Oval Definition:oval:org.opensuse.security:def:64146
Revision Date:2020-12-01Version:1
Title:Security update for the Linux Kernel (Important)
Description:

The SUSE Linux Enterprise 12 SP4 kernel was updated to receive various security and bugfixes.

The following security bugs were fixed:

- CVE-2020-1749: Use ip6_dst_lookup_flow instead of ip6_dst_lookup (bsc#1165629). - CVE-2020-14314: Fixed a potential negative array index in do_split() (bsc#1173798). - CVE-2020-14356: Fixed a null pointer dereference in cgroupv2 subsystem which could have led to privilege escalation (bsc#1175213). - CVE-2020-14331: Fixed a missing check in vgacon scrollback handling (bsc#1174205). - CVE-2020-16166: Fixed a potential issue which could have allowed remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG (bsc#1174757). - CVE-2020-24394: Fixed an issue which could set incorrect permissions on new filesystem objects when the filesystem lacks ACL support (bsc#1175518). - CVE-2020-10135: Legacy pairing and secure-connections pairing authentication Bluetooth might have allowed an unauthenticated user to complete authentication without pairing credentials via adjacent access (bsc#1171988). - CVE-2020-14386: Fixed a potential local privilege escalation via memory corruption (bsc#1176069).

The following non-security bugs were fixed:

- btrfs: remove a BUG_ON() from merge_reloc_roots() (bsc#1174784). - cifs: document and cleanup dfs mount (bsc#1144333 bsc#1172428). - cifs: Fix an error pointer dereference in cifs_mount() (bsc#1144333 bsc#1172428). - cifs: fix double free error on share and prefix (bsc#1144333 bsc#1172428). - cifs: handle empty list of targets in cifs_reconnect() (bsc#1144333 bsc#1172428). - cifs: handle RESP_GET_DFS_REFERRAL.PathConsumed in reconnect (bsc#1144333 bsc#1172428). - cifs: merge __{cifs,smb2}_reconnect[_tcon]() into cifs_tree_connect() (bsc#1144333 bsc#1172428). - cifs: only update prefix path of DFS links in cifs_tree_connect() (bsc#1144333 bsc#1172428). - cifs: reduce number of referral requests in DFS link lookups (bsc#1144333 bsc#1172428). - cifs: rename reconn_inval_dfs_target() (bsc#1144333 bsc#1172428). - Drivers: hv: vmbus: Only notify Hyper-V for die events that are oops (bsc#1175127). - ibmvnic: Fix IRQ mapping disposal in error path (bsc#1175112 ltc#187459). - ip6_tunnel: allow not to count pkts on tstats by passing dev as NULL (bsc#1175515). - ip_tunnel: allow not to count pkts on tstats by setting skb's dev to NULL (bsc#1175515). - ipvs: fix the connection sync failed in some cases (bsc#1174699). - kabi: hide new parameter of ip6_dst_lookup_flow() (bsc#1165629). - kabi: mask changes to struct ipv6_stub (bsc#1165629). - mm: Avoid calling build_all_zonelists_init under hotplug context (bsc#1154366). - mm, vmstat: reduce zone->lock holding time by /proc/pagetypeinfo (bsc#1175691). - ocfs2: add trimfs dlm lock resource (bsc#1175228). - ocfs2: add trimfs lock to avoid duplicated trims in cluster (bsc#1175228). - ocfs2: avoid inode removal while nfsd is accessing it (bsc#1172963). - ocfs2: avoid inode removal while nfsd is accessing it (bsc#1172963). - ocfs2: fix panic on nfs server over ocfs2 (bsc#1172963). - ocfs2: fix panic on nfs server over ocfs2 (bsc#1172963). - ocfs2: fix remounting needed after setfacl command (bsc#1173954). - ocfs2: fix the application IO timeout when fstrim is running (bsc#1175228). - ocfs2: load global_inode_alloc (bsc#1172963). - ocfs2: load global_inode_alloc (bsc#1172963). - powerpc/eeh: Fix pseries_eeh_configure_bridge() (bsc#1174689). - powerpc/pseries: PCIE PHB reset (bsc#1174689). - Revert 'ocfs2: fix panic on nfs server over ocfs2 (bsc#1172963).' This reverts commit 2638f62c6bc33d4c10ce0dddbf240aa80d366d7b. - Revert 'ocfs2: load global_inode_alloc (bsc#1172963).' This reverts commit f04f670651f505cb354f26601ec5f5e4428f2f47. - scsi: scsi_dh_alua: skip RTPG for devices only supporting active/optimized (bsc#1174978). - selftests/livepatch: fix mem leaks in test-klp-shadow-vars (bsc#1071995). - selftests/livepatch: more verification in test-klp-shadow-vars (bsc#1071995). - selftests/livepatch: rework test-klp-shadow-vars (bsc#1071995). - selftests/livepatch: simplify test-klp-callbacks busy target tests (bsc#1071995). - Update patch reference for a tipc fix patch (bsc#1175515) - x86/unwind/orc: Fix ORC for newly forked tasks (bsc#1058115). - xen: do not reschedule in preemption off sections (bsc#1175749).
Family:unixClass:patch
Status:Reference(s):1013712
1058115
1071995
1115015
1115022
1115025
1121826
1144333
1145579
1145580
1145582
1154366
1163026
1165629
1171988
1172399
1172428
1172963
1173786
1173798
1173954
1174010
1174205
1174579
1174689
1174699
1174757
1174784
1174978
1175112
1175127
1175213
1175223
1175228
1175515
1175518
1175596
1175691
1175749
1176069
1177472
1178428
CVE-2012-5519
CVE-2014-3537
CVE-2014-5029
CVE-2014-5030
CVE-2014-5031
CVE-2015-1158
CVE-2015-1159
CVE-2016-9798
CVE-2017-18248
CVE-2018-16843
CVE-2018-16844
CVE-2018-16845
CVE-2018-4180
CVE-2018-4181
CVE-2018-4182
CVE-2018-4183
CVE-2018-4700
CVE-2019-6133
CVE-2019-9511
CVE-2019-9513
CVE-2019-9516
CVE-2020-10135
CVE-2020-14314
CVE-2020-14331
CVE-2020-14356
CVE-2020-14386
CVE-2020-14765
CVE-2020-14776
CVE-2020-14789
CVE-2020-14812
CVE-2020-15180
CVE-2020-15953
CVE-2020-16166
CVE-2020-1749
CVE-2020-24394
CVE-2020-5208
CVE-2020-7068
openSUSE-SU-2019:1914-1
openSUSE-SU-2019:2120-1
openSUSE-SU-2019:2588-1
openSUSE-SU-2020:0247-1
openSUSE-SU-2020:1354-1
openSUSE-SU-2020:1454-1
SUSE-SU-2020:2623-1
SUSE-SU-2020:3497-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Module for Basesystem 15 SP1
SUSE Linux Enterprise Server 12 SP4-LTSS
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • libpolkit0-0.114-lp151.5.3 is installed
  • OR libpolkit0-32bit-0.114-lp151.5.3 is installed
  • OR polkit-0.114-lp151.5.3 is installed
  • OR polkit-devel-0.114-lp151.5.3 is installed
  • OR polkit-doc-0.114-lp151.5.3 is installed
  • OR typelib-1_0-Polkit-1_0-0.114-lp151.5.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • libetpan-1.9.4-lp152.3.3 is installed
  • OR libetpan-devel-1.9.4-lp152.3.3 is installed
  • OR libetpan20-1.9.4-lp152.3.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • cups-2.2.7-3.11 is installed
  • OR cups-client-2.2.7-3.11 is installed
  • OR cups-config-2.2.7-3.11 is installed
  • OR cups-devel-2.2.7-3.11 is installed
  • OR libcups2-2.2.7-3.11 is installed
  • OR libcups2-32bit-2.2.7-3.11 is installed
  • OR libcupscgi1-2.2.7-3.11 is installed
  • OR libcupsimage2-2.2.7-3.11 is installed
  • OR libcupsmime1-2.2.7-3.11 is installed
  • OR libcupsppdc1-2.2.7-3.11 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND Package Information
  • kernel-default-4.12.14-95.60 is installed
  • OR kernel-default-base-4.12.14-95.60 is installed
  • OR kernel-default-devel-4.12.14-95.60 is installed
  • OR kernel-default-man-4.12.14-95.60 is installed
  • OR kernel-devel-4.12.14-95.60 is installed
  • OR kernel-macros-4.12.14-95.60 is installed
  • OR kernel-source-4.12.14-95.60 is installed
  • OR kernel-syms-4.12.14-95.60 is installed
  • BACK