Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

suse-cvrf логотип

SUSE-SU-2026:4282-1

Опубликовано: 22 сент. 2026
Источник: suse-cvrf

Описание

Security update for the Linux Kernel

The SUSE Linux Enterprise 12 SP5 kernel was updated to fix various security issues:

The following security issues were fixed:

  • CVE-2025-40277: drm/vmwgfx: Validate command header size against (bsc#1254894).
  • CVE-2025-68214: timers: Fix NULL function pointer race in timer_shutdown_sync() (bsc#1255225).
  • CVE-2026-43116: netfilter: ctnetlink: ensure safe access to master conntrack (bsc#1264619).
  • CVE-2026-43125: dlm: validate length in dlm_search_rsb_tree (bsc#1264541).
  • CVE-2026-43134: Bluetooth: L2CAP: Fix missing key size check for L2CAP_LE_CONN_REQ (bsc#1264308).
  • CVE-2026-43257: media: cx88: Add missing unmap in snd_cx88_hw_params() (bsc#1264296).
  • CVE-2026-43277: ACPI / APEI: Make GHES estatus header validation more user friendly (bsc#1264594).
  • CVE-2026-43363: x86/apic: Disable x2apic on resume if the kernel expects so (bsc#1265068).
  • CVE-2026-43416: powerpc, perf: Check that current->mm is alive before getting user callchain (bsc#1265121).
  • CVE-2026-45941: tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure (bsc#1266920).
  • CVE-2026-46070: md/raid5: validate payload size before accessing journal metadata (bsc#1267501).
  • CVE-2026-46107: dm-thin: fix metadata refcount underflow (bsc#1267612).
  • CVE-2026-46108: ipmi:si: Return state to normal if message allocation fails (bsc#1267615).
  • CVE-2026-46128: ipmi: Check event message buffer response for bad data (bsc#1267643).
  • CVE-2026-52912: netfilter: nf_queue: hold bridge skb->dev while queued (bsc#1269000).
  • CVE-2026-52920: netfilter: xt_policy: fix strict mode inbound policy matching (bsc#1269013).
  • CVE-2026-52925: vrf: Fix a potential NPD when removing a port from a VRF (bsc#1268987).
  • CVE-2026-52939: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion (bsc#1268972).
  • CVE-2026-52946: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling (bsc#1269113).
  • CVE-2026-53001: netfilter: xtables: restrict several matches to inet family (bsc#1269114).
  • CVE-2026-53059: dm log: fix out-of-bounds write due to region_count overflow (bsc#1269655).
  • CVE-2026-53061: dm cache: fix dirty mapping checking in passthrough mode switching (bsc#1269685).
  • CVE-2026-53077: net/rds: Restrict use of RDS/IB to the initial network namespace (bsc#1269412).
  • CVE-2026-53089: bpf: Fix use-after-free in offloaded map/prog info fill (bsc#1269783).
  • CVE-2026-53091: net: do not use skb_mac_header() in qdisc_pkt_len_init() (bsc#1269530).
  • CVE-2026-53163: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued (bsc#1269306).
  • CVE-2026-53219: netfilter: x_tables: avoid leaking percpu counter pointers (bsc#1269686).
  • CVE-2026-53220: netfilter: revalidate bridge ports (bsc#1269381).
  • CVE-2026-53223: net: guard timestamp cmsgs to real error queue skbs (bsc#1269301).
  • CVE-2026-53228: ipv6: sit: reload inner IPv6 header after GSO offloads (bsc#1269256).
  • CVE-2026-53238: netlabel: validate unlabeled address and mask attribute lengths (bsc#1269774).
  • CVE-2026-53264: net/sched: act_api: use RCU with deferred freeing for action lifecycle (bsc#1269238).
  • CVE-2026-53309: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison (bsc#1269815).
  • CVE-2026-53403: fbdev: Fix fb_new_modelist to prevent null-ptr-deref in (bsc#1271731).
  • CVE-2026-63810: block: Avoid mounting the bdev pseudo-filesystem in userspace (bsc#1272297).
  • CVE-2026-63823: security: don't use RCU accessors for cred->session_keyring (bsc#1272182).
  • CVE-2026-63860: RDMA/core: Prefer NLA_NUL_STRING (bsc#1272429).
  • CVE-2026-63868: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr (bsc#1272497).
  • CVE-2026-63887: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf (bsc#1272385).
  • CVE-2026-63888: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() (bsc#1272390).
  • CVE-2026-63890: scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker (bsc#1272426).
  • CVE-2026-63891: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() (bsc#1272641).
  • CVE-2026-63920: ipv6: validate extension header length before copying to cmsg (bsc#1272877).
  • CVE-2026-63962: usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() (bsc#1272482).
  • CVE-2026-63990: bonding: refuse to enslave CAN devices (bsc#1273027).
  • CVE-2026-64001: ALSA: pcm: oss: Fix setup list UAF on proc write error (bsc#1273734).
  • CVE-2026-64002: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() (bsc#1273774).
  • CVE-2026-64005: net/smc: Do not re-initialize smc hashtables (bsc#1273831).
  • CVE-2026-64007: netfilter: synproxy: refresh tcphdr after skb_ensure_writable (bsc#1273105).
  • CVE-2026-64010: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() (bsc#1273882).
  • CVE-2026-64011: nfc: llcp: Fix use-after-free in llcp_sock_release() (bsc#1273891).
  • CVE-2026-64015: security/keys: fix missed RCU read section on lookup (bsc#1273762).
  • CVE-2026-64088: batman-adv: tt: fix negative tt_buff_len (bsc#1273463).
  • CVE-2026-64103: scsi: isci: Fix use-after-free in device removal path (bsc#1273759).
  • CVE-2026-64109: af_unix: Peek the queue synchronized (bsc#1273748).
  • CVE-2026-64113: ixgbevf: fix use-after-free in VEPA multicast source pruning (bsc#1272262).
  • CVE-2026-64114: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 (bsc#1273742).
  • CVE-2026-64115: vsock/vmci: fix UAF when peer resets connection during handshake (bsc#1273745).
  • CVE-2026-64118: qed: fix double free in qed_cxt_tables_alloc() (bsc#1273749).
  • CVE-2026-64178: Bluetooth: bnep: Fix UAF read of dev->name (bsc#1273946).
  • CVE-2026-64190: net: team: fix NULL pointer dereference in team_xmit during mode change (bsc#1272210).
  • CVE-2026-64304: crypto: qat - validate RSA CRT component lengths (bsc#1273944).
  • CVE-2026-64306: crypto: drbg - Fix returning success on failure in CTR_DRBG (bsc#1273939).
  • CVE-2026-64312: crypto: pcrypt - restore callback for non-parallel fallback (bsc#1273968).
  • CVE-2026-64313: crypto: ecc - Fix carry overflow in vli multiplication (bsc#1273940).
  • CVE-2026-64315: printk: add print_hex_dump_devel() (bsc#1274028).
  • CVE-2026-64317: isofs: bound Rock Ridge symlink components to the SL record (bsc#1273936).
  • CVE-2026-64322: udf: validate sparing table length as an entry count, not a byte count (bsc#1273958).
  • CVE-2026-64323: udf: validate VAT header length against the VAT inode size (bsc#1273305).
  • CVE-2026-64332: USB: ulpi: fix memory leak on registration failure (bsc#1273285).
  • CVE-2026-64333: USB: serial: digi_acceleport: fix write buffer corruption (bsc#1273933).
  • CVE-2026-64334: USB: serial: digi_acceleport: fix hard lockup on disconnect (bsc#1273942).
  • CVE-2026-64340: USB: legousbtower: fix use-after-free on disconnect race (bsc#1274003).
  • CVE-2026-64341: USB: iowarrior: fix use-after-free on disconnect race (bsc#1273895).
  • CVE-2026-64343: USB: ldusb: fix use-after-free on disconnect race (bsc#1273974).
  • CVE-2026-64344: USB: idmouse: simplify disconnect handling (bsc#1274019).
  • CVE-2026-64381: smb: client: Fix next buffer leak in receive_encrypted_standard() (bsc#1273860).
  • CVE-2026-64408: Bluetooth: bnep: pin L2CAP connection during netdev registration (bsc#1273778).
  • CVE-2026-64411: netfilter: ebtables: terminate table name before find_table_lock() (bsc#1274077).
  • CVE-2026-64412: netfilter: ebtables: module names must be null-terminated (bsc#1273780).
  • CVE-2026-64423: ipv4: igmp: remove multicast group from hash table on device destruction (bsc#1274274).
  • CVE-2026-64436: net: af_key: initialize alg_key_len for IPComp states (bsc#1274277).
  • CVE-2026-64470: Bluetooth: btusb: fix use-after-free on marvell probe failure (bsc#1273892).
  • CVE-2026-64471: Bluetooth: btusb: fix use-after-free on registration failure (bsc#1274278).
  • CVE-2026-64512: ACPI: CPPC: Suppress UBSAN warning caused by field misuse (bsc#1273597).
  • CVE-2026-64513: KVM: x86: Move update_cr8_intercept() to lapic.c (bsc#1273327).
  • CVE-2026-64541: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket (bsc#1273303).
  • CVE-2026-64544: crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents (bsc#1273316).
  • CVE-2026-64547: net: usb: net1080: validate packet_len before pad-byte access in rx_fixup (bsc#1273319).
  • CVE-2026-64551: sctp: validate STALE_COOKIE cause length before reading staleness (bsc#1273813).
  • CVE-2026-64553: net: psample: fix info leak in PSAMPLE_ATTR_DATA (bsc#1273336).
  • CVE-2026-64562: KVM: nVMX: Hide shadow VMCS right after VMCLEAR (bsc#1273930).
  • CVE-2026-64567: btrfs: reject free space cache with more entries than pages (bsc#1274006).
  • CVE-2026-64581: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() (bsc#1274041).
  • CVE-2026-64582: RDMA/rxe: Fix a use-after-free problem in rxe_mmap (bsc#1274040).
  • CVE-2026-68082: libceph: fix two unsafe bare decodes in decode_lockers() (bsc#1274581).
  • CVE-2026-68093: KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug (bsc#1274725).
  • CVE-2026-68111: drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() (bsc#1274873).
  • CVE-2026-68117: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() (bsc#1274881).
  • CVE-2026-68121: pppoe: reload header pointer after dev_hard_header() (bsc#1274888).
  • CVE-2026-68123: net: openvswitch: don't call pad_packet if not necessary (bsc#1275169).
  • CVE-2026-68129: gve: fix Rx queue stall on alloc failure (bsc#1275517).
  • CVE-2026-68141: net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() (bsc#1275094).
  • CVE-2026-68143: net: slip: serialize receive against buffer reallocation (bsc#1275583).
  • CVE-2026-68153: libceph: remove debugfs files before client teardown (bsc#1275301).
  • CVE-2026-68154: libceph: reject zero bucket types in crush_decode (bsc#1275303).
  • CVE-2026-68155: libceph: Reject monmaps advertising zero monitors (bsc#1275304).
  • CVE-2026-68156: libceph: refresh auth->authorizer_buf{,_len} after authorizer update (bsc#1275305).
  • CVE-2026-68158: libceph: Fix multiplication overflow in decode_new_up_state_weight() (bsc#1275307).
  • CVE-2026-68159: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE (bsc#1275470).
  • CVE-2026-68188: Bluetooth: RFCOMM: Fix session UAF in set_termios (bsc#1274953).
  • CVE-2026-68197: wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper (bsc#1274804).
  • CVE-2026-68198: wifi: ath6kl: fix use-after-free in aggr_reset_state() (bsc#1274803).
  • CVE-2026-68202: ALSA: seq: close a re-opened queue timer in the destructor (bsc#1275161).
  • CVE-2026-68234: drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved (bsc#1275650).
  • CVE-2026-68238: drm/amdgpu: Release VFCT ACPI table reference (bsc#1275704).
  • CVE-2026-68277: drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers (bsc#1275125).
  • CVE-2026-68278: drm/dp/mst: fix buffer overflows in sideband chunk accumulation (bsc#1275870).
  • CVE-2026-68279: drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers (bsc#1275871).
  • CVE-2026-68284: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() (bsc#1275970).
  • CVE-2026-68289: tipc: keep the skb in rcv queue until the whole data is read (bsc#1275976).
  • CVE-2026-68299: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets (bsc#1275088).
  • CVE-2026-68300: sctp: auth: verify auth requirement when auth_chunk is NULL (bsc#1275083).
  • CVE-2026-68313: tipc: fix infinite loop in __tipc_nl_compat_dumpit (bsc#1274665).
  • CVE-2026-68315: sctp: validate stream count in sctp_process_strreset_inreq() (bsc#1274662).
  • CVE-2026-68320: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid (bsc#1274659).
  • CVE-2026-68325: iommu/amd: Bound the early ACPI HID map (bsc#1274651).
  • CVE-2026-68328: nfp: Check resource mutex allocation (bsc#1274646).
  • CVE-2026-68329: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() (bsc#1274645).
  • CVE-2026-68338: net/packet: avoid fanout hook re-registration after unregister (bsc#1274637).
  • CVE-2026-68349: wifi: carl9170: fix buffer overflow in rx_stream failover path (bsc#1274681).
  • CVE-2026-68351: wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read (bsc#1274678).
  • CVE-2026-68357: watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() (bsc#1274737).
  • CVE-2026-68363: wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request (bsc#1275164).
  • CVE-2026-68397: net/iucv: take a reference on the socket found in afiucv_hs_rcv() (bsc#1274898).
  • CVE-2026-68398: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF (bsc#1274908).
  • CVE-2026-68405: wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock (bsc#1274896).
  • CVE-2026-68410: wifi: libertas: fix memory leak in helper_firmware_cb() (bsc#1274710).
  • CVE-2026-68425: IB/mad: Drop unmatched RMPP responses before reassembly (bsc#1274700).
  • CVE-2026-68426: esp: remove the skb from the chain when it's enqueued in cryptd_wq (bsc#1274705).
  • CVE-2026-68428: KVM: x86/mmu: Fix use-after-free on vendor module reload (bsc#1274699).
  • CVE-2026-68432: vxlan: require CAP_NET_ADMIN in the device netns for changelink (bsc#1274800).
  • CVE-2026-68433: libceph: bound get_version reply decode to front len (bsc#1274801).
  • CVE-2026-68450: btrfs: free mapping node on duplicate reloc root insert (bsc#1274834).
  • CVE-2026-68480: x86/bugs: Make Safe-RET robust against interrupt injection (bsc#1274208).
  • CVE-2026-72017: net: macb: drop in-flight Tx SKBs on close (bsc#1276840).
  • CVE-2026-72020: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new (bsc#1275506).
  • CVE-2026-72036: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked (bsc#1277034).
  • CVE-2026-72083: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE (bsc#1275535).
  • CVE-2026-72084: scsi: target: Write NULL to *port_nexus_ptr if no ISID (bsc#1275540).
  • CVE-2026-72086: scsi: xen: scsiback: Free unsubmitted command instead of double-putting it (bsc#1277179).
  • CVE-2026-72108: dm thin metadata: fix metadata snapshot consistency on commit failure (bsc#1277350).
  • CVE-2026-72135: tpm: Make the TPM character devices non-seekable (bsc#1277571).
  • CVE-2026-72138: xen/gntdev: fix error handling in ioctl (bsc#1277235).
  • CVE-2026-72142: i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) (bsc#1277522).
  • CVE-2026-72164: ocfs2: avoid moving extents to occupied clusters (bsc#1277553).
  • CVE-2026-72251: netfilter: nf_nat_sip: reload possible stale data pointer (bsc#1275827).
  • CVE-2026-72282: KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers (bsc#1277728).
  • CVE-2026-72284: KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs (bsc#1277730).
  • CVE-2026-72296: net: ife: require ETH_HLEN to be pullable in ife_decode() (bsc#1275923).
  • CVE-2026-72297: net: atm: reject out-of-range traffic classes in QoS validation (bsc#1277738).
  • CVE-2026-72323: ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() (bsc#1275985).
  • CVE-2026-72339: qede: fix off-by-one in BD ring consumption on build_skb failure (bsc#1276006).
  • CVE-2026-72389: bridge: stp: Fix a potential use-after-free when deleting a bridge (bsc#1273869).
  • CVE-2026-72421: ipv4: fib: Don't ignore error route in local/main tables (bsc#1277023).
  • CVE-2026-72450: xfrm: validate selector family and prefixlen during match (bsc#1278113).
  • CVE-2026-72466: xprtrdma: Fix bcall rep leak and unbounded peek (bsc#1277057).
  • CVE-2026-72487: PCI: Introduce named defines for PCI ROM (bsc#1276767).
  • CVE-2026-72502: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) (bsc#1276542).
  • CVE-2026-74255: tipc: fix UAF in tipc_l2_send_msg() (bsc#1276547).
  • CVE-2026-74261: ALSA: seq: avoid stale FIFO cells during resize (bsc#1276528).
  • CVE-2026-74265: net: mana: initialize gdma queue id to INVALID_QUEUE_ID (bsc#1276517).
  • CVE-2026-74271: power: supply: core: Delete two error messages for a failed memory allocation in power_supply_check_supplies() (bsc#1276502).
  • CVE-2026-74278: ALSA: seq: Fix kernel heap address leak in bounce_error_event() (bsc#1278132).
  • CVE-2026-74279: crypto: cavium/cpt - fix DMA cleanup using wrong loop index (bsc#1276479).
  • CVE-2026-74296: RDMA/mlx5: Release the HW-provided UAR index rather than the SW one (bsc#1276452).
  • CVE-2026-74297: RDMA/mlx5: Fix undefined shift of user RQ WQE size (bsc#1276446).
  • CVE-2026-74302: Bluetooth: hci_core: Fix UAF in hci_unregister_dev() (bsc#1276445).
  • CVE-2026-74334: RDMA/nldev: Fix locking when accessing mr->pd (bsc#1277095).
  • CVE-2026-74341: wifi: wcn36xx: fix heap overflow from oversized firmware HAL response (bsc#1277089).
  • CVE-2026-74377: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path (bsc#1278236).
  • CVE-2026-74378: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe (bsc#1278233).
  • CVE-2026-74382: net/sched: cls_bpf: prevent unbounded recursion in offload rollback (bsc#1278240).
  • CVE-2026-74388: ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data (bsc#1278253).
  • CVE-2026-74406: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive() (bsc#1276395).
  • CVE-2026-74416: drm/radeon: fix memory leak in radeon_ring_restore() on lock failure (bsc#1276343).
  • CVE-2026-74417: drm/radeon: fix integer overflow in radeon_align_pitch() (bsc#1276363).
  • CVE-2026-74454: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO (bsc#1277073).
  • CVE-2026-74479: net: pktgen: fix proc entry use-after-free (bsc#1276354).
  • CVE-2026-74482: mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios (bsc#1276346).
  • CVE-2026-74488: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames (bsc#1276350).
  • CVE-2026-74495: igbvf: Fix leak in TX DMA error cleanup (bsc#1275864).
  • CVE-2026-74496: fou: Fix use-after-free in fou_create() (bsc#1275867).
  • CVE-2026-74508: Bluetooth: HIDP: reject frames without a transaction header (bsc#1277893).
  • CVE-2026-74510: Bluetooth: mgmt: fix UAF in pair command cancellation (bsc#1275950).
  • CVE-2026-74519: pinctrl: devicetree: don't free uninitialized dev_name on error path (bsc#1275810).
  • CVE-2026-74537: Bluetooth: ISO: hold sk properly in iso_conn_ready (bsc#1275687).
  • CVE-2026-74548: forcedeth: fix UAF of txrx_stats in nv_remove (bsc#1275695).
  • CVE-2026-74550: net: do not send ICMP/NDISC Redirects when peer allocation fails (bsc#1275688).
  • CVE-2026-74556: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer (bsc#1275696).
  • CVE-2026-74557: scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer (bsc#1275685).
  • CVE-2026-74582: af_packet: fix raw sockets over 6in4 tunnel (bsc#1275784).
  • CVE-2026-74584: RDMA/bnxt_re: zero shared page before exposing to userspace (bsc#1277066).
  • CVE-2026-74669: ipvs: clear IPv4 options after rebasing tunnel ICMP errors (bsc#1277391).
  • CVE-2026-74673: Input: evdev - fix information leak in evdev_pass_values() (bsc#1277637).
  • CVE-2026-74705: udp: fix potential use-after-free in tunnel segmentation (bsc#1276922).
  • CVE-2026-74743: macvlan: inherit needed_headroom and needed_tailroom from lowerdev (bsc#1277908).
  • CVE-2026-80534: xfs: fix ilock leak on error in xfs_dq_get_next_id (bsc#1277022).
  • CVE-2026-80574: Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet (bsc#1277329).
  • CVE-2026-80580: fbdev: bound mode sysfs output to the sysfs buffer (bsc#1278294).
  • CVE-2026-80590: inet: frags: strip GSO state from fragments before reassembly (bsc#1277275).
  • CVE-2026-80603: netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read (bsc#1278293).
  • CVE-2026-80609: qede: fix out-of-bounds check for cqe->len_list (bsc#1278334).
  • CVE-2026-80714: ipvs: do not propagate one-packet flag to synced conns (bsc#1277561).
  • CVE-2026-80737: serial: amba-pl011: synchronize DMA teardown (bsc#1279487).
  • CVE-2026-80765: HID: hyperv: validate initial device info bounds (bsc#1279499).
  • CVE-2026-80819: Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept (bsc#1279607).
  • CVE-2026-80909: drm/amdgpu: Reject UVD message with invalid number of h265 refs (bsc#1279422).

