Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2020:3544-1

Опубликовано: 26 нояб. 2020
Источник: suse-cvrf

Описание

Security update for the Linux Kernel

The SUSE Linux Enterprise 12 SP4 kernel was updated to receive various security and bug fixes.

The following security bugs were fixed:

  • CVE-2020-25705: A flaw in the way reply ICMP packets are limited in was found that allowed to quickly scan open UDP ports. This flaw allowed an off-path remote user to effectively bypassing source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software and services that rely on UDP source port randomization (like DNS) are indirectly affected as well. Kernel versions may be vulnerable to this issue (bsc#1175721, bsc#1178782).
  • CVE-2020-25704: Fixed a memory leak in perf_event_parse_addr_filter() (bsc#1178393).
  • CVE-2020-25668: Fixed a use-after-free in con_font_op() (bnc#1178123).
  • CVE-2020-25656: Fixed a concurrency use-after-free in vt_do_kdgkb_ioctl (bnc#1177766).
  • CVE-2020-25285: Fixed a race condition between hugetlb sysctl handlers in mm/hugetlb.c (bnc#1176485).
  • CVE-2020-0430: Fixed an OOB read in skb_headlen of /include/linux/skbuff.h (bnc#1176723).
  • CVE-2020-14351: Fixed a race in the perf_mmap_close() function (bsc#1177086).
  • CVE-2020-16120: Fixed a permissions issue in ovl_path_open() (bsc#1177470).
  • CVE-2020-8694: Restricted energy meter to root access (bsc#1170415).
  • CVE-2020-12351: Implemented a kABI workaround for bluetooth l2cap_ops filter addition (bsc#1177724).
  • CVE-2020-12352: Fixed an information leak when processing certain AMP packets aka 'BleedingTooth' (bsc#1177725).
  • CVE-2020-25212: Fixed a TOCTOU mismatch in the NFS client code (bnc#1176381).
  • CVE-2020-25645: Fixed an an issue in IPsec that caused traffic between two Geneve endpoints to be unencrypted (bnc#1177511).
  • CVE-2020-14381: Fixed a UAF in the fast user mutex (futex) wait operation (bsc#1176011).
  • CVE-2020-25643: Fixed an improper input validation in the ppp_cp_parse_cr function of the HDLC_PPP module (bnc#1177206).
  • CVE-2020-25641: Fixed a zero-length biovec request issued by the block subsystem could have caused the kernel to enter an infinite loop, causing a denial of service (bsc#1177121).
  • CVE-2020-26088: Fixed an improper CAP_NET_RAW check in NFC socket creation could have been used by local attackers to create raw sockets, bypassing security mechanisms (bsc#1176990).
  • CVE-2020-14390: Fixed an out-of-bounds memory write leading to memory corruption or a denial of service when changing screen size (bnc#1176235).
  • CVE-2020-0432: Fixed an out of bounds write due to an integer overflow (bsc#1176721).
  • CVE-2020-0427: Fixed an out of bounds read due to a use after free (bsc#1176725).
  • CVE-2020-0431: Fixed an out of bounds write due to a missing bounds check (bsc#1176722).
  • CVE-2020-0404: Fixed a linked list corruption due to an unusual root cause (bsc#1176423).
  • CVE-2020-25284: Fixed an incomplete permission checking for access to rbd devices, which could have been leveraged by local attackers to map or unmap rbd block devices (bsc#1176482).
  • CVE-2020-27673: Fixed an issue where rogue guests could have caused denial of service of Dom0 via high frequency events (XSA-332 bsc#1177411)
  • CVE-2020-27675: Fixed a race condition in event handler which may crash dom0 (XSA-331 bsc#1177410).

The following non-security bugs were fixed:

  • btrfs: remove root usage from can_overcommit (bsc#1131277).
  • hv: vmbus: Add timeout to vmbus_wait_for_unload (bsc#1177816).
  • hyperv_fb: disable superfluous VERSION_WIN10_V5 case (bsc#1175306).
  • hyperv_fb: Update screen_info after removing old framebuffer (bsc#1175306).
  • livepatch: Add -fdump-ipa-clones to build (). Add support for -fdump-ipa-clones GCC option. Update config files accordingly.
  • livepatch: Test if -fdump-ipa-clones is really available As of now we add -fdump-ipa-clones unconditionally. It does not cause a trouble if the kernel is build with the supported toolchain. Otherwise it could fail easily. Do the correct thing and test for the availability.
  • NFS: On fatal writeback errors, we need to call nfs_inode_remove_request() (bsc#1177340).
  • NFS: only invalidate dentrys that are clearly invalid (bsc#1178669 bsc#1170139).
  • NFS: Revalidate the file mapping on all fatal writeback errors (bsc#1177340).
  • NFSv4: do not mark all open state for recovery when handling recallable state revoked flag (bsc#1176935).
  • obsolete_kmp: provide newer version than the obsoleted one (boo#1170232).
  • ocfs2: give applications more IO opportunities during fstrim (bsc#1175228).
  • powerpc/pseries/cpuidle: add polling idle for shared processor guests (bsc#1178765 ltc#188968).
  • rpadlpar_io: Add MODULE_DESCRIPTION entries to kernel modules (bsc#1176869 ltc#188243).
  • scsi: fnic: Do not call 'scsi_done()' for unhandled commands (bsc#1168468, bsc#1171675).
  • scsi: qla2xxx: Do not consume srb greedily (bsc#1173233).
  • scsi: qla2xxx: Handle incorrect entry_type entries (bsc#1173233).
  • video: hyperv: hyperv_fb: Obtain screen resolution from Hyper-V host (bsc#1175306).
  • video: hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (bsc#1175306).
  • video: hyperv: hyperv_fb: Use physical memory for fb on HyperV Gen 1 VMs (bsc#1175306).
  • x86/kexec: Use up-to-dated screen_info copy to fill boot params (bsc#1175306).
  • xen/blkback: use lateeoi irq binding (XSA-332 bsc#1177411).
  • xen/events: add a new 'late EOI' evtchn framework (XSA-332 bsc#1177411).
  • xen/events: add a proper barrier to 2-level uevent unmasking (XSA-332 bsc#1177411).
  • xen/events: avoid removing an event channel while handling it (XSA-331 bsc#1177410).
  • xen/events: block rogue events for some time (XSA-332 bsc#1177411).
  • xen/events: defer eoi in case of excessive number of events (XSA-332 bsc#1177411).
  • xen/events: do not use chip_data for legacy IRQs (XSA-332 bsc#1065600).
  • xen/events: fix race in evtchn_fifo_unmask() (XSA-332 bsc#1177411).
  • xen/events: switch user event channels to lateeoi model (XSA-332 bsc#1177411).
  • xen/events: use a common cpu hotplug hook for event channels (XSA-332 bsc#1177411).
  • xen/netback: use lateeoi irq binding (XSA-332 bsc#1177411).
  • xen/pciback: use lateeoi irq binding (XSA-332 bsc#1177411).
  • xen/scsiback: use lateeoi irq binding (XSA-332 bsc#1177411).
  • xen uses irqdesc::irq_data_common::handler_data to store a per interrupt XEN data pointer which contains XEN specific information (XSA-332 bsc#1065600).

