Oval Definition:oval:org.opensuse.security:def:60970
Revision Date:2020-12-01Version:1
Title:Security update for the Linux Kernel (Important)
Description:

The SUSE Linux Enterprise 12 SP3 kernel was updated to receive various security and bugfixes.

The following security bugs were fixed:

- CVE-2020-0543: Fixed a side channel attack against special registers which could have resulted in leaking of read values to cores other than the one which called it. This attack is known as Special Register Buffer Data Sampling (SRBDS) or 'CrossTalk' (bsc#1154824). - CVE-2020-12652: Fixed an issue which could have allowed local users to hold an incorrect lock during the ioctl operation and trigger a race condition (bsc#1171218). - CVE-2020-12653: Fixed an issue in the wifi driver which could have allowed local users to gain privileges or cause a denial of service (bsc#1171195). - CVE-2020-12654: Fixed an issue in he wifi driver which could have allowed a remote AP to trigger a heap-based buffer overflow (bsc#1171202). - CVE-2020-12656: Fixed an improper handling of certain domain_release calls leadingch could have led to a memory leak (bsc#1171219). - CVE-2020-12114: Fixed A pivot_root race condition which could have allowed local users to cause a denial of service (panic) by corrupting a mountpoint reference counter (bsc#1171098). - CVE-2020-10757: Fixed an issue where remaping hugepage DAX to anon mmap could have caused user PTE access (bsc#1172317).

The following non-security bugs were fixed:

- can, slip: Protect tty->disc_data in write_wakeup and close with RCU (bsc#1171698). - clocksource/drivers/hyper-v: Set TSC clocksource as default w/ InvariantTSC (bsc#1170620). - Drivers: HV: Send one page worth of kmsg dump over Hyper-V during panic (bsc#1170618). - Drivers: hv: vmbus: Fix the issue with freeing up hv_ctl_table_hdr (bsc#1170618). - Drivers: hv: vmbus: Get rid of MSR access from vmbus_drv.c (bsc#1170618). - Drivers: hv: vmbus: Make panic reporting to be more useful (bsc#1170618). - Drivers: hv: vmus: Fix the check for return value from kmsg get dump buffer (bsc#1170618). - EDAC: Convert to new X86 CPU match macros - ibmvfc: do not send implicit logouts prior to NPIV login (bsc#1169625 ltc#184611). - ibmvfc: Fix NULL return compiler warning (bsc#1161951 ltc#183551). - KEYS: reaching the keys quotas correctly (bsc#1171689). - NFS: Cleanup if nfs_match_client is interrupted (bsc#1169025). - NFS: Fix a double unlock from nfs_match,get_client (bsc#1169025). - NFS: make nfs_match_client killable (bsc#1169025). - NFS: Unlock requests must never fail (bsc#1172032). - random: always use batched entropy for get_random_u{32,64} (bsc#1164871). - Revert 'ipc,sem: remove uneeded sem_undo_list lock usage in exit_sem()' (bsc#1172221). - scsi: ibmvfc: Avoid loss of all paths during SVC node reboot (bsc#1161951 ltc#183551). - scsi: ibmvfc: Fix NULL return compiler warning (bsc#1161951 ltc#183551). - x86/dumpstack/64: Handle faults when printing the 'Stack: ' part of an OOPS (bsc#1170383). - x86/hyperv: Allow guests to enable InvariantTSC (bsc#1170620). - x86/Hyper-V: Free hv_panic_page when fail to register kmsg dump (bsc#1170618). - x86/Hyper-V: Report crash data in die() when panic_on_oops is set (bsc#1170618). - x86/Hyper-V: Report crash register data or kmsg before running crash kernel (bsc#1170618). - x86/Hyper-V: Report crash register data when sysctl_record_panic_msg is not set (bsc#1170618). - x86: hyperv: report value of misc_features (git fixes). - x86/Hyper-V: Trigger crash enlightenment only once during system crash (bsc#1170618). - x86/Hyper-V: Unload vmbus channel in hv panic callback (bsc#1170618).