The following non security issues were fixed:

  • fcntl: Fix potential deadlock in send_sig{io, urg}() (bsc#1269113).
  • mkspec-dtb: Move DTS prefix into package list.
  • mkspec-dtb: Move provides-obsoletes to package list.
  • mkspec-dtb: Put per-architecture package lists into a hash.
  • mkspec-dtb: re-indent.
  • net: tap: set skb->dev before parsing virtio net header in tap_get_user_xdp() (git-fixes bsc#1274550).
  • RDMA/mlx5: Fix integer overflow of user QP buffer size (git-fixes).
  • s390/barrier: Make array_index_mask_nospec() __always_inline (bsc#1270264).
  • s390/syscalls: Add spectre boundary for syscall dispatch table (bsc#1270264).
  • smb/client: handle overlapping allocated ranges in fallocate (bsc#1274902).
  • smb: client: harden POSIX SID length parsing (bsc#1273557).

Список пакетов

Image SLES12-SP5-GCE-BYOS
kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS
cluster-md-kmp-default-4.12.14-122.328.1
dlm-kmp-default-4.12.14-122.328.1
gfs2-kmp-default-4.12.14-122.328.1
kernel-default-4.12.14-122.328.1
ocfs2-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-On-Demand
cluster-md-kmp-default-4.12.14-122.328.1
dlm-kmp-default-4.12.14-122.328.1
gfs2-kmp-default-4.12.14-122.328.1
kernel-default-4.12.14-122.328.1
ocfs2-kmp-default-4.12.14-122.328.1
SUSE Linux Enterprise Live Patching 12 SP5
kernel-default-kgraft-4.12.14-122.328.1
kernel-default-kgraft-devel-4.12.14-122.328.1
kgraft-patch-4_12_14-122_328-default-1-8.5.1
SUSE Linux Enterprise Server 12 SP5-LTSS
cluster-md-kmp-default-4.12.14-122.328.1
dlm-kmp-default-4.12.14-122.328.1
gfs2-kmp-default-4.12.14-122.328.1
kernel-default-4.12.14-122.328.1
kernel-default-base-4.12.14-122.328.1
kernel-default-devel-4.12.14-122.328.1
kernel-default-man-4.12.14-122.328.1
kernel-devel-4.12.14-122.328.1
kernel-macros-4.12.14-122.328.1
kernel-source-4.12.14-122.328.1
kernel-syms-4.12.14-122.328.1
ocfs2-kmp-default-4.12.14-122.328.1
SUSE Linux Enterprise Server LTSS Extended Security 12 SP5
cluster-md-kmp-default-4.12.14-122.328.1
dlm-kmp-default-4.12.14-122.328.1
gfs2-kmp-default-4.12.14-122.328.1
kernel-default-4.12.14-122.328.1
kernel-default-base-4.12.14-122.328.1
kernel-default-devel-4.12.14-122.328.1
kernel-devel-4.12.14-122.328.1
kernel-macros-4.12.14-122.328.1
kernel-source-4.12.14-122.328.1
kernel-syms-4.12.14-122.328.1
ocfs2-kmp-default-4.12.14-122.328.1

Описание

In the Linux kernel, the following vulnerability has been resolved: geneve: fix header validation in geneve[6]_xmit_skb syzbot is able to trigger an uninit-value in geneve_xmit() [1] Problem : While most ip tunnel helpers (like ip_tunnel_get_dsfield()) uses skb_protocol(skb, true), pskb_inet_may_pull() is only using skb->protocol. If anything else than ETH_P_IPV6 or ETH_P_IP is found in skb->protocol, pskb_inet_may_pull() does nothing at all. If a vlan tag was provided by the caller (af_packet in the syzbot case), the network header might not point to the correct location, and skb linear part could be smaller than expected. Add skb_vlan_inet_prepare() to perform a complete mac validation. Use this in geneve for the moment, I suspect we need to adopt this more broadly. v4 - Jakub reported v3 broke l2_tos_ttl_inherit.sh selftest - Only call __vlan_get_protocol() for vlan types. v2,v3 - Addressed Sabrina comments on v1 and v2 [1] BUG: KMSAN: uninit-value in geneve_xmit_skb drivers/net/geneve.c:910 [inline] BUG: KMSAN: uninit-value in geneve_xmit+0x302d/0x5420 drivers/net/geneve.c:1030 geneve_xmit_skb drivers/net/geneve.c:910 [inline] geneve_xmit+0x302d/0x5420 drivers/net/geneve.c:1030 __netdev_start_xmit include/linux/netdevice.h:4903 [inline] netdev_start_xmit include/linux/netdevice.h:4917 [inline] xmit_one net/core/dev.c:3531 [inline] dev_hard_start_xmit+0x247/0xa20 net/core/dev.c:3547 __dev_queue_xmit+0x348d/0x52c0 net/core/dev.c:4335 dev_queue_xmit include/linux/netdevice.h:3091 [inline] packet_xmit+0x9c/0x6c0 net/packet/af_packet.c:276 packet_snd net/packet/af_packet.c:3081 [inline] packet_sendmsg+0x8bb0/0x9ef0 net/packet/af_packet.c:3113 sock_sendmsg_nosec net/socket.c:730 [inline] __sock_sendmsg+0x30f/0x380 net/socket.c:745 __sys_sendto+0x685/0x830 net/socket.c:2191 __do_sys_sendto net/socket.c:2203 [inline] __se_sys_sendto net/socket.c:2199 [inline] __x64_sys_sendto+0x125/0x1d0 net/socket.c:2199 do_syscall_64+0xd5/0x1f0 entry_SYSCALL_64_after_hwframe+0x6d/0x75 Uninit was created at: slab_post_alloc_hook mm/slub.c:3804 [inline] slab_alloc_node mm/slub.c:3845 [inline] kmem_cache_alloc_node+0x613/0xc50 mm/slub.c:3888 kmalloc_reserve+0x13d/0x4a0 net/core/skbuff.c:577 __alloc_skb+0x35b/0x7a0 net/core/skbuff.c:668 alloc_skb include/linux/skbuff.h:1318 [inline] alloc_skb_with_frags+0xc8/0xbf0 net/core/skbuff.c:6504 sock_alloc_send_pskb+0xa81/0xbf0 net/core/sock.c:2795 packet_alloc_skb net/packet/af_packet.c:2930 [inline] packet_snd net/packet/af_packet.c:3024 [inline] packet_sendmsg+0x722d/0x9ef0 net/packet/af_packet.c:3113 sock_sendmsg_nosec net/socket.c:730 [inline] __sock_sendmsg+0x30f/0x380 net/socket.c:745 __sys_sendto+0x685/0x830 net/socket.c:2191 __do_sys_sendto net/socket.c:2203 [inline] __se_sys_sendto net/socket.c:2199 [inline] __x64_sys_sendto+0x125/0x1d0 net/socket.c:2199 do_syscall_64+0xd5/0x1f0 entry_SYSCALL_64_after_hwframe+0x6d/0x75 CPU: 0 PID: 5033 Comm: syz-executor346 Not tainted 6.9.0-rc1-syzkaller-00005-g928a87efa423 #0 Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 02/29/2024


