Oval Definition:oval:org.opensuse.security:def:64186
Revision Date:2020-12-01Version:1
Title:Security update for the Linux Kernel (Important)
Description:



The SUSE Linux Enterprise 12 SP4 kernel was updated to receive various security and bug fixes.

The following security bugs were fixed:

- CVE-2020-25705: A flaw in the way reply ICMP packets are limited in was found that allowed to quickly scan open UDP ports. This flaw allowed an off-path remote user to effectively bypassing source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software and services that rely on UDP source port randomization (like DNS) are indirectly affected as well. Kernel versions may be vulnerable to this issue (bsc#1175721, bsc#1178782). - CVE-2020-25704: Fixed a memory leak in perf_event_parse_addr_filter() (bsc#1178393). - CVE-2020-25668: Fixed a use-after-free in con_font_op() (bnc#1178123). - CVE-2020-25656: Fixed a concurrency use-after-free in vt_do_kdgkb_ioctl (bnc#1177766). - CVE-2020-25285: Fixed a race condition between hugetlb sysctl handlers in mm/hugetlb.c (bnc#1176485). - CVE-2020-0430: Fixed an OOB read in skb_headlen of /include/linux/skbuff.h (bnc#1176723). - CVE-2020-14351: Fixed a race in the perf_mmap_close() function (bsc#1177086). - CVE-2020-16120: Fixed a permissions issue in ovl_path_open() (bsc#1177470). - CVE-2020-8694: Restricted energy meter to root access (bsc#1170415). - CVE-2020-12351: Implemented a kABI workaround for bluetooth l2cap_ops filter addition (bsc#1177724). - CVE-2020-12352: Fixed an information leak when processing certain AMP packets aka 'BleedingTooth' (bsc#1177725). - CVE-2020-25212: Fixed a TOCTOU mismatch in the NFS client code (bnc#1176381). - CVE-2020-25645: Fixed an an issue in IPsec that caused traffic between two Geneve endpoints to be unencrypted (bnc#1177511). - CVE-2020-14381: Fixed a UAF in the fast user mutex (futex) wait operation (bsc#1176011). - CVE-2020-25643: Fixed an improper input validation in the ppp_cp_parse_cr function of the HDLC_PPP module (bnc#1177206). - CVE-2020-25641: Fixed a zero-length biovec request issued by the block subsystem could have caused the kernel to enter an infinite loop, causing a denial of service (bsc#1177121). - CVE-2020-26088: Fixed an improper CAP_NET_RAW check in NFC socket creation could have been used by local attackers to create raw sockets, bypassing security mechanisms (bsc#1176990). - CVE-2020-14390: Fixed an out-of-bounds memory write leading to memory corruption or a denial of service when changing screen size (bnc#1176235). - CVE-2020-0432: Fixed an out of bounds write due to an integer overflow (bsc#1176721). - CVE-2020-0427: Fixed an out of bounds read due to a use after free (bsc#1176725). - CVE-2020-0431: Fixed an out of bounds write due to a missing bounds check (bsc#1176722). - CVE-2020-0404: Fixed a linked list corruption due to an unusual root cause (bsc#1176423). - CVE-2020-25284: Fixed an incomplete permission checking for access to rbd devices, which could have been leveraged by local attackers to map or unmap rbd block devices (bsc#1176482). - CVE-2020-27673: Fixed an issue where rogue guests could have caused denial of service of Dom0 via high frequency events (XSA-332 bsc#1177411) - CVE-2020-27675: Fixed a race condition in event handler which may crash dom0 (XSA-331 bsc#1177410).

The following non-security bugs were fixed:

- btrfs: remove root usage from can_overcommit (bsc#1131277). - hv: vmbus: Add timeout to vmbus_wait_for_unload (bsc#1177816). - hyperv_fb: disable superfluous VERSION_WIN10_V5 case (bsc#1175306). - hyperv_fb: Update screen_info after removing old framebuffer (bsc#1175306). - livepatch: Add -fdump-ipa-clones to build (). Add support for -fdump-ipa-clones GCC option. Update config files accordingly. - livepatch: Test if -fdump-ipa-clones is really available As of now we add -fdump-ipa-clones unconditionally. It does not cause a trouble if the kernel is build with the supported toolchain. Otherwise it could fail easily. Do the correct thing and test for the availability. - NFS: On fatal writeback errors, we need to call nfs_inode_remove_request() (bsc#1177340). - NFS: only invalidate dentrys that are clearly invalid (bsc#1178669 bsc#1170139). - NFS: Revalidate the file mapping on all fatal writeback errors (bsc#1177340). - NFSv4: do not mark all open state for recovery when handling recallable state revoked flag (bsc#1176935). - obsolete_kmp: provide newer version than the obsoleted one (boo#1170232). - ocfs2: give applications more IO opportunities during fstrim (bsc#1175228). - powerpc/pseries/cpuidle: add polling idle for shared processor guests (bsc#1178765 ltc#188968). - rpadlpar_io: Add MODULE_DESCRIPTION entries to kernel modules (bsc#1176869 ltc#188243). - scsi: fnic: Do not call 'scsi_done()' for unhandled commands (bsc#1168468, bsc#1171675). - scsi: qla2xxx: Do not consume srb greedily (bsc#1173233). - scsi: qla2xxx: Handle incorrect entry_type entries (bsc#1173233). - video: hyperv: hyperv_fb: Obtain screen resolution from Hyper-V host (bsc#1175306). - video: hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (bsc#1175306). - video: hyperv: hyperv_fb: Use physical memory for fb on HyperV Gen 1 VMs (bsc#1175306). - x86/kexec: Use up-to-dated screen_info copy to fill boot params (bsc#1175306). - xen/blkback: use lateeoi irq binding (XSA-332 bsc#1177411). - xen/events: add a new 'late EOI' evtchn framework (XSA-332 bsc#1177411). - xen/events: add a proper barrier to 2-level uevent unmasking (XSA-332 bsc#1177411). - xen/events: avoid removing an event channel while handling it (XSA-331 bsc#1177410). - xen/events: block rogue events for some time (XSA-332 bsc#1177411). - xen/events: defer eoi in case of excessive number of events (XSA-332 bsc#1177411). - xen/events: do not use chip_data for legacy IRQs (XSA-332 bsc#1065600). - xen/events: fix race in evtchn_fifo_unmask() (XSA-332 bsc#1177411). - xen/events: switch user event channels to lateeoi model (XSA-332 bsc#1177411). - xen/events: use a common cpu hotplug hook for event channels (XSA-332 bsc#1177411). - xen/netback: use lateeoi irq binding (XSA-332 bsc#1177411). - xen/pciback: use lateeoi irq binding (XSA-332 bsc#1177411). - xen/scsiback: use lateeoi irq binding (XSA-332 bsc#1177411). - xen uses irqdesc::irq_data_common::handler_data to store a per interrupt XEN data pointer which contains XEN specific information (XSA-332 bsc#1065600).
Family:unixClass:patch
Status:Reference(s):1051510
1058115
1065600
1118367
1118368
1124194
1125369
1128598
1131277
1132657
1132879
1135247
1138687
1139924
1146090
1146091
1146093
1146094
1146095
1146097
1146099
1146100
1159550
1159723
1159729
1160947
1163524
1166965
1168468
1170139
1170232
1170415
1171417
1171675
1172073
1172366
1173115
1173233
1174148
1174150
1174152
1174253
1175228
1175306
1175721
1175882
1176011
1176235
1176278
1176381
1176423
1176482
1176485
1176698
1176721
1176722
1176723
1176725
1176732
1176733
1176869
1176907
1176922
1176935
1176950
1176990
1177027
1177086
1177121
1177206
1177340
1177410
1177411
1177470
1177511
1177724
1177725
1177766
1177816
1178123
1178330
1178393
1178669
1178765
1178782
1178838
CVE-2016-10198
CVE-2016-10199
CVE-2017-5837
CVE-2017-5838
CVE-2017-5839
CVE-2017-5840
CVE-2017-5841
CVE-2017-5842