Family:unixClass:patch
Status:Reference(s):1002734
1041447
1041470
1050896
1057460
1076390
1082810
1085018
1085855
1086690
1087078
1087088
1090368
1090820
1090869
1092497
1094150
1094154
1094161
1094301
1098813
1100835
1101776
1101777
1101786
1101788
1101791
1101794
1101800
1101802
1101804
1101810
1106514
1128503
1128829
1128963
1129231
1135966
1135967
1138459
1141853
1146519
1146544
1150466
1152107
1154824
1155321
1155897
1155898
1156187
1156318
1157038
1157042
1157070
1157143
1157158
1157191
1157324
1157333
1158132
1158381
1158394
1158398
1158410
1158413
1158417
1158427
1158445
1158823
1158824
1158827
1158834
1158900
1158903
1158904
1158954
1159329
1160968
1161719
1161951
1163809
1164871
1165528
1169025
1169625
1169658
1170383
1170618
1170620
1171098
1171195
1171202
1171218
1171219
1171689
1171698
1172032
1172221
1172317
1172437
1173160
1173798
1174205
1174757
1174771
1175112
1175127
1175228
1175691
1176069
1177158
929900
955131
966304
CVE-2016-1000031
CVE-2017-18269
CVE-2017-9263
CVE-2017-9265
CVE-2018-11236
CVE-2018-11237
CVE-2018-11354
CVE-2018-11355
CVE-2018-11356
CVE-2018-11357
CVE-2018-11358
CVE-2018-11359
CVE-2018-11360
CVE-2018-11361
CVE-2018-11362
CVE-2018-12181
CVE-2018-14339
CVE-2018-14340
CVE-2018-14341
CVE-2018-14342
CVE-2018-14343
CVE-2018-14344
CVE-2018-14367
CVE-2018-14368
CVE-2018-14369
CVE-2018-14370
CVE-2018-16056
CVE-2018-16057
CVE-2018-16058
CVE-2018-20852
CVE-2018-2579
CVE-2018-2582
CVE-2018-2588
CVE-2018-2599
CVE-2018-2602
CVE-2018-2603
CVE-2018-2618
CVE-2018-2633
CVE-2018-2634
CVE-2018-2637
CVE-2018-2641
CVE-2018-2657
CVE-2018-2663
CVE-2018-2677
CVE-2018-2678
CVE-2018-8897
CVE-2019-0154
CVE-2019-0155
CVE-2019-10160
CVE-2019-14895
CVE-2019-14901
CVE-2019-15213
CVE-2019-16231
CVE-2019-16746
CVE-2019-18660
CVE-2019-18680
CVE-2019-18683
CVE-2019-18805
CVE-2019-19052
CVE-2019-19062
CVE-2019-19065
CVE-2019-19073
CVE-2019-19074
CVE-2019-19332
CVE-2019-19338
CVE-2019-19523
CVE-2019-19524
CVE-2019-19525
CVE-2019-19527
CVE-2019-19530
CVE-2019-19531
CVE-2019-19532
CVE-2019-19533
CVE-2019-19534
CVE-2019-19535
CVE-2019-19536
CVE-2019-19537
CVE-2019-8625
CVE-2019-8710
CVE-2019-8720
CVE-2019-8743
CVE-2019-8764
CVE-2019-8766
CVE-2019-8769
CVE-2019-8771
CVE-2019-8782
CVE-2019-8783
CVE-2019-8808
CVE-2019-8811
CVE-2019-8812
CVE-2019-8813
CVE-2019-8814
CVE-2019-8815
CVE-2019-8816
CVE-2019-8819
CVE-2019-8820
CVE-2019-8823
CVE-2019-8835
CVE-2019-8844
CVE-2019-8846
CVE-2020-0543
CVE-2020-10018
CVE-2020-10745
CVE-2020-10757
CVE-2020-10757
CVE-2020-11793
CVE-2020-12114
CVE-2020-12652
CVE-2020-12653
CVE-2020-12654
CVE-2020-12656
CVE-2020-14314
CVE-2020-14331
CVE-2020-14355
CVE-2020-14386
CVE-2020-16166
CVE-2020-2583
CVE-2020-2590
CVE-2020-2593
CVE-2020-2601
CVE-2020-2604
CVE-2020-2654
CVE-2020-2659
CVE-2020-3862
CVE-2020-3864
CVE-2020-3865
CVE-2020-3867
CVE-2020-3868
SUSE-SU-2017:2212-1
SUSE-SU-2018:0694-1
SUSE-SU-2018:1562-1
SUSE-SU-2018:2891-1
SUSE-SU-2019:2091-1
SUSE-SU-2020:0628-1
SUSE-SU-2020:1135-1
SUSE-SU-2020:1596-1