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal socket state. Disallow this by adding a new ctx->write field that indiciates exclusive ownership for writing.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Fix incorrect boolean values in af_alg_ctx Commit 1b34cbbf4f01 ("crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg") changed some fields from bool to 1-bit bitfields of type u32. However, some assignments to these fields, specifically 'more' and 'merge', assign values greater than 1. These relied on C's implicit conversion to bool, such that zero becomes false and nonzero becomes true. With a 1-bit bitfields of type u32 instead, mod 2 of the value is taken instead, resulting in 0 being assigned in some cases when 1 was intended. Fix this by restoring the bool type.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/vmwgfx: Validate command header size against SVGA_CMD_MAX_DATASIZE This data originates from userspace and is used in buffer offset calculations which could potentially overflow causing an out-of-bounds access.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: timers: Fix NULL function pointer race in timer_shutdown_sync() There is a race condition between timer_shutdown_sync() and timer expiration that can lead to hitting a WARN_ON in expire_timers(). The issue occurs when timer_shutdown_sync() clears the timer function to NULL while the timer is still running on another CPU. The race scenario looks like this: CPU0 CPU1 <SOFTIRQ> lock_timer_base() expire_timers() base->running_timer = timer; unlock_timer_base() [call_timer_fn enter] mod_timer() ... timer_shutdown_sync() lock_timer_base() // For now, will not detach the timer but only clear its function to NULL if (base->running_timer != timer) ret = detach_if_pending(timer, base, true); if (shutdown) timer->function = NULL; unlock_timer_base() [call_timer_fn exit] lock_timer_base() base->running_timer = NULL; unlock_timer_base() ... // Now timer is pending while its function set to NULL. // next timer trigger <SOFTIRQ> expire_timers() WARN_ON_ONCE(!fn) // hit ... lock_timer_base() // Now timer will detach if (base->running_timer != timer) ret = detach_if_pending(timer, base, true); if (shutdown) timer->function = NULL; unlock_timer_base() The problem is that timer_shutdown_sync() clears the timer function regardless of whether the timer is currently running. This can leave a pending timer with a NULL function pointer, which triggers the WARN_ON_ONCE(!fn) check in expire_timers(). Fix this by only clearing the timer function when actually detaching the timer. If the timer is running, leave the function pointer intact, which is safe because the timer will be properly detached when it finishes running.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: use skb_vlan_inet_prepare() in __ip6_tnl_rcv() Blamed commit did not take care of VLAN encapsulations as spotted by syzbot [1]. Use skb_vlan_inet_prepare() instead of pskb_inet_may_pull(). [1] BUG: KMSAN: uninit-value in __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline] BUG: KMSAN: uninit-value in INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline] BUG: KMSAN: uninit-value in IP6_ECN_decapsulate+0x7a8/0x1fa0 include/net/inet_ecn.h:321 __INET_ECN_decapsulate include/net/inet_ecn.h:253 [inline] INET_ECN_decapsulate include/net/inet_ecn.h:275 [inline] IP6_ECN_decapsulate+0x7a8/0x1fa0 include/net/inet_ecn.h:321 ip6ip6_dscp_ecn_decapsulate+0x16f/0x1b0 net/ipv6/ip6_tunnel.c:729 __ip6_tnl_rcv+0xed9/0x1b50 net/ipv6/ip6_tunnel.c:860 ip6_tnl_rcv+0xc3/0x100 net/ipv6/ip6_tunnel.c:903 gre_rcv+0x1529/0x1b90 net/ipv6/ip6_gre.c:-1 ip6_protocol_deliver_rcu+0x1c89/0x2c60 net/ipv6/ip6_input.c:438 ip6_input_finish+0x1f4/0x4a0 net/ipv6/ip6_input.c:489 NF_HOOK include/linux/netfilter.h:318 [inline] ip6_input+0x9c/0x330 net/ipv6/ip6_input.c:500 ip6_mc_input+0x7ca/0xc10 net/ipv6/ip6_input.c:590 dst_input include/net/dst.h:474 [inline] ip6_rcv_finish+0x958/0x990 net/ipv6/ip6_input.c:79 NF_HOOK include/linux/netfilter.h:318 [inline] ipv6_rcv+0xf1/0x3c0 net/ipv6/ip6_input.c:311 __netif_receive_skb_one_core net/core/dev.c:6139 [inline] __netif_receive_skb+0x1df/0xac0 net/core/dev.c:6252 netif_receive_skb_internal net/core/dev.c:6338 [inline] netif_receive_skb+0x57/0x630 net/core/dev.c:6397 tun_rx_batched+0x1df/0x980 drivers/net/tun.c:1485 tun_get_user+0x5c0e/0x6c60 drivers/net/tun.c:1953 tun_chr_write_iter+0x3e9/0x5c0 drivers/net/tun.c:1999 new_sync_write fs/read_write.c:593 [inline] vfs_write+0xbe2/0x15d0 fs/read_write.c:686 ksys_write fs/read_write.c:738 [inline] __do_sys_write fs/read_write.c:749 [inline] __se_sys_write fs/read_write.c:746 [inline] __x64_sys_write+0x1fb/0x4d0 fs/read_write.c:746 x64_sys_call+0x30ab/0x3e70 arch/x86/include/generated/asm/syscalls_64.h:2 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xd3/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f Uninit was created at: slab_post_alloc_hook mm/slub.c:4960 [inline] slab_alloc_node mm/slub.c:5263 [inline] kmem_cache_alloc_node_noprof+0x9e7/0x17a0 mm/slub.c:5315 kmalloc_reserve+0x13c/0x4b0 net/core/skbuff.c:586 __alloc_skb+0x805/0x1040 net/core/skbuff.c:690 alloc_skb include/linux/skbuff.h:1383 [inline] alloc_skb_with_frags+0xc5/0xa60 net/core/skbuff.c:6712 sock_alloc_send_pskb+0xacc/0xc60 net/core/sock.c:2995 tun_alloc_skb drivers/net/tun.c:1461 [inline] tun_get_user+0x1142/0x6c60 drivers/net/tun.c:1794 tun_chr_write_iter+0x3e9/0x5c0 drivers/net/tun.c:1999 new_sync_write fs/read_write.c:593 [inline] vfs_write+0xbe2/0x15d0 fs/read_write.c:686 ksys_write fs/read_write.c:738 [inline] __do_sys_write fs/read_write.c:749 [inline] __se_sys_write fs/read_write.c:746 [inline] __x64_sys_write+0x1fb/0x4d0 fs/read_write.c:746 x64_sys_call+0x30ab/0x3e70 arch/x86/include/generated/asm/syscalls_64.h:2 do_syscall_x64 arch/x86/entry/syscall_64.c:63 [inline] do_syscall_64+0xd3/0xf80 arch/x86/entry/syscall_64.c:94 entry_SYSCALL_64_after_hwframe+0x77/0x7f CPU: 0 UID: 0 PID: 6465 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(none) Hardware name: Google Google Compute Engine/Google Compute Engine, BIOS Google 10/25/2025


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ACPI: processor: Fix previous acpi_processor_errata_piix4() fix After commi f132e089fe89 ("ACPI: processor: Fix NULL-pointer dereference in acpi_processor_errata_piix4()"), device pointers may be dereferenced after dropping references to the device objects pointed to by them, which may cause a use-after-free to occur. Moreover, debug messages about enabling the errata may be printed if the errata flags corresponding to them are unset. Address all of these issues by moving message printing to the points in the code where the errata flags are set.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: s390/syscalls: Add spectre boundary for syscall dispatch table The s390 syscall number is directly controlled by userspace, but does not have an array_index_nospec() boundary to prevent access past the syscall function pointer tables.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: ctnetlink: ensure safe access to master conntrack Holding reference on the expectation is not sufficient, the master conntrack object can just go away, making exp->master invalid. To access exp->master safely: - Grab the nf_conntrack_expect_lock, this gets serialized with clean_from_lists() which also holds this lock when the master conntrack goes away. - Hold reference on master conntrack via nf_conntrack_find_get(). Not so easy since the master tuple to look up for the master conntrack is not available in the existing problematic paths. This patch goes for extending the nf_conntrack_expect_lock section to address this issue for simplicity, in the cases that are described below this is just slightly extending the lock section. The add expectation command already holds a reference to the master conntrack from ctnetlink_create_expect(). However, the delete expectation command needs to grab the spinlock before looking up for the expectation. Expand the existing spinlock section to address this to cover the expectation lookup. Note that, the nf_ct_expect_iterate_net() calls already grabs the spinlock while iterating over the expectation table, which is correct. The get expectation command needs to grab the spinlock to ensure master conntrack does not go away. This also expands the existing spinlock section to cover the expectation lookup too. I needed to move the netlink skb allocation out of the spinlock to keep it GFP_KERNEL. For the expectation events, the IPEXP_DESTROY event is already delivered under the spinlock, just move the delivery of IPEXP_NEW under the spinlock too because the master conntrack event cache is reached through exp->master. While at it, add lockdep notations to help identify what codepaths need to grab the spinlock.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: dlm: validate length in dlm_search_rsb_tree The len parameter in dlm_dump_rsb_name() is not validated and comes from network messages. When it exceeds DLM_RESNAME_MAXLEN, it can cause out-of-bounds write in dlm_search_rsb_tree(). Add length validation to prevent potential buffer overflow.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: L2CAP: Fix missing key size check for L2CAP_LE_CONN_REQ This adds a check for encryption key size upon receiving L2CAP_LE_CONN_REQ which is required by L2CAP/LE/CFC/BV-15-C which expects L2CAP_CR_LE_BAD_KEY_SIZE.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: media: cx88: Add missing unmap in snd_cx88_hw_params() In error path, add cx88_alsa_dma_unmap() to release resource acquired by cx88_alsa_dma_map().


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: APEI/GHES: ensure that won't go past CPER allocated record The logic at ghes_new() prevents allocating too large records, by checking if they're bigger than GHES_ESTATUS_MAX_SIZE (currently, 64KB). Yet, the allocation is done with the actual number of pages from the CPER bios table location, which can be smaller. Yet, a bad firmware could send data with a different size, which might be bigger than the allocated memory, causing an OOPS: Unable to handle kernel paging request at virtual address fff00000f9b40000 Mem abort info: ESR = 0x0000000096000007 EC = 0x25: DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x07: level 3 translation fault Data abort info: ISV = 0, ISS = 0x00000007, ISS2 = 0x00000000 CM = 0, WnR = 0, TnD = 0, TagAccess = 0 GCS = 0, Overlay = 0, DirtyBit = 0, Xs = 0 swapper pgtable: 4k pages, 52-bit VAs, pgdp=000000008ba16000 [fff00000f9b40000] pgd=180000013ffff403, p4d=180000013fffe403, pud=180000013f85b403, pmd=180000013f68d403, pte=0000000000000000 Internal error: Oops: 0000000096000007 [#1] SMP Modules linked in: CPU: 0 UID: 0 PID: 303 Comm: kworker/0:1 Not tainted 6.19.0-rc1-00002-gda407d200220 #34 PREEMPT Hardware name: QEMU QEMU Virtual Machine, BIOS unknown 02/02/2022 Workqueue: kacpi_notify acpi_os_execute_deferred pstate: 214020c5 (nzCv daIF +PAN -UAO -TCO +DIT -SSBS BTYPE=--) pc : hex_dump_to_buffer+0x30c/0x4a0 lr : hex_dump_to_buffer+0x328/0x4a0 sp : ffff800080e13880 x29: ffff800080e13880 x28: ffffac9aba86f6a8 x27: 0000000000000083 x26: fff00000f9b3fffc x25: 0000000000000004 x24: 0000000000000004 x23: ffff800080e13905 x22: 0000000000000010 x21: 0000000000000083 x20: 0000000000000001 x19: 0000000000000008 x18: 0000000000000010 x17: 0000000000000001 x16: 00000007c7f20fec x15: 0000000000000020 x14: 0000000000000008 x13: 0000000000081020 x12: 0000000000000008 x11: ffff800080e13905 x10: ffff800080e13988 x9 : 0000000000000000 x8 : 0000000000000000 x7 : 0000000000000001 x6 : 0000000000000020 x5 : 0000000000000030 x4 : 00000000fffffffe x3 : 0000000000000000 x2 : ffffac9aba78c1c8 x1 : ffffac9aba76d0a8 x0 : 0000000000000008 Call trace: hex_dump_to_buffer+0x30c/0x4a0 (P) print_hex_dump+0xac/0x170 cper_estatus_print_section+0x90c/0x968 cper_estatus_print+0xf0/0x158 __ghes_print_estatus+0xa0/0x148 ghes_proc+0x1bc/0x220 ghes_notify_hed+0x5c/0xb8 notifier_call_chain+0x78/0x148 blocking_notifier_call_chain+0x4c/0x80 acpi_hed_notify+0x28/0x40 acpi_ev_notify_dispatch+0x50/0x80 acpi_os_execute_deferred+0x24/0x48 process_one_work+0x15c/0x3b0 worker_thread+0x2d0/0x400 kthread+0x148/0x228 ret_from_fork+0x10/0x20 Code: 6b14033f 540001ad a94707e2 f100029f (b8747b44) ---[ end trace 0000000000000000 ]--- Prevent that by taking the actual allocated are into account when checking for CPER length. [ rjw: Subject tweaks ]


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: x86/apic: Disable x2apic on resume if the kernel expects so When resuming from s2ram, firmware may re-enable x2apic mode, which may have been disabled by the kernel during boot either because it doesn't support IRQ remapping or for other reasons. This causes the kernel to continue using the xapic interface, while the hardware is in x2apic mode, which causes hangs. This happens on defconfig + bare metal + s2ram. Fix this in lapic_resume() by disabling x2apic if the kernel expects it to be disabled, i.e. when x2apic_mode = 0. The ACPI v6.6 spec, Section 16.3 [1] says firmware restores either the pre-sleep configuration or initial boot configuration for each CPU, including MSR state: When executing from the power-on reset vector as a result of waking from an S2 or S3 sleep state, the platform firmware performs only the hardware initialization required to restore the system to either the state the platform was in prior to the initial operating system boot, or to the pre-sleep configuration state. In multiprocessor systems, non-boot processors should be placed in the same state as prior to the initial operating system boot. (further ahead) If this is an S2 or S3 wake, then the platform runtime firmware restores minimum context of the system before jumping to the waking vector. This includes: CPU configuration. Platform runtime firmware restores the pre-sleep configuration or initial boot configuration of each CPU (MSR, MTRR, firmware update, SMBase, and so on). Interrupts must be disabled (for IA-32 processors, disabled by CLI instruction). (and other things) So at least as per the spec, re-enablement of x2apic by the firmware is allowed if "x2apic on" is a part of the initial boot configuration. [1] https://uefi.org/specs/ACPI/6.6/16_Waking_and_Sleeping.html#initialization [ bp: Massage. ]


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: powerpc, perf: Check that current->mm is alive before getting user callchain It may happen that mm is already released, which leads to kernel panic. This adds the NULL check for current->mm, similarly to commit 20afc60f892d ("x86, perf: Check that current->mm is alive before getting user callchain"). I was getting this panic when running a profiling BPF program (profile.py from bcc-tools): [26215.051935] Kernel attempted to read user page (588) - exploit attempt? (uid: 0) [26215.051950] BUG: Kernel NULL pointer dereference on read at 0x00000588 [26215.051952] Faulting instruction address: 0xc00000000020fac0 [26215.051957] Oops: Kernel access of bad area, sig: 11 [#1] [...] [26215.052049] Call Trace: [26215.052050] [c000000061da6d30] [c00000000020fc10] perf_callchain_user_64+0x2d0/0x490 (unreliable) [26215.052054] [c000000061da6dc0] [c00000000020f92c] perf_callchain_user+0x1c/0x30 [26215.052057] [c000000061da6de0] [c0000000005ab2a0] get_perf_callchain+0x100/0x360 [26215.052063] [c000000061da6e70] [c000000000573bc8] bpf_get_stackid+0x88/0xf0 [26215.052067] [c000000061da6ea0] [c008000000042258] bpf_prog_16d4ab9ab662f669_do_perf_event+0xf8/0x274 [...] In addition, move storing the top-level stack entry to generic perf_callchain_user to make sure the top-evel entry is always captured, even if current->mm is NULL. [Maddy: fixed message to avoid checkpatch format style error]


