Oval Definition:oval:org.opensuse.security:def:87331
Revision Date:2020-01-10Version:1
Title:Security update for the Linux Kernel (Moderate)
Description:

The SLE12 SP3 Teradata kernel was updated to receive various security and bugfixes.

The following security bugs were fixed:

- CVE-2019-20054: Fixed a NULL pointer dereference in drop_sysctl_table() in fs/proc/proc_sysctl.c, related to put_links (bnc#1159910). - CVE-2019-20096: Fixed a memory leak in __feat_register_sp() in net/dccp/feat.c, which may cause denial of service (bnc#1159908). - CVE-2019-19966: Fixed a use-after-free in cpia2_exit() in drivers/media/usb/cpia2/cpia2_v4l.c that will cause denial of service (bnc#1159841). - CVE-2019-19447: Mounting a crafted ext4 filesystem image, performing some operations, and unmounting could lead to a use-after-free in ext4_put_super in fs/ext4/super.c, related to dump_orphan_list in fs/ext4/super.c (bnc#1158819). - CVE-2019-19319: A setxattr operation, after a mount of a crafted ext4 image, can cause a slab-out-of-bounds write access because of an ext4_xattr_set_entry use-after-free in fs/ext4/xattr.c when a large old_size value is used in a memset call (bnc#1158021). - CVE-2019-19767: Fixed mishandling of ext4_expand_extra_isize, as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry, related to fs/ext4/inode.c and fs/ext4/super.c (bnc#1159297).

The following non-security bugs were fixed:

- Revert patch since it is causing IO hangs (bsc#1103717 bsc#1153753). - ext4: fix use-after-free race with debug_want_extra_isize (bsc#1136449).
Family:unixClass:patch
Status:Reference(s):1103717
1136449
1153753
1158021
1158819
1159297
1159841
1159908
1159910
972655
CVE-2019-19319
CVE-2019-19447
CVE-2019-19767
CVE-2019-19966
CVE-2019-20054
CVE-2019-20096
Platform(s):SUSE Linux Enterprise Server 12 SP3-TERADATA
Product(s):
BACK