SUSE-SU-2020:2066-1
SUSE-SU-2020:2582-1
SUSE-SU-2020:3085-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Server 12 SP3
SUSE Linux Enterprise Server 12 SP3-BCL
SUSE Linux Enterprise Server 12 SP3-ESPOS
SUSE Linux Enterprise Server 12 SP3-LTSS
SUSE Linux Enterprise Server 12 SP3-TERADATA
SUSE Linux Enterprise Server 12 SP4
SUSE Linux Enterprise Server 12 SP4-ESPOS
SUSE Linux Enterprise Server 12 SP4-LTSS
SUSE OpenStack Cloud 9
SUSE OpenStack Cloud Crowbar 8
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • MozillaFirefox-68.6.0-lp151.2.33 is installed
  • OR MozillaFirefox-branding-upstream-68.6.0-lp151.2.33 is installed
  • OR MozillaFirefox-buildsymbols-68.6.0-lp151.2.33 is installed
  • OR MozillaFirefox-devel-68.6.0-lp151.2.33 is installed
  • OR MozillaFirefox-translations-common-68.6.0-lp151.2.33 is installed
  • OR MozillaFirefox-translations-other-68.6.0-lp151.2.33 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • qemu-4.2.1-lp152.9.3 is installed
  • OR qemu-arm-4.2.1-lp152.9.3 is installed
  • OR qemu-audio-alsa-4.2.1-lp152.9.3 is installed
  • OR qemu-audio-pa-4.2.1-lp152.9.3 is installed
  • OR qemu-audio-sdl-4.2.1-lp152.9.3 is installed
  • OR qemu-block-curl-4.2.1-lp152.9.3 is installed
  • OR qemu-block-dmg-4.2.1-lp152.9.3 is installed
  • OR qemu-block-gluster-4.2.1-lp152.9.3 is installed
  • OR qemu-block-iscsi-4.2.1-lp152.9.3 is installed
  • OR qemu-block-nfs-4.2.1-lp152.9.3 is installed
  • OR qemu-block-rbd-4.2.1-lp152.9.3 is installed
  • OR qemu-block-ssh-4.2.1-lp152.9.3 is installed
  • OR qemu-extra-4.2.1-lp152.9.3 is installed
  • OR qemu-guest-agent-4.2.1-lp152.9.3 is installed
  • OR qemu-ipxe-1.0.0+-lp152.9.3 is installed
  • OR qemu-ksm-4.2.1-lp152.9.3 is installed
  • OR qemu-kvm-4.2.1-lp152.9.3 is installed
  • OR qemu-lang-4.2.1-lp152.9.3 is installed
  • OR qemu-linux-user-4.2.1-lp152.9.3 is installed
  • OR qemu-microvm-4.2.1-lp152.9.3 is installed
  • OR qemu-ppc-4.2.1-lp152.9.3 is installed
  • OR qemu-s390-4.2.1-lp152.9.3 is installed
  • OR qemu-seabios-1.12.1+-lp152.9.3 is installed
  • OR qemu-sgabios-8-lp152.9.3 is installed
  • OR qemu-testsuite-4.2.1-lp152.9.3 is installed
  • OR qemu-tools-4.2.1-lp152.9.3 is installed
  • OR qemu-ui-curses-4.2.1-lp152.9.3 is installed
  • OR qemu-ui-gtk-4.2.1-lp152.9.3 is installed
  • OR qemu-ui-sdl-4.2.1-lp152.9.3 is installed
  • OR qemu-ui-spice-app-4.2.1-lp152.9.3 is installed
  • OR qemu-vgabios-1.12.1+-lp152.9.3 is installed
  • OR qemu-vhost-user-gpu-4.2.1-lp152.9.3 is installed
  • OR qemu-x86-4.2.1-lp152.9.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3 is installed
  • AND openvswitch-2.7.0-3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-BCL is installed
  • AND Package Information
  • libpython2_7-1_0-2.7.13-28.31 is installed
  • OR libpython2_7-1_0-32bit-2.7.13-28.31 is installed
  • OR python-2.7.13-28.31 is installed
  • OR python-32bit-2.7.13-28.31 is installed
  • OR python-base-2.7.13-28.31 is installed