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: tpm: tpm_i2c_infineon: Fix locality leak on get_burstcount() failure get_burstcount() can return -EBUSY on timeout. When this happens, the function returns directly without releasing the locality that was acquired at the beginning of tpm_tis_i2c_send(). Use goto out_err to ensure proper cleanup when get_burstcount() fails.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: md/raid5: validate payload size before accessing journal metadata r5c_recovery_analyze_meta_block() and r5l_recovery_verify_data_checksum_for_mb() iterate over payloads in a journal metadata block using on-disk payload size fields without validating them against the remaining space in the metadata block. A corrupted journal contains payload sizes extending beyond the PAGE_SIZE boundary can cause out-of-bounds reads when accessing payload fields or computing offsets. Add bounds validation for each payload type to ensure the full payload fits within meta_size before processing.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: dm-thin: fix metadata refcount underflow There's a bug in dm-thin in the function rebalance_children. If the internal btree node has one entry, the code tries to copy all btree entries from the node's child to the node itself and then decrement the child's reference count. If the child node is shared (it has reference count > 1), we won't free it, so there would be two pointers to each of the grandchildren nodes. But the reference counts of the grandchildren is not increased, thus the reference count doesn't match the number of pointers that point to the grandchildren. This results in "device mapper: space map common: unable to decrement block" errors. Fix this bug by incrementing reference counts on the grandchildren if the btree node is shared.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipmi:si: Return state to normal if message allocation fails There were places where nothing would get started if a message allocation failed, so the driver needs to return to normal state.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipmi: Check event message buffer response for bad data The event message buffer response data size got checked later when processing, but check it right after the response comes back. It appears some BMCs may return an empty message instead of an error when fetching events. There are apparently some new BMCs that make this error, so we need to compensate.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_queue: hold bridge skb->dev while queued br_pass_frame_up() rewrites skb->dev from the ingress port to the bridge master before queueing bridge LOCAL_IN packets. NFQUEUE only holds references on state.in/out and bridge physdevs, so a queued bridge packet can retain a freed bridge master in skb->dev until reinjection. When the verdict is reinjected later, br_netif_receive_skb() re-enters the receive path with skb->dev still pointing at the freed bridge master, triggering a use-after-free. Store skb->dev in the queue entry, hold a reference on it for the queue lifetime, and use the saved device when dropping queued packets during NETDEV_DOWN handling.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: xt_policy: fix strict mode inbound policy matching match_policy_in() walks sec_path entries from the last transform to the first one, but strict policy matching needs to consume info->pol[] in the same forward order as the rule layout. Derive the strict-match policy position from the number of transforms already consumed so that multi-element inbound rules are matched consistently.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: vrf: Fix a potential NPD when removing a port from a VRF RCU readers that identified a net device as a VRF port using netif_is_l3_slave() assume that a subsequent call to netdev_master_upper_dev_get_rcu() will return a VRF device. They then continue to dereference its l3mdev operations. This assumption is not always correct and can result in a NPD [1]. There is no RCU synchronization when removing a port from a VRF, so it is possible for an RCU reader to see a new master device (e.g., a bridge) that does not have l3mdev operations. Fix by adding RCU synchronization after clearing the IFF_L3MDEV_SLAVE flag. Skip this synchronization when a net device is removed from a VRF as part of its deletion and when the VRF device itself is deleted. In the latter case an RCU grace period will pass by the time RTNL is released. [1] BUG: kernel NULL pointer dereference, address: 0000000000000000 [...] RIP: 0010:l3mdev_fib_table_rcu (net/l3mdev/l3mdev.c:181) [...] Call Trace: <TASK> l3mdev_fib_table_by_index (net/l3mdev/l3mdev.c:201 net/l3mdev/l3mdev.c:189) __inet_bind (net/ipv4/af_inet.c:499 (discriminator 3)) inet_bind_sk (net/ipv4/af_inet.c:469) __sys_bind (./include/linux/file.h:62 (discriminator 1) ./include/linux/file.h:83 (discriminator 1) net/socket.c:1951 (discriminator 1)) __x64_sys_bind (net/socket.c:1969 (discriminator 1) net/socket.c:1967 (discriminator 1) net/socket.c:1967 (discriminator 1)) do_syscall_64 (arch/x86/entry/syscall_64.c:63 (discriminator 1) arch/x86/entry/syscall_64.c:94 (discriminator 1)) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:130)


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/rds: fix NULL deref in rds_ib_send_cqe_handler() on masked atomic completion rds_ib_xmit_atomic() always programs a masked atomic opcode (IB_WR_MASKED_ATOMIC_CMP_AND_SWP or IB_WR_MASKED_ATOMIC_FETCH_AND_ADD) for every RDS atomic cmsg. But the completion-side switch in rds_ib_send_unmap_op() only handles the non-masked opcodes, so a masked atomic completion falls through to default and returns rm == NULL while send->s_op is left set. rds_ib_send_cqe_handler() then dereferences the NULL rm via rm->m_final_op, oopsing in softirq context. An unprivileged AF_RDS sendmsg() of an atomic cmsg over an active RDS/IB connection triggers it; on hardware that natively accepts masked atomics (mlx4, mlx5) no extra setup is needed. RDS/IB: rds_ib_send_unmap_op: unexpected opcode 0xd in WR! Oops: general protection fault [#1] SMP KASAN KASAN: null-ptr-deref in range [0x0000000000000190-0x0000000000000197] RIP: rds_ib_send_cqe_handler+0x25c/0xb10 (net/rds/ib_send.c:282) Call Trace: <IRQ> rds_ib_send_cqe_handler (net/rds/ib_send.c:282) poll_scq (net/rds/ib_cm.c:274) rds_ib_tasklet_fn_send (net/rds/ib_cm.c:294) tasklet_action_common (kernel/softirq.c:943) handle_softirqs (kernel/softirq.c:573) run_ksoftirqd (kernel/softirq.c:479) </IRQ> Kernel panic - not syncing: Fatal exception in interrupt Handle the masked atomic opcodes in the same case as the non-masked ones: they map to the same struct rds_message.atomic union member, so the existing container_of()/rds_ib_send_unmap_atomic() body is correct for them.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fs/fcntl: fix SOFTIRQ-unsafe lock order in fasync signaling A SOFTIRQ-safe to SOFTIRQ-unsafe lock order deadlock can occur in send_sigio() and send_sigurg() when a process group receives a signal. When FASYNC is configured for a process group (PIDTYPE_PGID), both functions use read_lock(&tasklist_lock) to traverse the task list. However, they are frequently called from softirq context: - send_sigio() via input_inject_event -> kill_fasync - send_sigurg() via tcp_check_urg -> sk_send_sigurg (NET_RX_SOFTIRQ) The deadlock is caused by the rwlock writer fairness mechanism: 1. CPU 0 (process context) holds read_lock(&tasklist_lock) in do_wait(). 2. CPU 1 (process context) attempts write_lock(&tasklist_lock) in fork() or exit() and spins, which blocks all new readers. 3. CPU 0 is interrupted by a softirq (e.g., TCP URG packet reception). 4. The softirq calls send_sigurg() and attempts to acquire read_lock(&tasklist_lock), deadlocking because CPU 1 is waiting. Since PID hashing and do_each_pid_task() traversals are already RCU-protected, the read_lock on tasklist_lock is no longer strictly required for safe traversal. Fix this by replacing tasklist_lock with rcu_read_lock(), aligning the process group signaling path with the single-PID path. This also mitigates a potential remote denial of service vector via TCP URG packets. Lockdep splat: ===================================================== WARNING: SOFTIRQ-safe -> SOFTIRQ-unsafe lock order detected [...] Chain exists of: &dev->event_lock --> &f_owner->lock --> tasklist_lock Possible interrupt unsafe locking scenario: CPU0 CPU1 ---- ---- lock(tasklist_lock); local_irq_disable(); lock(&dev->event_lock); lock(&f_owner->lock); <Interrupt> lock(&dev->event_lock); *** DEADLOCK ***


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: xtables: restrict several matches to inet family This is a partial revert of: commit ab4f21e6fb1c ("netfilter: xtables: use NFPROTO_UNSPEC in more extensions") to allow ipv4 and ipv6 only. - xt_mac - xt_owner - xt_physdev These extensions are not used by ebtables in userspace. Moreover, xt_realm is only for ipv4, since dst->tclassid is ipv4 specific.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: dm log: fix out-of-bounds write due to region_count overflow The local variable region_count in create_log_context() is declared as unsigned int (32-bit), but dm_sector_div_up() returns sector_t (64-bit). When a device-mapper target has a sufficiently large ti->len with a small region_size, the division result can exceed UINT_MAX. The truncated value is then used to calculate bitset_size, causing clean_bits, sync_bits, and recovering_bits to be allocated far smaller than needed for the actual number of regions. Subsequent log operations (log_set_bit, log_clear_bit, log_test_bit) use region indices derived from the full untruncated region space, causing out-of-bounds writes to kernel heap memory allocated by vmalloc. This can be reproduced by creating a mirror target whose region_count overflows 32 bits: dmsetup create bigzero --table '0 8589934594 zero' dmsetup create mymirror --table '0 8589934594 mirror \ core 2 2 nosync 2 /dev/mapper/bigzero 0 \ /dev/mapper/bigzero 0' The status output confirms the truncation (sync_count=1 instead of 4294967297, because 0x100000001 was truncated to 1): $ dmsetup status mymirror 0 8589934594 mirror 2 254:1 254:1 1/4294967297 ... This leads to a kernel crash in core_in_sync: BUG: scheduling while atomic: (udev-worker)/9150/0x00000000 RIP: 0010:core_in_sync+0x14/0x30 [dm_log] CR2: 0000000000000008 Fixing recursive fault but reboot is needed! Fix by widening the local region_count to sector_t and adding an explicit overflow check before the value is assigned to lc->region_count.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: dm cache: fix dirty mapping checking in passthrough mode switching As mentioned in commit 9b1cc9f251af ("dm cache: share cache-metadata object across inactive and active DM tables"), dm-cache assumed table reload occurs after suspension, while LVM's table preload breaks this assumption. The dirty mapping check for passthrough mode was designed around this assumption and is performed during table creation, causing the check to fail with preload while metadata updates are ongoing. This risks loading dirty mappings into passthrough mode, resulting in data loss. Reproduce steps: 1. Create a writeback cache with zero migration_threshold to produce dirty mappings dmsetup create cmeta --table "0 8192 linear /dev/sdc 0" dmsetup create cdata --table "0 131072 linear /dev/sdc 8192" dmsetup create corig --table "0 262144 linear /dev/sdc 262144" dd if=/dev/zero of=/dev/mapper/cmeta bs=4k count=1 oflag=direct dmsetup create cache --table "0 262144 cache /dev/mapper/cmeta \ /dev/mapper/cdata /dev/mapper/corig 128 2 metadata2 writeback smq \ 2 migration_threshold 0" 2. Preload a table in passthrough mode dmsetup reload cache --table "0 262144 cache /dev/mapper/cmeta \ /dev/mapper/cdata /dev/mapper/corig 128 2 metadata2 passthrough smq 0" 3. Write to the first cache block to make it dirty fio --filename=/dev/mapper/cache --name=populate --rw=write --bs=4k \ --direct=1 --size=64k 4. Resume the inactive table. Now it's possible to load the dirty block into passthrough mode. dmsetup resume cache Fix by moving the checks to the preresume phase to support table preloading. Also remove the unused function dm_cache_metadata_all_clean.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/rds: Restrict use of RDS/IB to the initial network namespace Prevent using RDS/IB in network namespaces other than the initial one. The existing RDS/IB code will not work properly in non-initial network namespaces.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: bpf: Fix use-after-free in offloaded map/prog info fill When querying info for an offloaded BPF map or program, bpf_map_offload_info_fill_ns() and bpf_prog_offload_info_fill_ns() obtain the network namespace with get_net(dev_net(offmap->netdev)). However, the associated netdev's netns may be racing with teardown during netns destruction. If the netns refcount has already reached 0, get_net() performs a refcount_t increment on 0, triggering: refcount_t: addition on 0; use-after-free. Although rtnl_lock and bpf_devs_lock ensure the netdev pointer remains valid, they cannot prevent the netns refcount from reaching zero. Fix this by using maybe_get_net() instead of get_net(). maybe_get_net() uses refcount_inc_not_zero() and returns NULL if the refcount is already zero, which causes ns_get_path_cb() to fail and the caller to return -ENOENT -- the correct behavior when the netns is being destroyed.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: pull headers in qdisc_pkt_len_segs_init() Most ndo_start_xmit() methods expects headers of gso packets to be already in skb->head. net/core/tso.c users are particularly at risk, because tso_build_hdr() does a memcpy(hdr, skb->data, hdr_len); qdisc_pkt_len_segs_init() already does a dissection of gso packets. Use pskb_may_pull() instead of skb_header_pointer() to make sure drivers do not have to reimplement this. Some malicious packets could be fed, detect them so that we can drop them sooner with a new SKB_DROP_REASON_SKB_BAD_GSO drop_reason.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: Bound root directory content to block size __tb_property_parse_dir() does not check that content_offset + content_len fits within block_len for the root directory case. When rootdir->length equals or exceeds block_len - 2, the entry loop reads past the allocated property block. Add a bounds check after computing content_offset and content_len to reject directories whose content extends past the block.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: locking/rtmutex: Skip remove_waiter() when waiter is not enqueued syzbot triggered the following splat in remove_waiter() via FUTEX_CMP_REQUEUE_PI: KASAN: null-ptr-deref in range [0x0000000000000a88-0x0000000000000a8f] class_raw_spinlock_constructor remove_waiter+0x159/0x1200 kernel/locking/rtmutex.c:1561 rt_mutex_start_proxy_lock+0x103/0x120 futex_requeue+0x10e4/0x20d0 __x64_sys_futex+0x34f/0x4d0 task_blocks_on_rt_mutex() does not arm the waiter upon deadlock detection, leaving waiter->task nil, where 3bfdc63936dd ("rtmutex: Use waiter::task instead of current in remove_waiter()") made this fatal. Furthermore, rt_mutex_start_proxy_lock() should not be calling into remove_waiter() upon a successfully grabbing the rtmutex. 1a1fb985f2e2 ("futex: Handle early deadlock return correctly"), moved the remove_waiter() out of __rt_mutex_start_proxy_lock() (where 'ret' was only ever 0 or < 0) into the wrapper. Tighten this check to account for try_to_take_rt_mutex().


