
1100132
1101822
1101841
1102346
1102486
1102517
1102715
1102797
1103269
1103445
1103717
1104319
1104485
1104494
1104495
1104683
1104897
1105271
1105292
1105322
1105323
1105392
1105396
1105524
1105536
1105769
1106016
1106105
1106185
1106229
1106271
1106275
1106276
1106278
1106281
1106283
1106369
1106509
1106511
1106697
1106929
1106934
1106995
1107060
1107078
1107319
1107320
1107689
1107735
1107966
1111177
1111622
1113246
1114710
1120386
1121086
1121567
1122668
1122838
1122839
1123755
1124223
1124799
1124800
1124802
1124803
1124805
1124806
1124824
1124825
1124826
1124827
1125099
1127153
1130840
1131060
1133147
1137325
1138743
1141853
1145929
1149591
1149955
1153238
1154118
1154328
1154844
1154849
1155689
1156146
1157155
1157157
1157303
1157804
1158021
1158642
1158819
1159199
1159285
1159297
1159841
1159908
1159910
1159911
1159912
1160195
1161586
1162227
1162423
1162928
1162929
1162931
1163508
1163971
1164009
1164051
1164069
1164078
1164846
1165111
1165311
1165873
1165881
1165984
1165985
1167421
1167423
1167629
1168075
1168295
1168424
1168630
1168829
1168854
1169511
1170056
1170345
1170778
1170847
1171477
1171930
1173274
1174091
1174543
1174701
761500
922448
929736
935252
945455
947357
961596
963575
966170
966172
967128
969470
969476
969477
970506
982303
986216
CVE-2015-2296
CVE-2017-12618
CVE-2017-18078
CVE-2017-18255
CVE-2017-9217
CVE-2017-9445
CVE-2018-10876
CVE-2018-10877
CVE-2018-10878
CVE-2018-10879
CVE-2018-10880
CVE-2018-10881
CVE-2018-10882
CVE-2018-10883
CVE-2018-10902
CVE-2018-10938
CVE-2018-1128
CVE-2018-1129
CVE-2018-12126
CVE-2018-12127
CVE-2018-12130
CVE-2018-12896
CVE-2018-13093
CVE-2018-13094
CVE-2018-13095
CVE-2018-14647
CVE-2018-14662
CVE-2018-15572
CVE-2018-16658
CVE-2018-16846
CVE-2018-16889
CVE-2018-17189
CVE-2018-17199
CVE-2018-18074
CVE-2018-20852
CVE-2018-21008
CVE-2018-6554
CVE-2018-6555
CVE-2018-9363
CVE-2019-11091
CVE-2019-14615
CVE-2019-14818
CVE-2019-14834
CVE-2019-14896
CVE-2019-14897
CVE-2019-16056
CVE-2019-16935
CVE-2019-18675
CVE-2019-19066
CVE-2019-19319
CVE-2019-19447
CVE-2019-19767
CVE-2019-19768
CVE-2019-19965
CVE-2019-19966
CVE-2019-20054
CVE-2019-20096
CVE-2019-20907
CVE-2019-3693
CVE-2019-3701
CVE-2019-3880
CVE-2019-5108
CVE-2019-7572
CVE-2019-7573
CVE-2019-7574
CVE-2019-7575
CVE-2019-7576
CVE-2019-7577
CVE-2019-7578
CVE-2019-7635
CVE-2019-7636
CVE-2019-7637
CVE-2019-7638
CVE-2019-9455
CVE-2019-9458
CVE-2019-9947
CVE-2020-10690
CVE-2020-10720
CVE-2020-10722
CVE-2020-10942
CVE-2020-11494
CVE-2020-11608
CVE-2020-11609
CVE-2020-14422
CVE-2020-2732
CVE-2020-2756
CVE-2020-2757
CVE-2020-2773
CVE-2020-2781
CVE-2020-2800
CVE-2020-2803
CVE-2020-2805
CVE-2020-2830
CVE-2020-6819
CVE-2020-6820
CVE-2020-8647
CVE-2020-8648
CVE-2020-8649
CVE-2020-8992
CVE-2020-9383
SUSE-SU-2017:2031-1
SUSE-SU-2017:3278-1
SUSE-SU-2018:0546-1
SUSE-SU-2018:2776-1
SUSE-SU-2019:0899-1
SUSE-SU-2020:0419-1
SUSE-SU-2020:0928-1
SUSE-SU-2020:1275-1
SUSE-SU-2020:1792-1
SUSE-SU-2020:2194-1
SUSE-SU-2020:2699-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-ESPOS
SUSE OpenStack Cloud Crowbar 8
SUSE OpenStack Cloud Crowbar 9
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • pdns-4.1.11-20 is installed
  • OR pdns-backend-geoip-4.1.8-lp151.2.3 is installed
  • OR pdns-backend-godbc-4.1.11-20 is installed
  • OR pdns-backend-ldap-4.1.11-20 is installed
  • OR pdns-backend-lua-4.1.11-20 is installed
  • OR pdns-backend-mydns-4.1.11-20 is installed
  • OR pdns-backend-mysql-4.1.11-20 is installed
  • OR pdns-backend-postgresql-4.1.11-20 is installed
  • OR pdns-backend-remote-4.1.11-20 is installed
  • OR pdns-backend-sqlite3-4.1.11-20 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • chromedriver-84.0.4147.89-lp152.2.6 is installed
  • OR chromium-84.0.4147.89-lp152.2.6 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND Package Information
  • libsystemd0-228-150.9 is installed
  • OR libsystemd0-32bit-228-150.9 is installed
  • OR libudev1-228-150.9 is installed
  • OR libudev1-32bit-228-150.9 is installed
  • OR systemd-228-150.9 is installed
  • OR systemd-32bit-228-150.9 is installed
  • OR systemd-bash-completion-228-150.9 is installed
  • OR systemd-sysvinit-228-150.9 is installed
  • OR udev-228-150.9 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • dpdk-16.11.9-8.15 is installed
  • OR dpdk-kmp-default-16.11.9_k4.4.180_94.127-8.15 is installed
  • OR dpdk-tools-16.11.9-8.15 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • java-1_7_0-openjdk-1.7.0.261-43.38 is installed
  • OR java-1_7_0-openjdk-demo-1.7.0.261-43.38 is installed
  • OR java-1_7_0-openjdk-devel-1.7.0.261-43.38 is installed