Список пакетов

Image SLES12-SP4-Azure-BYOS
kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS
kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS
kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS
kernel-default-4.12.14-95.65.1
Image SLES12-SP4-SAP-Azure
cluster-md-kmp-default-4.12.14-95.65.1
dlm-kmp-default-4.12.14-95.65.1
gfs2-kmp-default-4.12.14-95.65.1
kernel-default-4.12.14-95.65.1
ocfs2-kmp-default-4.12.14-95.65.1
Image SLES12-SP4-SAP-Azure-BYOS
cluster-md-kmp-default-4.12.14-95.65.1
dlm-kmp-default-4.12.14-95.65.1
gfs2-kmp-default-4.12.14-95.65.1
kernel-default-4.12.14-95.65.1
ocfs2-kmp-default-4.12.14-95.65.1
Image SLES12-SP4-SAP-Azure-LI-BYOS-Production
cluster-md-kmp-default-4.12.14-95.65.1
dlm-kmp-default-4.12.14-95.65.1
gfs2-kmp-default-4.12.14-95.65.1
kernel-default-4.12.14-95.65.1
ocfs2-kmp-default-4.12.14-95.65.1
Image SLES12-SP4-SAP-Azure-VLI-BYOS-Production
cluster-md-kmp-default-4.12.14-95.65.1
dlm-kmp-default-4.12.14-95.65.1
gfs2-kmp-default-4.12.14-95.65.1
kernel-default-4.12.14-95.65.1
ocfs2-kmp-default-4.12.14-95.65.1
Image SLES12-SP4-SAP-EC2-HVM
cluster-md-kmp-default-4.12.14-95.65.1
dlm-kmp-default-4.12.14-95.65.1
gfs2-kmp-default-4.12.14-95.65.1
kernel-default-4.12.14-95.65.1
ocfs2-kmp-default-4.12.14-95.65.1
Image SLES12-SP4-SAP-EC2-HVM-BYOS
cluster-md-kmp-default-4.12.14-95.65.1
dlm-kmp-default-4.12.14-95.65.1
gfs2-kmp-default-4.12.14-95.65.1
kernel-default-4.12.14-95.65.1
ocfs2-kmp-default-4.12.14-95.65.1
Image SLES12-SP4-SAP-GCE
cluster-md-kmp-default-4.12.14-95.65.1
dlm-kmp-default-4.12.14-95.65.1
gfs2-kmp-default-4.12.14-95.65.1
kernel-default-4.12.14-95.65.1
ocfs2-kmp-default-4.12.14-95.65.1
Image SLES12-SP4-SAP-GCE-BYOS
cluster-md-kmp-default-4.12.14-95.65.1
dlm-kmp-default-4.12.14-95.65.1
gfs2-kmp-default-4.12.14-95.65.1
kernel-default-4.12.14-95.65.1
ocfs2-kmp-default-4.12.14-95.65.1
Image SLES12-SP4-SAP-OCI-BYOS
cluster-md-kmp-default-4.12.14-95.65.1
dlm-kmp-default-4.12.14-95.65.1
gfs2-kmp-default-4.12.14-95.65.1
kernel-default-4.12.14-95.65.1
ocfs2-kmp-default-4.12.14-95.65.1
SUSE Linux Enterprise High Availability Extension 12 SP4
cluster-md-kmp-default-4.12.14-95.65.1
dlm-kmp-default-4.12.14-95.65.1
gfs2-kmp-default-4.12.14-95.65.1
ocfs2-kmp-default-4.12.14-95.65.1
SUSE Linux Enterprise Live Patching 12 SP4
kernel-default-kgraft-4.12.14-95.65.1
kernel-default-kgraft-devel-4.12.14-95.65.1
kgraft-patch-4_12_14-95_65-default-1-6.5.1
SUSE Linux Enterprise Server 12 SP4-LTSS
kernel-default-4.12.14-95.65.1
kernel-default-base-4.12.14-95.65.1
kernel-default-devel-4.12.14-95.65.1
kernel-default-man-4.12.14-95.65.1
kernel-devel-4.12.14-95.65.1
kernel-macros-4.12.14-95.65.1
kernel-source-4.12.14-95.65.1
kernel-syms-4.12.14-95.65.1
SUSE Linux Enterprise Server for SAP Applications 12 SP4
kernel-default-4.12.14-95.65.1
kernel-default-base-4.12.14-95.65.1
kernel-default-devel-4.12.14-95.65.1
kernel-devel-4.12.14-95.65.1
kernel-macros-4.12.14-95.65.1
kernel-source-4.12.14-95.65.1
kernel-syms-4.12.14-95.65.1
SUSE OpenStack Cloud 9
kernel-default-4.12.14-95.65.1
kernel-default-base-4.12.14-95.65.1
kernel-default-devel-4.12.14-95.65.1
kernel-devel-4.12.14-95.65.1
kernel-macros-4.12.14-95.65.1
kernel-source-4.12.14-95.65.1
kernel-syms-4.12.14-95.65.1
SUSE OpenStack Cloud Crowbar 9
kernel-default-4.12.14-95.65.1
kernel-default-base-4.12.14-95.65.1
kernel-default-devel-4.12.14-95.65.1
kernel-devel-4.12.14-95.65.1
kernel-macros-4.12.14-95.65.1
kernel-source-4.12.14-95.65.1
kernel-syms-4.12.14-95.65.1

Описание

In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-111893654References: Upstream kernel


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

In create_pinctrl of core.c, there is a possible out of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-140550171


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

In skb_headlen of /include/linux/skbuff.h, there is a possible out of bounds read due to memory corruption. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-153881554


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

In kbd_keycode of keyboard.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-144161459


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

In skb_to_mamac of networking.c, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID: A-143560807


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

Improper input validation in BlueZ may allow an unauthenticated user to potentially enable escalation of privilege via adjacent access.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local attacker with permission to monitor perf events to corrupt memory and possibly escalate privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

A flaw was found in the Linux kernel's futex implementation. This flaw allows a local attacker to corrupt system memory or escalate their privileges when creating a futex on a filesystem that is about to be unmounted. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

A flaw was found in the Linux kernel in versions before 5.9-rc6. When changing screen size, an out-of-bounds memory write can occur leading to memory corruption or a denial of service. Due to the nature of the flaw, privilege escalation cannot be fully ruled out.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