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: x_tables: avoid leaking percpu counter pointers The native and compat get-entries paths copy the fixed rule entry header from the kernelized rule blob to userspace before overwriting the entry's counter fields with a sanitized counter snapshot. On SMP kernels, entry->counters.pcnt contains the percpu allocation address used by x_tables rule counters. A caller can provide a userspace buffer that faults during the initial fixed-header copy after pcnt has been copied but before the later sanitized counter copy runs. The syscall then returns -EFAULT while leaving the raw percpu pointer in userspace. Copy only the fixed entry prefix before counters from the kernelized rule blob, then copy the sanitized counter snapshot into the counter field. Apply this ordering to the IPv4, IPv6, and ARP native and compat get-entries implementations so a fault cannot expose the internal percpu counter pointer.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: revalidate bridge ports ebt_redirect_tg() dereferences br_port_get_rcu() return without a NULL check, causing a kernel panic when the bridge port has been removed between the original hook invocation and an NFQUEUE reinject. A mere NULL check isn't sufficient, however. As sashiko review points out userspace can not only remove the port from the bridge, it could also place the device in a different virtual device, e.g. macvlan. If this happens, we must drop the packet, there is no way for us to reinject it into the bridge path. Switch to _upper API, we don't need the bridge port structure. Also, this fix keeps another bug intact: Both nfnetlink_log and nfnetlink_queue use CONFIG_BRIDGE_NETFILTER too aggressive, which prevents certain logging features when queueing in bridge family: NETFILTER_FAMILY_BRIDGE can be enabled while the old CONFIG_BRIDGE_NETFILTER cruft is off. Fixes tag is a common ancestor, this was always broken.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: guard timestamp cmsgs to real error queue skbs skb_is_err_queue() treats PACKET_OUTGOING as the sole marker for an skb from sk_error_queue. That assumption is not true for AF_PACKET sockets: outgoing packet taps are also delivered to packet sockets with skb->pkt_type == PACKET_OUTGOING, but their skb->cb is owned by AF_PACKET instead of struct sock_exterr_skb. If such an skb is received with timestamping enabled, the generic timestamp cmsg path can read AF_PACKET control-buffer state as sock_exterr_skb::opt_stats. With SO_RXQ_OVFL enabled, the packet drop counter overlaps opt_stats. An odd drop count makes the path emit SCM_TIMESTAMPING_OPT_STATS with skb->len and skb->data. For non-linear skbs this copies past the linear head and can trigger hardened usercopy or disclose adjacent heap contents. Keep skb_is_err_queue() local to net/socket.c, but make it verify that the PACKET_OUTGOING marker is paired with the sock_rmem_free destructor installed by sock_queue_err_skb(). AF_PACKET receive skbs use normal receive ownership and no longer pass as error-queue skbs, while legitimate sk_error_queue entries keep the PACKET_OUTGOING marker and sock_rmem_free ownership.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv6: sit: reload inner IPv6 header after GSO offloads ipip6_tunnel_xmit() caches the inner IPv6 header pointer at function entry and continues using it after iptunnel_handle_offloads(). For GSO skbs, iptunnel_handle_offloads() calls skb_header_unclone(). When the skb header is cloned, skb_header_unclone() can call pskb_expand_head(), which may move the skb head. The pskb_expand_head() contract requires pointers into the skb header to be reloaded after the call. If the later skb_realloc_headroom() branch is not taken, SIT uses the stale iph6 pointer to read the inner hop limit and DS field. That can read from a freed skb head after the old head's remaining clone is released. Reload iph6 after the offload helper succeeds and before subsequent reads from the inner IPv6 header. Keep the existing reload after skb_realloc_headroom(), since that branch can also replace the skb.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netlabel: validate unlabeled address and mask attribute lengths netlbl_unlabel_addrinfo_get() used the address attribute length to determine whether the attribute data could be read as an IPv4 or IPv6 address, but did not independently validate the corresponding mask attribute length. A crafted Generic Netlink request could therefore provide a valid IPv4/IPv6 address attribute with a shorter mask attribute, which would later be read as a full struct in_addr or struct in6_addr. NLA_BINARY policy lengths are maximum lengths by default, so use NLA_POLICY_EXACT_LEN() for the unlabeled IPv4/IPv6 address and mask attributes. This rejects short attributes during policy validation and also exposes the exact length requirements through policy introspection.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/sched: act_api: use RCU with deferred freeing for action lifecycle When NEWTFILTER and DELFILTER are run concurrently it is possible to create a race with an associated action. Let's illustrate with CPU0 running NEWTFILTER and CPU1 running DELFILTER: 0: mutex_lock() <-- holds the idr lock 0: rcu_read_lock() 0: p = idr_find(idr, index) <-- action p is valid (RCU protects IDR) 0: mutex_unlock() <-- releases the idr lock 1: refcount_dec_and_mutex_lock() <-- refcnt 1->0, mutex held 1: idr_remove(idr, index) <-- Action removed from IDR 1: mutex_unlock() <-- mutex released allowing us to delete the action 1: tcf_action_cleanup(p); kfree(p) <-- Kfrees p immediately, no deferral 0: refcount_inc_not_zero(&p->tcfa_refcnt) <-- ouch, UAF p points to freed memory This patch fixes the race condition between NEWTFILTER and DELFILTER by adding struct rcu_head to tc_action used in the deferral and introducing a call_rcu() in the delete path to defer the final kfree(). Note: this is a revert of commit d7fb60b9cafb ("net_sched: get rid of tcfa_rcu") but also modernization/simplification to directly use kfree_rcu(). Let's illustrate the new restored code path: 0: rcu_read_lock() 1: refcount_dec_and_mutex_lock() <-- refcnt 1->0, mutex held 1: idr_remove(idr, index) 1: mutex_unlock() 1: call_rcu(&p->tcfa_rcu, tcf_action_rcu_free) <-- defer kfree after grace period 0: p = idr_find(idr, index) 0: refcount_inc_not_zero(&p->tcfa_refcnt) <-- fails, refcnt already 0 1: rcu_read_unlock() <-- release so freeing can run after grace period After CPU1 calls idr_remove(), the object is no longer reachable through the IDR. CPU0's subsequent idr_find() will return NULL, and even if it still held a stale pointer, the immediate kfree() is now deferred until after the RCU grace period, so no UAF can occur.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: dm cache policy smq: check allocation under invalidate lock commit 2d1f7b65f5de ("dm cache policy smq: fix missing locks in invalidating cache blocks") added mq->lock around the destructive part of smq_invalidate_mapping(), but left the e->allocated check outside the critical section. That leaves a check-then-act race. Two concurrent invalidators can both observe e->allocated as true before either of them takes mq->lock. The first invalidator that acquires the lock removes the entry from the queues and hash table and then calls free_entry(), which clears e->allocated and puts the entry back on the free list. The second invalidator can then acquire mq->lock and continue with the stale result of the unlocked check. This can corrupt the SMQ queues or hash table by deleting an entry that is no longer on those structures. It can also hit the allocation check in free_entry() when the same entry is freed again. Move the allocation check under mq->lock so the predicate and the destructive operations are serialized by the same lock.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison The local-vs-remote region comparison loop uses '<=' instead of '<', causing it to read one entry past the valid range of qr_regions. The other loops in the same function correctly use '<'. Fix the loop condition to use '<' for consistency and correctness.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: zero-initialize GART table on allocation GART TLB is flushed after unmapping but not after mapping. Since amdgpu_bo_create_kernel() does not zero-initialize the buffer, when a single PTE is written the TLB may speculatively load other uninitialized entries from the same cacheline. Those garbage entries can appear valid, and a subsequent write to another PTE in the same cacheline may cause the GPU to use a stale garbage PTE from the TLB. Fix this by calling memset_io() to zero-initialize the GART table with gart_pte_flags immediately after allocation. Using AMDGPU_GEM_CREATE_VRAM_CLEARED, SDMA-based clear will not work since SDMA needs GART to be initialized to work. (cherry picked from commit d9af8263b82b6eaa60c5718e0c6631c5037e4b24)


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fuse: re-lock request before replacing page cache folio fuse_try_move_folio() unlocks the request on entry but does not re-lock it on the success path. This means fuse_chan_abort() can end the request and free the fuse_io_args (eg fuse_readpages_end()) while the subsequent copy chain logic after fuse_try_move_folio() accesses the fuse_io_args, leading to use-after-free issues. Fix this by calling lock_request() before replace_page_cache_folio(). This ensures the request is locked on the success path which will prevent the fuse_io_args from being freed while the later copying logic runs, and also ensures that the ap->folios[i]->mapping is never null since ap->folios[i] will always point to the newfolio after replace_page_cache_folio().


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fbdev: Fix fb_new_modelist to prevent null-ptr-deref in fb_videomode_to_var info->var, a framebuffer's current mode, is expected to have a matching entry in info->modelist. var_to_display() relies on this and treats a failed fb_match_mode() as "This should not happen". fb_set_var() keeps it true by adding the mode to the list on every change, and do_register_framebuffer() does the same at registration. store_modes() replaces the modelist from userspace. fb_new_modelist() validates the new modes but does not check that info->var still has a match. It relies on fbcon_new_modelist() to re-point consoles, but that only handles consoles mapped to the framebuffer. With fbcon unbound there are none, so info->var is left describing a mode that is no longer in the list. A later console takeover runs var_to_display(), where fb_match_mode() returns NULL and leaves fb_display[i].mode NULL. fbcon_switch() passes it to display_to_var(), and fb_videomode_to_var() dereferences the NULL mode. Keep the current mode in the list in fb_new_modelist(), the same way fb_set_var() does.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: block: Avoid mounting the bdev pseudo-filesystem in userspace The bdev pseudo-filesystem is an internal kernel filesystem with which userspace should not interfere. Unregister it so that userspace cannot even attempt to mount it. This fixes a bug [1] that occurs when attempting to access files, because the system call move_mount() uses pointers declared in the inode_operations structure, which for the bdev pseudo-filesystem are always equal to 0. `inode->i_op = &empty_iops;` [1] BUG: kernel NULL pointer dereference, address: 0000000000000000 #PF: supervisor instruction fetch in kernel mode #PF: error_code(0x0010) - not-present page PGD 23380067 P4D 23380067 PUD 23381067 PMD 0 Oops: 0010 [#1] PREEMPT SMP KASAN NOPTI CPU: 2 PID: 17125 Comm: syz-executor.0 Not tainted 6.1.155-syzkaller-00350-g84221fde2681 #0 Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.12.0-1 04/01/2014 RIP: 0010:0x0 Call Trace: <TASK> lookup_open.isra.0+0x700/0x1180 fs/namei.c:3460 open_last_lookups fs/namei.c:3550 [inline] path_openat+0x953/0x2700 fs/namei.c:3780 do_filp_open+0x1c5/0x410 fs/namei.c:3810 do_sys_openat2+0x171/0x4d0 fs/open.c:1318 do_sys_open fs/open.c:1334 [inline] __do_sys_openat fs/open.c:1350 [inline] __se_sys_openat fs/open.c:1345 [inline] __x64_sys_openat+0x13c/0x1f0 fs/open.c:1345 do_syscall_x64 arch/x86/entry/common.c:51 [inline] do_syscall_64+0x35/0x80 arch/x86/entry/common.c:81 entry_SYSCALL_64_after_hwframe+0x6e/0xd8 Found by Linux Verification Center (linuxtesting.org) with Syzkaller.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: keys: Pin request_key_auth payload in instantiate paths A: request_key() B: KEYCTL_INSTANTIATE_IOV ================ ========================= create auth key store rka in auth key wait for helper get auth key load rka from auth key copy user payload sleep on #PF helper completed detach and free rka destroy auth key wake up use rka->target_key **USE-AFTER-FREE** Give request_key_auth payloads a refcount. Take a payload reference while authkey->sem stabilizes the payload and revocation state. Hold that reference across the instantiate and reject paths. Drop the auth key owning reference from revoke and destroy. [jarkko: Replaced the first two paragraphs of text with an actual concurrency scenario.]


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/core: Prefer NLA_NUL_STRING These attributes are evaluated as c-string (passed to strcmp), but NLA_STRING doesn't check for the presence of a \0 terminator. Either this needs to switch to nla_strcmp() and needs to adjust printf fmt specifier to not use plain %s, or this needs to use NLA_NUL_STRING. As the code has been this way for long time, it seems to me that userspace does include the terminating nul, even tough its not enforced so far, and thus NLA_NUL_STRING use is the simpler solution.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: garp: fix unsigned integer underflow in garp_pdu_parse_attr The receive-side GARP attribute parser computes dlen with reversed operands: dlen = sizeof(*ga) - ga->len; ga->len is the on-wire attribute length and includes the GARP attribute header. For normal attributes with data, ga->len is larger than sizeof(*ga), so the subtraction underflows in unsigned arithmetic. The resulting value is later passed to garp_attr_lookup(), whose length argument is u8. After truncation, the parsed data length usually no longer matches the length stored for locally registered attributes, so received Join/Leave events are ignored. This breaks the GARP receive path for common attributes, such as GVRP VLAN registration attributes. Compute the data length as the attribute length minus the header length.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Bound iscsi_encode_text_output() appends to rsp_buf iscsi_encode_text_output() concatenates "key=value\0" records into login->rsp_buf, an 8192-byte kzalloc(MAX_KEY_VALUE_PAIRS) buffer allocated in iscsit_alloc_login_setup_buffer(). The three sprintf() call sites in this function (lines 1398, 1411, 1424 in v7.1-rc2) never check the remaining buffer capacity: *length += sprintf(output_buf, "%s=%s", er->key, er->value); *length += 1; output_buf = textbuf + *length; The 8192-byte ceiling at iscsi_target_check_login_request() bounds the *input* Login PDU payload, but a single PDU can carry up to 2048 minimal four-byte "a=b\0" pairs, each unknown key expanding to a 16-byte "a=NotUnderstood\0" output record via iscsi_add_notunderstood_response(). 2048 * 16 = 32 KiB of output into an 8 KiB buffer, producing a ~24 KiB heap overrun in the kmalloc-8k slab. The fix introduces a static iscsi_encode_text_record() helper that uses snprintf() with a per-call bounds check against the remaining buffer, and threads a u32 textbuf_size parameter through iscsi_encode_text_output(). Both call sites in iscsi_target_handle_csg_zero() (PHASE_SECURITY) and iscsi_target_handle_csg_one() (PHASE_OPERATIONAL) pass MAX_KEY_VALUE_PAIRS. On overflow the encoder logs the condition, calls iscsi_release_extra_responses() to drop queued records, and returns -1; both caller sites now emit ISCSI_STATUS_CLS_INITIATOR_ERR / ISCSI_LOGIN_STATUS_INIT_ERR via iscsit_tx_login_rsp() before returning, so the initiator sees an explicit failed-login response rather than a silent connection drop. (Prior to this patch only the PHASE_OPERATIONAL caller did that; the PHASE_SECURITY caller is converted to the same shape.)