  • OR java-1_7_0-openjdk-headless-1.7.0.261-43.38 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • MozillaFirefox-68.6.1-109.113 is installed
  • OR MozillaFirefox-translations-common-68.6.1-109.113 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • libdcerpc-binding0-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libdcerpc-binding0-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libdcerpc0-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libdcerpc0-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libndr-krb5pac0-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libndr-krb5pac0-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libndr-nbt0-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libndr-nbt0-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libndr-standard0-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libndr-standard0-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libndr0-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libndr0-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libnetapi0-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libnetapi0-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libsamba-credentials0-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libsamba-credentials0-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libsamba-errors0-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libsamba-errors0-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libsamba-hostconfig0-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libsamba-hostconfig0-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libsamba-passdb0-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libsamba-passdb0-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libsamba-util0-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libsamba-util0-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libsamdb0-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libsamdb0-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libsmbclient0-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libsmbclient0-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libsmbconf0-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libsmbconf0-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libsmbldap0-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libsmbldap0-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libtevent-util0-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libtevent-util0-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libwbclient0-4.6.16+git.154.2998451b912-3.40 is installed
  • OR libwbclient0-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR samba-4.6.16+git.154.2998451b912-3.40 is installed
  • OR samba-client-4.6.16+git.154.2998451b912-3.40 is installed
  • OR samba-client-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR samba-doc-4.6.16+git.154.2998451b912-3.40 is installed
  • OR samba-libs-4.6.16+git.154.2998451b912-3.40 is installed
  • OR samba-libs-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • OR samba-winbind-4.6.16+git.154.2998451b912-3.40 is installed
  • OR samba-winbind-32bit-4.6.16+git.154.2998451b912-3.40 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND Package Information
  • aaa_base-13.2+git20140911.61c1681-38.8 is installed
  • OR aaa_base-extras-13.2+git20140911.61c1681-38.8 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • AND Package Information
  • kernel-default-4.12.14-95.60 is installed
  • OR kernel-default-base-4.12.14-95.60 is installed
  • OR kernel-default-devel-4.12.14-95.60 is installed
  • OR kernel-devel-4.12.14-95.60 is installed
  • OR kernel-macros-4.12.14-95.60 is installed
  • OR kernel-source-4.12.14-95.60 is installed
  • OR kernel-syms-4.12.14-95.60 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • kernel-default-4.4.180-94.116 is installed
  • OR kernel-default-base-4.4.180-94.116 is installed
  • OR kernel-default-devel-4.4.180-94.116 is installed
  • OR kernel-default-kgraft-4.4.180-94.116 is installed
  • OR kernel-devel-4.4.180-94.116 is installed
  • OR kernel-macros-4.4.180-94.116 is installed
  • OR kernel-source-4.4.180-94.116 is installed
  • OR kernel-syms-4.4.180-94.116 is installed
  • OR kgraft-patch-4_4_180-94_116-default-1-4.3 is installed
  • OR kgraft-patch-SLE12-SP3_Update_31-1-4.3 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 9 is installed
  • AND Package Information
  • dnsmasq-2.78-18.12 is installed
  • OR dnsmasq-utils-2.78-18.12 is installed
  • BACK