Overlayfs did not properly perform permission checking when copying up files in an overlayfs and could be exploited from within a user namespace, if, for example, unprivileged user namespaces were allowed. It was possible to have a file not readable by an unprivileged user to be copied to a mountpoint controlled by the user, like a removable device. This was introduced in kernel version 4.19 by commit d1d04ef ("ovl: stack file ops"). This was fixed in kernel version 5.8 by commits 56230d9 ("ovl: verify permissions in ovl_path_open()"), 48bd024 ("ovl: switch to mounter creds in readdir") and 05acefb ("ovl: check permission to open real file"). Additionally, commits 130fdbc ("ovl: pass correct flags for opening real directory") and 292f902 ("ovl: call secutiry hook in ovl_real_ioctl()") in kernel 5.8 might also be desired or necessary. These additional commits introduced a regression in overlay mounts within user namespaces which prevented access to files with ownership outside of the user namespace. This regression was mitigated by subsequent commit b6650da ("ovl: do not fail because of O_NOATIMEi") in kernel 5.11.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

A TOCTOU mismatch in the NFS client code in the Linux kernel before 5.8.3 could be used by local attackers to corrupt memory or possibly have unspecified other impact because a size check is in fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b4487b935452.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking for access to rbd devices, which could be leveraged by local attackers to map or unmap rbd block devices, aka CID-f44d04e696fe.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

A race condition between hugetlb sysctl handlers in mm/hugetlb.c in the Linux kernel before 5.8.8 could be used by local attackers to corrupt memory, cause a NULL pointer dereference, or possibly have unspecified other impact, aka CID-17743798d812.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

A flaw was found in the Linux kernel's implementation of biovecs in versions before 5.9-rc7. A zero-length biovec request issued by the block subsystem could cause the kernel to enter an infinite loop, causing a denial of service. This flaw allows a local attacker with basic privileges to issue requests to a block device, resulting in a denial of service. The highest threat from this vulnerability is to system availability.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

A flaw was found in the HDLC_PPP module of the Linux kernel in versions before 5.9-rc7. Memory corruption and a read overflow is caused by improper input validation in the ppp_cp_parse_cr function which can cause the system to crash or cause a denial of service. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

A flaw was found in the Linux kernel in versions before 5.9-rc7. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is to data confidentiality.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

A flaw was found in Linux Kernel because access to the global variable fg_console is not properly synchronized leading to a use after free in con_font_op.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

A flaw memory leak in the Linux kernel performance monitoring subsystem was found in the way if using PERF_EVENT_IOC_SET_FILTER. A local user could use this flaw to starve the resources causing denial of service.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

A flaw in ICMP packets in the Linux kernel may allow an attacker to quickly scan open UDP ports. This flaw allows an off-path remote attacker to effectively bypass source port UDP randomization. Software that relies on UDP source port randomization are indirectly affected as well on the Linux Based Products (RUGGEDCOM RM1224: All versions between v5.0 and v6.4, SCALANCE M-800: All versions between v5.0 and v6.4, SCALANCE S615: All versions between v5.0 and v6.4, SCALANCE SC-600: All versions prior to v2.1.3, SCALANCE W1750D: v8.3.0.1, v8.6.0, and v8.7.0, SIMATIC Cloud Connect 7: All versions, SIMATIC MV500 Family: All versions, SIMATIC NET CP 1243-1 (incl. SIPLUS variants): Versions 3.1.39 and later, SIMATIC NET CP 1243-7 LTE EU: Version


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

A missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c in the Linux kernel before 5.8.2 could be used by local attackers to create raw sockets, bypassing security mechanisms, aka CID-26896f01467a.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. Guest OS users can cause a denial of service (host OS hang) via a high rate of events to dom0, aka CID-e99502f76271.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. drivers/xen/events/events_base.c allows event-channel removal during the event-handling loop (a race condition). This can cause a use-after-free or NULL pointer dereference, as demonstrated by a dom0 crash via events for an in-reconfiguration paravirtualized device, aka CID-073d0552ead5.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки

Описание

Insufficient access control in the Linux kernel driver for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.


Затронутые продукты
Image SLES12-SP4-Azure-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-EC2-HVM-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-GCE-BYOS:kernel-default-4.12.14-95.65.1
Image SLES12-SP4-OCI-BYOS:kernel-default-4.12.14-95.65.1

Ссылки
Уязвимость SUSE-SU-2020:3544-1