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: scsi: target: iscsi: Fix CRC overread and double-free in iscsit_handle_text_cmd() Two latent bugs in the Text-phase handler, both present since the original LIO integration in commit e48354ce078c ("iscsi-target: Add iSCSI fabric support for target v4.1"): 1) DataDigest CRC buffer overread (4 bytes past text_in). text_in is kzalloc()'d at ALIGN(payload_length, 4). rx_size is then incremented by ISCSI_CRC_LEN to make room for the received DataDigest in the iovec, but the same (now-bumped) rx_size is passed as the buffer length to iscsit_crc_buf(): if (conn->conn_ops->DataDigest) { ... rx_size += ISCSI_CRC_LEN; } ... if (conn->conn_ops->DataDigest) { data_crc = iscsit_crc_buf(text_in, rx_size, 0, NULL); iscsit_crc_buf() walks rx_size bytes of text_in with crc32c(), so when DataDigest is negotiated it reads 4 bytes past the end of the text_in allocation. KASAN reproduces this directly on the unpatched mainline tree as slab-out-of-bounds in crc32c() called from the Text PDU path. The OOB bytes feed crc32c() and are then compared against the initiator-supplied checksum, so the value does not flow back to the attacker, but the kernel does read past the buffer on every Text PDU with DataDigest=CRC32C. Fix by passing the actual padded payload length (ALIGN(payload_length, 4)) that was used for the kzalloc(). 2) Stale cmd->text_in_ptr re-free (double-free) on ERL>0 bad DataDigest drop. On DataDigest mismatch with ErrorRecoveryLevel > 0 the handler silently drops the PDU and lets the initiator plug the CmdSN gap: kfree(text_in); return 0; cmd->text_in_ptr still points at the freed buffer. The next Text Request on the same ITT re-enters iscsit_setup_text_cmd(), which unconditionally does kfree(cmd->text_in_ptr); cmd->text_in_ptr = NULL; freeing the same pointer a second time. Session teardown via iscsit_release_cmd() has the same shape and hits the same double-free if the connection is dropped before a second Text Request arrives. On an unmodified mainline tree the bug-1 CRC overread fires first on the initial valid Text Request and perturbs the subsequent state, so #4 was isolated by building a kernel with only the bug-1 hunk of this patch applied plus temporary printk() observability around the three relevant kfree() sites. The observability prints are not part of this patch. On that build, a three-PDU Text Request sequence after login produces two back-to-back splats: BUG: KASAN: double-free in iscsit_setup_text_cmd+0x?? BUG: KASAN: double-free in iscsit_release_cmd+0x?? showing the same pointer freed in the ERL>0 drop path and again in iscsit_setup_text_cmd() (next Text Request on the same ITT) and once more in iscsit_release_cmd() (session teardown). On distro kernels with CONFIG_SLAB_FREELIST_HARDENED=y (default) the double-free becomes a remote kernel BUG(); on non-hardened kernels it corrupts the slab freelist. Fix by clearing cmd->text_in_ptr after the kfree() in the ERL>0 drop path. With both hunks applied #4 is directly observable on the stock tree without observability printks; fixing bug-1 alone would mask #4 less, not more, so the hunks are submitted together. Both fixes are one-liners. The Text PDU state machine is unchanged and the wire protocol is unaffected.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: scsi: fcoe: Reject FIP descriptors with zero fip_dlen in CVL walker drivers/scsi/fcoe/fcoe_ctlr.c::fcoe_ctlr_recv_clr_vlink() advanced the descriptor cursor by an attacker-supplied fip_dlen without ever requiring dlen >= sizeof(struct fip_desc) in the default branch. The named descriptor cases (FIP_DT_MAC, FIP_DT_NAME, FIP_DT_VN_ID) checked their per-type minimum lengths, but a FIP_DT_NON_CRITICAL descriptor (fip_dtype >= 128, which the standard requires receivers to silently ignore) skipped that check entirely. An unauthenticated L2 peer on the FCoE control VLAN could hang fcoe_ctlr_recv_work on an fcoe, qedf, or bnx2fc initiator indefinitely by emitting one FIP CVL frame whose single descriptor had fip_dtype == FIP_DT_NON_CRITICAL and fip_dlen == 0: the cursor advanced zero bytes per iteration and the loop condition rlen >= sizeof(*desc) stayed true forever, blocking every subsequent FIP frame on that controller. Tighten the outer dlen guard to also reject dlen < sizeof(struct fip_desc), so a malformed descriptor whose length cannot even cover the descriptor header is rejected before the switch. This is the same lower-bound the named cases already apply and is the minimum scope that closes the loop.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Cap recursion depth in __tb_property_parse_dir() A DIRECTORY entry's value field is used as the dir_offset for a recursive call into __tb_property_parse_dir() with no depth counter. A crafted peer that chains DIRECTORY entries into a back-reference loop drives the parser until the kernel stack is exhausted and the guard page fires. Any untrusted XDomain peer (cable, dock, in-line inspector, adjacent host) that reaches the PROPERTIES_REQUEST control-plane exchange can trigger this without authentication. Thread a depth counter through tb_property_parse() and __tb_property_parse_dir(), and reject blocks that exceed TB_PROPERTY_MAX_DEPTH = 8. That is comfortably larger than any observed legitimate XDomain layout. Operators who do not need XDomain host-to-host discovery can disable the path entirely with thunderbolt.xdomain=0 on the kernel command line.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: thunderbolt: property: Reject dir_len < 4 to prevent size_t underflow On the non-root path, __tb_property_parse_dir() takes dir_len from entry->length (u16 widened to size_t). Two distinct OOB conditions follow when entry->length < 4: 1. The non-root path begins with kmemdup(&block[dir_offset], sizeof(*dir->uuid), ...) which always reads 4 dwords from dir_offset. tb_property_entry_valid() only enforces dir_offset + entry->length <= block_len, so a crafted entry with dir_offset close to the end of the property block and entry->length in 0..3 passes that gate but lets the UUID copy run off the block (e.g. dir_offset = 497, dir_len = 3 in a 500-dword block reads block[497..501]). 2. After the kmemdup, content_len = dir_len - 4 underflows size_t to ~SIZE_MAX, nentries becomes SIZE_MAX / 4, and the entry walk runs OOB on each iteration until an entry fails validation or the kernel oopses on an unmapped page. Reject dir_len < 4 on the non-root path *before* the UUID kmemdup, which closes both holes. Also move INIT_LIST_HEAD(&dir->properties) up to immediately after the dir allocation so the new error-return path (and the existing uuid-alloc failure path) calling tb_property_free_dir() sees a walkable list rather than the zero-initialized NULL next/prev that list_for_each_entry_safe() would oops on.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: USB: serial: mct_u232: fix memory corruption with small endpoint The driver overrides the maximum transfer size for a specific device which only accepts 16 byte packets for its 32 byte bulk-out endpoint. Make sure to never increase the maximum transfer size to prevent slab corruption should a malicious device report a smaller endpoint max packet size than expected.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv6: validate extension header length before copying to cmsg ip6_datagram_recv_specific_ctl() builds IPV6_{HOPOPTS,DSTOPTS,RTHDR} cmsgs (and their IPV6_2292* legacy counterparts) by trusting the on-wire hdrlen byte (ptr[1]) when computing the put_cmsg() length. The length was validated only at parse time (ipv6_parse_hopopts(), etc.). An nftables payload-write expression can rewrite hdrlen after parsing and before the skb reaches recvmsg; the write itself is in-bounds but put_cmsg() then reads up to ((hdrlen+1) << 3) = 2040 bytes from an 8-byte header. nftables is reachable from an unprivileged user namespace, so this is an unprivileged slab-out-of-bounds read: BUG: KASAN: slab-out-of-bounds in put_cmsg+0x3ac/0x540 put_cmsg+0x3ac/0x540 udpv6_recvmsg+0xca0/0x1250 sock_recvmsg+0xdf/0x190 ____sys_recvmsg+0x1b1/0x620 Add ipv6_get_exthdr_len() which validates that at least two bytes are accessible before reading the hdrlen field, then checks the computed length against skb_tail_pointer(skb), returning 0 on failure. Extension headers are kept in the linear skb area by pskb_may_pull() during input, so skb_tail_pointer() is the correct bound. Use ipv6_get_exthdr_len() at all non-AH call sites: the five standalone cmsg blocks (HbH, 2292HbH, 2292DSTOPTS x2, 2292RTHDR) and the three standard cases in the extension-header walk loop (DSTOPTS, ROUTING, default). AH retains an inline bounds check because its length formula differs ((ptr[1]+2)<<2). The walk loop also gets a pre-read bounds check at the top to validate ptr before any case accesses ptr[0] or ptr[1]. When the walk loop detects a corrupted header, return from the function instead of continuing to process later socket options.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: USB: serial: omninet: fix memory corruption with small endpoint Make sure that the bulk-out buffers are at least as large as the hardcoded transfer size to avoid user-controlled slab corruption should a malicious device report a smaller endpoint max packet size than expected.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: usb: typec: tcpm: bound altmode_desc[] per iteration in svdm_consume_modes() svdm_consume_modes() checks pmdata->altmodes against the array size once before the loop over the count, but forgot to check the bound at every point in the loop. In the well-behaved SVDM discovery flow this is harmless because each of at most SVID_DISCOVERY_MAX SVIDs contributes at most MODE_DISCOVERY_MAX modes, exactly filling altmode_desc[ALTMODE_DISCOVERY_MAX]. But the CMDT_RSP_ACK handler in tcpm_pd_svdm() does not correlate an incoming ACK with any request the port actually sent. Once port->partner is set, an unsolicited Discover Modes ACK is consumed unconditionally. A broken or malicious port partner can therefore drive altmodes to ALTMODE_DISCOVERY_MAX - 1 via the normal flow, and then send one extra Discover Modes ACK with seven VDOs. Because the pre-loop check passes, the loop could then writes up to five entries past altmode_desc[]. For mode_data_prime the next field in struct tcpm_port is the partner_altmode[] pointer array, which then receives partner-chosen SVID/VDO bytes. Move the bound check inside the loop so the array can never be indexed past ALTMODE_DISCOVERY_MAX regardless of how many VDOs the partner supplies or how the function was reached.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: bonding: refuse to enslave CAN devices syzbot reported a kernel paging request crash in can_rx_unregister() inside net/can/af_can.c. The crash occurs because a virtual CAN device (vxcan) is being enslaved to a bonding master. During the enslavement process, the bonding driver mutates and modifies the network device states to fit an Ethernet-like aggregation model. However, CAN devices operate on a completely different Layer 2 architecture, relying on the CAN mid-layer private data structure (can_ml_priv) instead of standard Ethernet structures. Since bonding does not initialize or maintain these CAN structures, subsequent operations on the half-enslaved interface (such as closing associated sockets via isotp_release) lead to a null-pointer dereference when accessing the CAN receiver lists. Bonding CAN interfaces is architecturally invalid as CAN lacks MAC addresses, ARP capabilities, and standard Ethernet link-layer mechanisms. While generic loopback devices are blocked globally in net/core/dev.c, virtual CAN devices bypass this check because they do not carry the IFF_LOOPBACK flag, despite acting as local software-loopbacks. Fix this by explicitly blocking network devices of type ARPHRD_CAN from being enslaved at the very beginning of bond_enslave(). This prevents illegal state mutations, eliminates the resulting KASAN crashes, and avoids potential memory leaks from incomplete socket cleanups. As the CAN support has been added a long time after bonding the Fixes-tag points to the introduction of ARPHRD_CAN that would have needed a specific handling in bonding_main.c.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: pcm: oss: Fix setup list UAF on proc write error snd_pcm_oss_proc_write() links a newly allocated setup entry into the OSS setup list before duplicating the task name. If the task-name allocation fails, the error path frees the already linked entry and leaves setup_list pointing at freed memory. A later OSS device open can then walk the stale list entry in snd_pcm_oss_look_for_setup() and dereference freed memory. Allocate the task name and initialize the setup entry before publishing the entry on setup_list. Also fetch the initial proc read iterator only after taking setup_mutex, so all setup_list traversal follows the same list lifetime rules.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv4: free net->ipv4.sysctl_local_reserved_ports after unregister_net_sysctl_table() ipv4_sysctl_exit_net() is currently freeing net->ipv4.sysctl_local_reserved_ports too soon. Only after unregister_net_sysctl_table() we can be sure no threads can possibly use the sysctls, including /proc/sys/net/ipv4/ip_local_reserved_ports.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/smc: Do not re-initialize smc hashtables INIT_HLIST_HEAD(&smc_v*_hashinfo.ht) are called after smc_nl_init(), proto_register() and sock_register(). This can lead to smc_v*_hashinfo.ht being reset even though hash entries already exist and are being used, possibly resulting in a corrupted list. Remove unnecessary and dangerous re-initialisation of smc_v*_hashinfo.ht in smc_init(); it is implicitly initialised to zero anyhow. Add HLIST_HEAD_INIT to the definitions for clarity.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: synproxy: refresh tcphdr after skb_ensure_writable synproxy_tstamp_adjust() rewrites the TCP timestamp option in place and then patches the TCP checksum via inet_proto_csum_replace4() on the caller-supplied tcphdr pointer. Both ipv4_synproxy_hook() and ipv6_synproxy_hook() obtain that pointer with skb_header_pointer() before calling in, so it may either alias skb->head directly or point at the caller's on-stack _tcph buffer. Between obtaining the pointer and using it, the function calls skb_ensure_writable(skb, optend), which on a cloned or non-linear skb invokes pskb_expand_head() and frees the old skb->head. After that point the cached th is stale: caller (ipv[46]_synproxy_hook) th = skb_header_pointer(skb, ..., &_tcph) synproxy_tstamp_adjust(skb, protoff, th, ...) skb_ensure_writable(skb, optend) pskb_expand_head() /* kfree(old skb->head) */ ... inet_proto_csum_replace4(&th->check, ...) /* writes into freed head, or into the caller's stack copy leaving the on-wire checksum stale */ The option bytes are written through skb->data and are fine; only the checksum update goes through th and so lands in the wrong place. The result is either a write into freed slab memory or a packet leaving with a checksum that does not match its payload. Fix by re-deriving th from skb->data + protoff immediately after skb_ensure_writable() succeeds, so the subsequent checksum update targets the linear, writable header.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: Fix use-after-free race in nfc_llcp_recv_cc() A race condition exists in the NFC LLCP connection state machine where the connection acceptance packet (CC) can be processed concurrently with socket release. This can lead to a use-after-free of the socket object. When nfc_llcp_recv_cc() moves the socket from the connecting_sockets list to the sockets list, it does so without holding the socket lock. If llcp_sock_release() is executing concurrently, it might have already unlinked the socket and dropped its references, which can result in nfc_llcp_recv_cc() linking a freed socket into the live list. Fix this by holding lock_sock() during the state transition and list movement in nfc_llcp_recv_cc(). After acquiring the lock, check if the socket is still hashed to ensure it hasn't already been unlinked and marked for destruction by the release path. This aligns the locking pattern with recv_hdlc() and recv_disc().