CVE-2017-5843
CVE-2017-5844
CVE-2017-5845
CVE-2017-5846
CVE-2017-5847
CVE-2017-5848
CVE-2018-16838
CVE-2019-10072
CVE-2019-11328
CVE-2019-12418
CVE-2019-17563
CVE-2019-19724
CVE-2019-6471
CVE-2019-9511
CVE-2019-9512
CVE-2019-9513
CVE-2019-9514
CVE-2019-9515
CVE-2019-9516
CVE-2019-9517
CVE-2019-9518
CVE-2020-0404
CVE-2020-0427
CVE-2020-0430
CVE-2020-0431
CVE-2020-0432
CVE-2020-11800
CVE-2020-12351
CVE-2020-12352
CVE-2020-13845
CVE-2020-13846
CVE-2020-13847
CVE-2020-14351
CVE-2020-14381
CVE-2020-14390
CVE-2020-15803
CVE-2020-16120
CVE-2020-25212
CVE-2020-25284
CVE-2020-25285
CVE-2020-25641
CVE-2020-25643
CVE-2020-25645
CVE-2020-25656
CVE-2020-25668
CVE-2020-25704
CVE-2020-25705
CVE-2020-26088
CVE-2020-26117
CVE-2020-27673
CVE-2020-27675
CVE-2020-8694
openSUSE-SU-2019:1589-1
openSUSE-SU-2019:2114-1
openSUSE-SU-2019:2265-1
openSUSE-SU-2020:0038-1
openSUSE-SU-2020:1037-1
openSUSE-SU-2020:1604-1
openSUSE-SU-2020:1666-1
SUSE-SU-2020:3544-1
Platform(s):openSUSE Leap 15.1
openSUSE Leap 15.2
SUSE Linux Enterprise Module for Basesystem 15 SP1
SUSE Linux Enterprise Server 12 SP4-LTSS
Product(s):
Definition Synopsis
  • openSUSE Leap 15.1 is installed
  • AND Package Information
  • libipa_hbac-devel-1.16.1-lp151.7.3 is installed
  • OR libipa_hbac0-1.16.1-lp151.7.3 is installed
  • OR libnfsidmap-sss-1.16.1-lp151.7.3 is installed
  • OR libsss_certmap-devel-1.16.1-lp151.7.3 is installed
  • OR libsss_certmap0-1.16.1-lp151.7.3 is installed
  • OR libsss_idmap-devel-1.16.1-lp151.7.3 is installed
  • OR libsss_idmap0-1.16.1-lp151.7.3 is installed
  • OR libsss_nss_idmap-devel-1.16.1-lp151.7.3 is installed
  • OR libsss_nss_idmap0-1.16.1-lp151.7.3 is installed
  • OR libsss_simpleifp-devel-1.16.1-lp151.7.3 is installed
  • OR libsss_simpleifp0-1.16.1-lp151.7.3 is installed
  • OR python3-ipa_hbac-1.16.1-lp151.7.3 is installed
  • OR python3-sss-murmur-1.16.1-lp151.7.3 is installed
  • OR python3-sss_nss_idmap-1.16.1-lp151.7.3 is installed
  • OR python3-sssd-config-1.16.1-lp151.7.3 is installed
  • OR sssd-1.16.1-lp151.7.3 is installed
  • OR sssd-32bit-1.16.1-lp151.7.3 is installed
  • OR sssd-ad-1.16.1-lp151.7.3 is installed
  • OR sssd-dbus-1.16.1-lp151.7.3 is installed
  • OR sssd-ipa-1.16.1-lp151.7.3 is installed
  • OR sssd-krb5-1.16.1-lp151.7.3 is installed
  • OR sssd-krb5-common-1.16.1-lp151.7.3 is installed
  • OR sssd-ldap-1.16.1-lp151.7.3 is installed
  • OR sssd-proxy-1.16.1-lp151.7.3 is installed
  • OR sssd-tools-1.16.1-lp151.7.3 is installed
  • OR sssd-wbclient-1.16.1-lp151.7.3 is installed
  • OR sssd-wbclient-devel-1.16.1-lp151.7.3 is installed
  • OR sssd-winbind-idmap-1.16.1-lp151.7.3 is installed
  • Definition Synopsis
  • openSUSE Leap 15.2 is installed
  • AND Package Information
  • libXvnc-devel-1.9.0-lp152.7.3 is installed
  • OR libXvnc1-1.9.0-lp152.7.3 is installed
  • OR tigervnc-1.9.0-lp152.7.3 is installed
  • OR tigervnc-x11vnc-1.9.0-lp152.7.3 is installed
  • OR xorg-x11-Xvnc-1.9.0-lp152.7.3 is installed
  • OR xorg-x11-Xvnc-java-1.9.0-lp152.7.3 is installed
  • OR xorg-x11-Xvnc-module-1.9.0-lp152.7.3 is installed
  • OR xorg-x11-Xvnc-novnc-1.9.0-lp152.7.3 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Module for Basesystem 15 SP1 is installed
  • AND Package Information
  • gstreamer-1.12.5-1 is installed
  • OR gstreamer-lang-1.12.5-1 is installed
  • OR libgstreamer-1_0-0-1.12.5-1 is installed
  • Definition Synopsis
  • SUSE Linux Enterprise Server 12 SP4-LTSS is installed
  • AND Package Information
  • kernel-default-4.12.14-95.65 is installed
  • OR kernel-default-base-4.12.14-95.65 is installed
  • OR kernel-default-devel-4.12.14-95.65 is installed
  • OR kernel-default-man-4.12.14-95.65 is installed
  • OR kernel-devel-4.12.14-95.65 is installed
  • OR kernel-macros-4.12.14-95.65 is installed
  • OR kernel-source-4.12.14-95.65 is installed
  • OR kernel-syms-4.12.14-95.65 is installed
  • BACK