Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:1784-1

Опубликовано: 26 июн. 2020
Источник: suse-cvrf

Описание

Security update for the Linux Kernel (Live Patch 26 for SLE 12 SP3)

This update for the Linux Kernel 4.4.180-94_97 fixes several issues.

The following security issues were fixed:

  • CVE-2020-10757: Fixed an issue where remaping hugepage DAX to anon mmap could have caused user PTE access (bsc#1172437).
  • CVE-2019-15666: Fixed an out of bounds read __xfrm_policy_unlink, which could have led to denial of service (bsc#1172140).

Список пакетов

SUSE Linux Enterprise Server 12 SP3-LTSS
kgraft-patch-4_4_180-94_103-default-8-2.1
kgraft-patch-4_4_180-94_100-default-8-2.1
kgraft-patch-4_4_180-94_97-default-10-2.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3
kgraft-patch-4_4_180-94_103-default-8-2.1
kgraft-patch-4_4_180-94_100-default-8-2.1
kgraft-patch-4_4_180-94_97-default-10-2.1

Описание

An issue was discovered in the Linux kernel before 5.0.19. There is an out-of-bounds array access in __xfrm_policy_unlink, which will cause denial of service, because verify_newpolicy_info in net/xfrm/xfrm_user.c mishandles directory validation.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP3-LTSS:kgraft-patch-4_4_180-94_100-default-8-2.1
SUSE Linux Enterprise Server 12 SP3-LTSS:kgraft-patch-4_4_180-94_103-default-8-2.1
SUSE Linux Enterprise Server 12 SP3-LTSS:kgraft-patch-4_4_180-94_97-default-10-2.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3:kgraft-patch-4_4_180-94_100-default-8-2.1

Ссылки

Описание

A flaw was found in the Linux Kernel in versions after 4.5-rc1 in the way mremap handled DAX Huge Pages. This flaw allows a local attacker with access to a DAX enabled storage to escalate their privileges on the system.


Затронутые продукты
SUSE Linux Enterprise Server 12 SP3-LTSS:kgraft-patch-4_4_180-94_100-default-8-2.1
SUSE Linux Enterprise Server 12 SP3-LTSS:kgraft-patch-4_4_180-94_103-default-8-2.1
SUSE Linux Enterprise Server 12 SP3-LTSS:kgraft-patch-4_4_180-94_97-default-10-2.1
SUSE Linux Enterprise Server for SAP Applications 12 SP3:kgraft-patch-4_4_180-94_100-default-8-2.1

Ссылки
Уязвимость SUSE-SU-2020:1784-1