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: nfc: llcp: Fix use-after-free in llcp_sock_release() llcp_sock_release() unconditionally unlinks the socket from the local sockets list. However, if the socket is still in connecting state, it is on the connecting list. Fix this by checking the socket state and unlinking from the correct list.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: security/keys: fix missed RCU read section on lookup Nicholas Carlini reports that the keyring code calls assoc_array_find() in find_key_to_update() without holding the RCU read lock, while the assoc_array_gc() code really is designed around removing the node from the tree and then freeing it after an RCU grace-period. The regular key handling doesn't see this because holding the keyring semaphore hides any lifetime issues, but the persistent key handling uses a different model. Instead of extending the keyring locking, just do the simple RCU locking that the assoc_array was designed for.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: batman-adv: tt: fix negative tt_buff_len batadv_orig_node::tt_buff_len was declared as s16, but the field is never intended to hold a negative value. When a value greater than 32767 is assigned, it wraps to a negative signed integer. In batadv_send_other_tt_response(), tt_buff_len is temporarily widened to s32. The incorrectly negative s16 value propagates into the s32, causing batadv_tt_prepare_tvlv_global_data() to allocate a full sized buffer but populates only a small portion of it with the collected changeset. All remaining bits are kept uninitialized. Using an u16 avoids this type confusion and ensures that no (negative) sign extension is performed in batadv_send_other_tt_response().


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: scsi: isci: Fix use-after-free in device removal path The ISCI completion tasklet is initialized in isci_host_alloc() (drivers/scsi/isci/init.c:496) and scheduled from both MSI-X and legacy interrupt handlers (drivers/scsi/isci/host.c:223,613). isci_host_deinit() stops the controller and waits for stop completion, but it never kills completion_tasklet before teardown continues. A top-of-function tasklet_kill() is not sufficient here: interrupts are only disabled when isci_host_stop_complete() runs, so until wait_for_stop() returns the IRQ handlers can still requeue the tasklet. The tasklet callback also re-enables interrupts after draining completions, so killing the tasklet before the source is quiesced leaves the same race open. Once wait_for_stop() returns, no further IRQ-driven scheduling can occur. Kill completion_tasklet there so teardown cannot race a queued tasklet running on a dead ihost. On remove or unload, the stale callback can otherwise dereference ihost and touch ihost->smu_registers after the host lifetime ends. A UML + KASAN analogue reproduced the failure class both with no tasklet_kill() and with tasklet_kill() placed before source quiesce, and stayed clean once the kill happened after quiescing the scheduling source. This mirrors commit f6ab594672d4 ("scsi: aic94xx: fix use-after-free in device removal path"), but ISCI needs the kill after wait_for_stop().


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: af_unix: Fix UAF read of tail->len in unix_stream_data_wait() unix_stream_data_wait() does skb_peek_tail(&sk->sk_receive_queue) without holding any lock that prevents SKBs on that queue from being dequeued and freed. This has been the case since commit 79f632c71bea ("unix/stream: fix peeking with an offset larger than data in queue"). The first consequence of this is that the pointer comparison `tail != last` can be false even if `last` semantically refers to an already-freed SKB while `tail` is a new SKB allocated at the same address; which can cause unix_stream_data_wait() to wrongly keep blocking after new data has arrived, but only in a weird scenario where a peeking recv() and a normal recv() on the same socket are racing, which is probably not a real problem. But since commit 2b514574f7e8 ("net: af_unix: implement splice for stream af_unix sockets"), `tail` is actually dereferenced, which can cause UAF in the following race scenario (where test_setup() runs single-threaded, and afterwards, test_thread1() and test_thread2() run concurrently in two threads: ``` static int socks[2]; void test_setup(void) { socketpair(AF_UNIX, SOCK_STREAM, 0, socks); send(socks[1], "A", 1, 0); int peekoff = 1; setsockopt(socks[0], SOL_SOCKET, SO_PEEK_OFF, &peekoff, sizeof(peekoff)); } void test_thread1(void) { char dummy; recv(socks[0], &dummy, 1, MSG_PEEK); } void test_thread2(void) { char dummy; recv(socks[0], &dummy, 1, 0); shutdown(socks[1], SHUT_WR); } ``` when racing like this: ``` thread1 thread2 unix_stream_read_generic mutex_lock(&u->iolock) skb_peek(&sk->sk_receive_queue) skb_peek_next(skb, &sk->sk_receive_queue) mutex_unlock(&u->iolock) unix_stream_read_generic unix_state_lock(sk) skb_peek(&sk->sk_receive_queue) unix_state_unlock(sk) unix_stream_data_wait unix_state_lock(sk) tail = skb_peek_tail(&sk->sk_receive_queue) spin_lock(&sk->sk_receive_queue.lock) __skb_unlink(skb, &sk->sk_receive_queue) spin_unlock(&sk->sk_receive_queue.lock) consume_skb(skb) [frees the SKB] `tail != last`: false `tail`: true `tail->len != last_len` ***UAF*** ``` Fix the UAF by removing the read of tail->len; checking tail->len would only make sense if SKBs in the receive queue of a UNIX socket could grow, which can no longer happen. Kuniyuki explained: > When commit 869e7c62486e ("net: af_unix: implement stream sendpage > support") added sendpage() support, data could be appended to the last > skb in the receiver's queue. > > That's why we needed to check if the length of the last skb was changed > while waiting for new data in unix_stream_data_wait(). > > However, commit a0dbf5f818f9 ("af_unix: Support MSG_SPLICE_PAGES") and > commit 57d44a354a43 ("unix: Convert unix_stream_sendpage() to use > MSG_SPLICE_PAGES") refactored sendmsg(), and now data is always added > to a new skb. That means this fix is not suitable for kernels before 6.5.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ixgbevf: fix use-after-free in VEPA multicast source pruning ixgbevf_clean_rx_irq() prunes frames whose source MAC matches the VF's own address (VEPA multicast workaround) by freeing the skb and continuing to the next descriptor: dev_kfree_skb_irq(skb); continue; The skb pointer is declared outside the while loop and persists across iterations. Because the continue skips the "skb = NULL" reset at the bottom of the loop, the next iteration enters the "else if (skb)" path and calls ixgbevf_add_rx_frag() on the freed skb, dereferencing skb_shinfo(skb)->nr_frags - a use-after-free in NAPI softirq context. The sibling driver iavf already handles this correctly by nulling the pointer before continuing. Apply the same pattern here. I do not have ixgbevf hardware; the bug was found by static analysis (scan_drop_continue_loops.py + semgrep drop_continue_in_loop, multi-tool corroboration with the highest score in the scan). The UAF was confirmed under KASAN by loading a test module that reproduces the exact code pattern (alloc skb, kfree_skb, then read skb_shinfo(skb)->nr_frags): BUG: KASAN: slab-use-after-free in ixgbevf_uaf_test_init+0x100/0x1000 Read of size 8 at addr 000000006163ae78 by task insmod/30 freed 208-byte region [000000006163adc0, 000000006163ae90) QEMU emulates igb (82576) but not ixgbe (82599), and the igbvf VF driver does not include the VEPA source pruning path, so a full end-to-end reproduction with emulated hardware was not possible.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv4: raw: reject IP_HDRINCL packets with ihl < 5 raw_send_hdrinc() validates that the caller-supplied IPv4 header fits within the message length: iphlen = iph->ihl * 4; err = -EINVAL; if (iphlen > length) goto error_free; if (iphlen >= sizeof(*iph)) { /* fix up saddr, tot_len, id, csum, transport_header */ } It does not, however, reject ihl < 5. For such a packet the "if (iphlen >= sizeof(*iph))" branch is skipped, leaving the crafted iphdr untouched, but the packet is still handed to __ip_local_out() and onward. Downstream consumers that read iph->ihl assume a sane value: net/ipv4/ah4.c:ah_output() in particular subtracts sizeof(struct iphdr) from top_iph->ihl * 4 and passes the (signed-int-negative, then cast to size_t) result to memcpy(), producing an OOB access of length close to SIZE_MAX and a host kernel panic. An IPv4 header with ihl < 5 is malformed by definition (RFC 791: "Internet Header Length is the length of the internet header in 32 bit words ... Note that the minimum value for a correct header is 5."). The kernel should not be willing to inject such a packet into its own output path. Reject "iphlen < sizeof(*iph)" alongside the existing "iphlen > length" check. This matches the principle that locally constructed packets that re-enter the IP stack must pass the same basic sanity tests that a foreign packet would be subjected to. Once this lands, the "if (iphlen >= sizeof(*iph))" wrapper around the fixup branch becomes redundant; left in place to keep the patch minimal and backport-friendly. A follow-up can unwrap it. Note that commit 86f4c90a1c5c ("ipv4, ipv6: ensure raw socket message is big enough to hold an IP header") ensures the message buffer is large enough to hold an iphdr, but does not constrain the self-reported iph->ihl. Reachability: the malformed packet source is any caller with CAP_NET_RAW, including an unprivileged process in a user+net namespace on a kernel with CONFIG_USER_NS=y. The reproduced AH crash also requires a matching xfrm AH policy on the outgoing route; a container granted CAP_NET_ADMIN can install that state and policy in its netns. Loopback bypasses xfrm_output, so the trigger uses a real netdev. Reproduced on UML + KASAN: kernel-mode fault at addr 0x0 with memcpy_orig at the crash site. Same shape reproduces inside a rootless Docker container with --cap-add NET_ADMIN on a stock distro kernel.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: vsock/vmci: fix UAF when peer resets connection during handshake vmci_transport_recv_connecting_server() returned err = 0 for a peer RST in its default switch arm: err = pkt->type == VMCI_TRANSPORT_PACKET_TYPE_RST ? 0 : -EINVAL; That made vmci_transport_recv_listen() skip vsock_remove_pending(), leaving the pending socket on the listener's pending_links with sk_state = TCP_CLOSE while destroy: still dropped the explicit reference taken before schedule_delayed_work(). One second later vsock_pending_work() observed is_pending=true and performed full cleanup: vsock_remove_pending() then the two trailing sock_put(sk) calls -- the first reached refcount 0 and __sk_freed the socket, and the second wrote into the freed object: BUG: KASAN: slab-use-after-free in refcount_warn_saturate Write of size 4 at addr ffff88800b1cac80 by task kworker Workqueue: events vsock_pending_work Treat peer RST like any other unexpected packet type (err = -EINVAL). All destroy: arms now return err < 0, so vmci_transport_recv_listen() removes pending from pending_links synchronously and vsock_pending_work() takes the is_pending=false / !rejected branch, dropping only its own work reference. This also closes the multi-packet race Sashiko reported on v2: pending is removed from the list before any subsequent packet can find it. The pre-existing sk_acceptq_removed() gap on the err < 0 path of vmci_transport_recv_listen() that Sashiko also noted is not introduced or changed by this patch. Tested on lts-6.12.79 with KASAN: 52/100 unpatched -> 0/100 patched.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: qed: fix double free in qed_cxt_tables_alloc() If one of the later PF or VF CID bitmap allocations fails, qed_cid_map_alloc() jumps to cid_map_fail and frees the previously allocated CID bitmaps before returning an error. qed_cxt_tables_alloc() then calls qed_cxt_mngr_free(), which invokes qed_cid_map_free() again. Fix this by setting each CID bitmap pointer to NULL after bitmap_free() to avoid double free. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in v7.1-rc3. Runtime reproduction was not attempted because exercising the failing allocation path requires device-specific setup.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: btrfs: tracepoints: fix sleep while in atomic context in btrfs_sync_file() The trace event btrfs_sync_file() is called in an atomic context (all trace events are) and its call to dput(), which is needed due to the call to dget_parent(), can sleep, triggering a kernel splat. This can be reproduced by enabling the trace event and running btrfs/056 from fstests for example. The splat shown in dmesg is the following: [53.919] BUG: sleeping function called from invalid context at fs/dcache.c:970 [53.947] in_atomic(): 1, irqs_disabled(): 0, non_block: 0, pid: 32773, name: xfs_io [53.988] preempt_count: 2, expected: 0 [53.967] RCU nest depth: 0, expected: 0 [53.943] Preemption disabled at: [53.944] [<0000000000000000>] 0x0 [54.078] CPU: 0 UID: 0 PID: 32773 Comm: xfs_io Tainted: G W 7.1.0-rc1-btrfs-next-232+ #1 PREEMPT(full) [54.070] Tainted: [W]=WARN [54.071] Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS rel-1.16.2-0-gea1b7a073390-prebuilt.qemu.org 04/01/2014 [54.072] Call Trace: [54.074] <TASK> [54.076] dump_stack_lvl+0x56/0x80 [54.079] __might_resched.cold+0xd6/0x10f [54.072] dput.part.0+0x24/0x110 [54.078] trace_event_raw_event_btrfs_sync_file+0x75/0x140 [btrfs] [54.089] btrfs_sync_file+0x1ed/0x530 [btrfs] [54.087] ? __handle_mm_fault+0x8ae/0xed0 [54.089] btrfs_do_write_iter+0x172/0x210 [btrfs] [54.091] vfs_write+0x21f/0x450 [54.094] __x64_sys_pwrite64+0x8d/0xc0 [54.096] ? do_user_addr_fault+0x20c/0x670 [54.099] do_syscall_64+0x60/0xf20 [54.092] ? clear_bhb_loop+0x60/0xb0 [54.094] entry_SYSCALL_64_after_hwframe+0x76/0x7e So stop using dget_parent() and dput() and access the parent dentry directly as dentry->d_parent. This is also what ext4 is doing in its equivalent trace event ext4_sync_file_enter().


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: Fix UAF read of dev->name bnep_add_connection() needs to keep holding the bnep_session_sem while reading dev->name (just like bnep_get_connlist() does); otherwise the bnep_session() thread can concurrently free the net_device, which can for example be triggered by a concurrent bnep_del_connection(). (This UAF is fairly uninteresting from a security perspective; calling bnep_add_connection() requires passing a capable(CAP_NET_ADMIN) check. It also requires completely tearing down a netdev during a fairly tight race window.)