  • OR python-base-32bit-2.7.13-28.31 is installed
  • OR python-curses-2.7.13-28.31 is installed
  • OR python-demo-2.7.13-28.31 is installed
  • OR python-devel-2.7.13-28.31 is installed
  • OR python-doc-2.7.13-28.31 is installed
  • OR python-doc-pdf-2.7.13-28.31 is installed
  • OR python-gdbm-2.7.13-28.31 is installed
  • OR python-idle-2.7.13-28.31 is installed
  • OR python-tk-2.7.13-28.31 is installed
  • OR python-xml-2.7.13-28.31 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-ESPOS is installed
  • AND Package Information
  • kgraft-patch-4_4_180-94_113-default-5-2 is installed
  • OR kgraft-patch-SLE12-SP3_Update_30-5-2 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-LTSS is installed
  • AND Package Information
  • libjavascriptcoregtk-4_0-18-2.28.1-2.50 is installed
  • OR libwebkit2gtk-4_0-37-2.28.1-2.50 is installed
  • OR libwebkit2gtk3-lang-2.28.1-2.50 is installed
  • OR typelib-1_0-JavaScriptCore-4_0-2.28.1-2.50 is installed
  • OR typelib-1_0-WebKit2-4_0-2.28.1-2.50 is installed
  • OR webkit2gtk-4_0-injected-bundles-2.28.1-2.50 is installed
  • OR webkit2gtk3-2.28.1-2.50 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP3-TERADATA is installed
  • AND Package Information
  • jakarta-commons-fileupload-1.1.1-122.3 is installed
  • OR jakarta-commons-fileupload-javadoc-1.1.1-122.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4 is installed
  • AND autofs-5.0.9-28.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-ESPOS is installed
  • AND Package Information
  • MozillaFirefox-78.0.1-112.3 is installed
  • OR MozillaFirefox-branding-SLE-78-35.3 is installed
  • OR MozillaFirefox-devel-78.0.1-112.3 is installed
  • OR MozillaFirefox-translations-common-78.0.1-112.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND Package Information
  • tomcat-9.0.36-3.45 is installed
  • OR tomcat-admin-webapps-9.0.36-3.45 is installed
  • OR tomcat-docs-webapp-9.0.36-3.45 is installed
  • OR tomcat-el-3_0-api-9.0.36-3.45 is installed
  • OR tomcat-javadoc-9.0.36-3.45 is installed
  • OR tomcat-jsp-2_3-api-9.0.36-3.45 is installed
  • OR tomcat-lib-9.0.36-3.45 is installed
  • OR tomcat-servlet-4_0-api-9.0.36-3.45 is installed
  • OR tomcat-webapps-9.0.36-3.45 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud 9 is installed
  • AND python-urllib3-1.23-3.6 is installed
  • Definition Synopsis
  • SUSE OpenStack Cloud Crowbar 8 is installed
  • AND Package Information
  • kernel-default-4.4.180-94.121 is installed
  • OR kernel-default-base-4.4.180-94.121 is installed
  • OR kernel-default-devel-4.4.180-94.121 is installed
  • OR kernel-default-kgraft-4.4.180-94.121 is installed
  • OR kernel-devel-4.4.180-94.121 is installed
  • OR kernel-macros-4.4.180-94.121 is installed
  • OR kernel-source-4.4.180-94.121 is installed
  • OR kernel-syms-4.4.180-94.121 is installed
  • OR kgraft-patch-4_4_180-94_121-default-1-4.5 is installed
  • OR kgraft-patch-SLE12-SP3_Update_32-1-4.5 is installed
  • BACK