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: team: fix NULL pointer dereference in team_xmit during mode change __team_change_mode() clears team->ops with memset() before restoring safe dummy handlers via team_adjust_ops(). A concurrent team_xmit() running under RCU on another CPU can read team->ops.transmit during this window and call a NULL function pointer, crashing the kernel. The race requires a mode change (CAP_NET_ADMIN) concurrent with transmit on the team device. BUG: kernel NULL pointer dereference, address: 0000000000000000 Oops: 0010 [#1] SMP KASAN NOPTI RIP: 0010:0x0 Call Trace: team_xmit (drivers/net/team/team_core.c:1853) dev_hard_start_xmit (net/core/dev.c:3904) __dev_queue_xmit (net/core/dev.c:4871) packet_sendmsg (net/packet/af_packet.c:3109) __sys_sendto (net/socket.c:2265) The original code assumed that no ports means no traffic, so mode changes could freely memset()/memcpy() the ops. AF_PACKET with forced carrier breaks that assumption. Prevent the race instead of making it safe: replace memset()/memcpy() with per-field updates that never touch transmit or receive. Those two handlers are managed solely by team_adjust_ops(), which already installs dummies when tx_en_port_count == 0 (always true during mode change since no ports are present). WRITE_ONCE/READ_ONCE prevent store/load tearing on the handler pointers. synchronize_net() before exit_op() drains in-flight readers that may still reference old mode state from before port removal switched the handlers to dummies.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fuse: re-lock request before returning from fuse_ref_folio() fuse_ref_folio() unlocks the request but does not re-lock it before returning. fuse_chan_abort() can end the request and the async end callback (eg fuse_writepage_free()) can free the args while the subsequent copy chain logic after fuse_ref_folio() accesses them, leading to use-after-free issues. Fix this by locking the request in fuse_ref_folio() before returning.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: qat - validate RSA CRT component lengths The generic RSA key parser (rsa_helper.c) bounds each CRT component (p, q, dp, dq, qinv) by the modulus size n_sz, but qat_rsa_setkey_crt() allocates half-size DMA buffers (key_sz / 2) and right-aligns each component with: memcpy(dst + half_key_sz - len, src, len) When a CRT component is larger than half_key_sz the subtraction underflows and memcpy writes past the DMA buffer, causing memory corruption. Add a len > half_key_sz check next to the existing !len check for each of the five CRT components so the driver falls back to the non-CRT path instead of writing out of bounds.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: drbg - Fix returning success on failure in CTR_DRBG drbg_ctr_generate() sometimes returns success when it fails, leaving the output buffer uninitialized. Fix it.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - restore callback for non-parallel fallback pcrypt installs pcrypt_aead_done() on the child AEAD request before trying to submit it through padata. If padata_do_parallel() returns -EBUSY, pcrypt falls back to calling the child AEAD directly. That fallback must not keep the padata completion callback. Otherwise an asynchronous completion runs pcrypt_aead_done() even though the request was never enrolled in padata. Restore the original request callback and callback data before calling the child AEAD directly. This keeps the fallback path aligned with a direct AEAD request while leaving the parallel path unchanged.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: ecc - Fix carry overflow in vli multiplication The carry flag calculation fails when r01.m_high is saturated (0xFFFFFFFFFFFFFFFF) and addition of lower bits overflows. The condition (r01.m_high < product.m_high) doesn't handle the case where r01.m_high == product.m_high and an additional carry exists from lower-bit overflow. When commit 3c4b23901a0c ("crypto: ecdh - Add ECDH software support") introduced crypto/ecc.c, it split the muladd() function in the micro-ecc library into separate mul_64_64() and add_128_128() helpers. It seems the check got lost in translation. Add proper handling for this boundary by accounting for the carry from the lower addition.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: caam - use print_hex_dump_devel to guard key hex dumps Use print_hex_dump_devel() for dumping sensitive key material in *_setkey() to avoid leaking secrets at runtime when CONFIG_DYNAMIC_DEBUG is enabled.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: isofs: bound Rock Ridge symlink components to the SL record get_symlink_chunk() and the SL handling in parse_rock_ridge_inode_internal() walk the variable-length components of a Rock Ridge "SL" (symbolic link) record. Each component is a two-byte header (flags, len) followed by len bytes of text, so it occupies slp->len + 2 bytes. Both loops read slp->len and advance to the next component, and get_symlink_chunk() additionally does memcpy(rpnt, slp->text, slp->len), but neither checks that the component lies within the SL record before dereferencing it. A crafted SL record whose component declares a len that runs past the record (rr->len) therefore triggers an out-of-bounds read of up to 255 bytes. When the record sits at the tail of its backing buffer - for example a small kmalloc()ed continuation block reached through a CE record - the read crosses the allocation; get_symlink_chunk() then copies the out-of-bounds bytes into the symlink body returned to user space by readlink(), disclosing adjacent kernel memory. ISO 9660 images are routinely mounted from untrusted removable media - desktop environments auto-mount them (e.g. via udisks2) without CAP_SYS_ADMIN - so the record contents are attacker-controlled. Reject any component that does not fit in the remaining record bytes before using it. In get_symlink_chunk() return NULL, like the existing output-buffer (plimit) checks, so a malformed record makes readlink() fail with -EIO rather than silently returning a truncated target; in parse_rock_ridge_inode_internal() stop the inode-size walk.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: udf: validate sparing table length as an entry count, not a byte count udf_load_sparable_map() accepts a sparing table when sizeof(*st) + le16_to_cpu(st->reallocationTableLen) > sb->s_blocksize is false, i.e. it treats reallocationTableLen as a number of BYTES that must fit in the block. But the table is walked as an array of 8-byte sparingEntry elements: for (i = 0; i < le16_to_cpu(st->reallocationTableLen); i++) { struct sparingEntry *entry = &st->mapEntry[i]; ... entry->origLocation ... } in udf_get_pblock_spar15() and udf_relocate_blocks(). A reallocationTableLen of N therefore passes the check whenever sizeof(*st) + N <= blocksize, yet the consumers index sizeof(*st) + N * sizeof(struct sparingEntry) bytes -- up to ~8x the block. On a crafted UDF image this is an out-of-bounds read in udf_get_pblock_spar15(); udf_relocate_blocks() additionally feeds the same length to udf_update_tag(), whose crc_itu_t() reads far past the block, and its memmove() through st->mapEntry[] is an out-of-bounds write. Validate reallocationTableLen as the entry count it is, with struct_size().


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: udf: validate VAT header length against the VAT inode size udf_load_vat() takes the virtual partition's start offset straight from the on-disk VAT 2.0 header without checking it against the VAT inode size: map->s_type_specific.s_virtual.s_start_offset = le16_to_cpu(vat20->lengthHeader); map->s_type_specific.s_virtual.s_num_entries = (sbi->s_vat_inode->i_size - map->s_type_specific.s_virtual.s_start_offset) >> 2; lengthHeader is a fully attacker-controlled 16-bit value. If it exceeds the VAT inode size, the s_num_entries subtraction underflows to a huge count, which defeats the "block > s_num_entries" bound in udf_get_pblock_virt15(); and on the ICB-inline path that function reads ((__le32 *)(iinfo->i_data + s_start_offset))[block] so a large s_start_offset indexes past the inode's in-ICB data. Mounting a crafted UDF image with a virtual (VAT) partition then triggers an out-of-bounds read. Reject a VAT whose header length does not leave room for at least one entry within the VAT inode.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: USB: ulpi: fix memory leak on registration failure The allocated device name is never freed on early ULPI device registration failures. Fix this by initialising the device structure earlier and releasing the initial reference whenever registration fails.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: USB: serial: digi_acceleport: fix write buffer corruption The digi_write_inb_command() is supposed to wait for the write urb to become available or return an error, but instead it updates the transfer buffer and tries to resubmit the urb on timeout. To make things worse, for commands like break control where no timeout is used, the driver would corrupt the urb immediately due to a broken jiffies comparison (on 32-bit machines this takes five minutes of uptime to trigger due to INITIAL_JIFFIES). Fix this by adding the missing return on timeout and waiting indefinitely when no timeout has been specified as intended. This issue was (sort of) flagged by Sashiko when reviewing an unrelated change to the driver.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: USB: serial: digi_acceleport: fix hard lockup on disconnect If submitting the OOB write urb fails persistently (e.g if the device is being disconnected) the driver would loop indefinitely with interrupts disabled. Check for urb submission errors when sending OOB commands to avoid hanging if, for example, open(), set_termios() or close() races with a physical disconnect. This is issue was flagged by Sashiko when reviewing an unrelated change to the driver.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: USB: legousbtower: fix use-after-free on disconnect race mutex_unlock() may access the mutex structure after releasing the lock and therefore cannot be used to manage lifetime of objects directly (unlike spinlocks and refcounts). [1][2] Use a kref to release the driver data to avoid use-after-free in mutex_unlock() when release() races with disconnect(). [1] a51749ab34d9 ("locking/mutex: Document that mutex_unlock() is non-atomic") [2] 2b9d9e0a9ba0 ("locking/mutex: Clarify that mutex_unlock(), and most other sleeping locks, can still use the lock object after it's unlocked")


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: USB: iowarrior: fix use-after-free on disconnect race mutex_unlock() may access the mutex structure after releasing the lock and therefore cannot be used to manage lifetime of objects directly (unlike spinlocks and refcounts). [1][2] Use a kref to release the driver data to avoid use-after-free in mutex_unlock() when release() races with disconnect(). [1] a51749ab34d9 ("locking/mutex: Document that mutex_unlock() is non-atomic") [2] 2b9d9e0a9ba0 ("locking/mutex: Clarify that mutex_unlock(), and most other sleeping locks, can still use the lock object after it's unlocked")


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: USB: ldusb: fix use-after-free on disconnect race mutex_unlock() may access the mutex structure after releasing the lock and therefore cannot be used to manage lifetime of objects directly (unlike spinlocks and refcounts). [1][2] Use a kref to release the driver data to avoid use-after-free in mutex_unlock() when release() races with disconnect(). [1] a51749ab34d9 ("locking/mutex: Document that mutex_unlock() is non-atomic") [2] 2b9d9e0a9ba0 ("locking/mutex: Clarify that mutex_unlock(), and most other sleeping locks, can still use the lock object after it's unlocked")


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: USB: idmouse: fix use-after-free on disconnect race mutex_unlock() may access the mutex structure after releasing the lock and therefore cannot be used to manage lifetime of objects directly (unlike spinlocks and refcounts). [1][2] Use a kref to release the driver data to avoid use-after-free in mutex_unlock() when release() races with disconnect(). [1] a51749ab34d9 ("locking/mutex: Document that mutex_unlock() is non-atomic") [2] 2b9d9e0a9ba0 ("locking/mutex: Clarify that mutex_unlock(), and most other sleeping locks, can still use the lock object after it's unlocked")


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: smb: client: harden POSIX SID length parsing posix_info_sid_size() reads sid[1] to obtain the subauthority count, but its existing boundary check still accepts buffers with only one remaining byte. Require two bytes before reading sid[1] so all client paths that reuse the helper reject truncated POSIX SIDs safely.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix next buffer leak in receive_encrypted_standard() receive_encrypted_standard() allocates next_buffer before checking whether the number of compound PDUs already reached MAX_COMPOUND. If the limit check fails, the function returns immediately and the newly allocated next_buffer is not assigned to server->smallbuf/server->bigbuf, making it leaked. Move the MAX_COMPOUND check before allocating next_buffer.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: bnep: pin L2CAP connection during netdev registration bnep_add_connection() reads the L2CAP connection without holding the channel lock, then passes its HCI device to register_netdev(). Controller teardown can clear and release that connection concurrently, leaving the network device registration path to dereference a freed parent device. Take a reference to the L2CAP connection while holding the channel lock. Retain it until register_netdev() has taken the parent device reference.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: terminate table name before find_table_lock() update_counters() and compat_update_counters() forward a user-supplied 32-byte table name to find_table_lock() without NUL-terminating it. On a lookup miss, find_inlist_lock() calls try_then_request_module(..., "%s%s", "ebtable_", name), and vsnprintf() reads past the name field and the stack object until it hits a zero byte. BUG: KASAN: stack-out-of-bounds in string (lib/vsprintf.c:648 lib/vsprintf.c:730) Read of size 1 at addr ffff8880119dfb20 by task exploit/147 Call Trace: ... string (lib/vsprintf.c:648 lib/vsprintf.c:730) vsnprintf (lib/vsprintf.c:2945) __request_module (kernel/module/kmod.c:150) do_update_counters.isra.0 (net/bridge/netfilter/ebtables.c:371 net/bridge/netfilter/ebtables.c:380) update_counters (net/bridge/netfilter/ebtables.c:1440) do_ebt_set_ctl (net/bridge/netfilter/ebtables.c:2573) nf_setsockopt (net/netfilter/nf_sockopt.c:101) ip_setsockopt (net/ipv4/ip_sockglue.c:1424) raw_setsockopt (net/ipv4/raw.c:847) __sys_setsockopt (net/socket.c:2393) ... compat_do_replace() shares the same unterminated name via compat_copy_ebt_replace_from_user(); terminate it there too so all find_table_lock() callers behave alike. The other callers already terminate the name after the copy.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: ebtables: module names must be null-terminated We need to explicitly check the length, else we may pass non-null terminated string to request_module().


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv4: igmp: remove multicast group from hash table on device destruction When a device is destroyed under RTNL, ip_mc_destroy_dev() iterates through the multicast list and calls ip_ma_put() on each membership, scheduling them for RCU reclamation. However, they are not unlinked from the device's multicast hash table (mc_hash). Since the device remains published in dev->ip_ptr until after ip_mc_destroy_dev() completes, concurrent RCU readers traversing mc_hash can still locate and access the multicast group after its refcount is decremented. If the RCU callback runs and frees the group while a reader is accessing it, a use-after-free occurs. Fix this by unlinking the multicast group from mc_hash using ip_mc_hash_remove() before scheduling it for reclamation. BUG: KASAN: slab-use-after-free in ip_check_mc_rcu+0x149/0x3f0 Read of size 4 at addr ffff888009bf1408 by task mausezahn/2276 Call Trace: <IRQ> dump_stack_lvl+0x67/0x90 print_report+0x175/0x7c0 kasan_report+0x147/0x180 ip_check_mc_rcu+0x149/0x3f0 udp_v4_early_demux+0x36d/0x12d0 ip_rcv_finish_core+0xb8b/0x1390 ip_rcv_finish+0x54/0x120 NF_HOOK+0x213/0x2b0 __netif_receive_skb+0x126/0x340 process_backlog+0x4f2/0xf00 __napi_poll+0x92/0x2c0 net_rx_action+0x583/0xc60 handle_softirqs+0x236/0x7f0 do_softirq+0x57/0x80 </IRQ> Allocated by task 2239: kasan_save_track+0x3e/0x80 __kasan_kmalloc+0x72/0x90 ____ip_mc_inc_group+0x31a/0xa40 __ip_mc_join_group+0x334/0x3f0 do_ip_setsockopt+0x16fa/0x2010 ip_setsockopt+0x3f/0x90 do_sock_setsockopt+0x1ad/0x300 Freed by task 0: kasan_save_track+0x3e/0x80 kasan_save_free_info+0x40/0x50 __kasan_slab_free+0x3a/0x60 __rcu_free_sheaf_prepare+0xd4/0x220 rcu_free_sheaf+0x36/0x190 rcu_core+0x8d9/0x12f0 handle_softirqs+0x236/0x7f0


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: af_key: initialize alg_key_len for IPComp states pfkey_msg2xfrm_state() handles the IPComp (SADB_X_SATYPE_IPCOMP) case by allocating x->calg and copying only the algorithm name: x->calg = kmalloc_obj(*x->calg); if (!x->calg) { err = -ENOMEM; goto out; } strcpy(x->calg->alg_name, a->name); x->props.calgo = sa->sadb_sa_encrypt; Unlike the authentication (x->aalg) and encryption (x->ealg) branches of the same function, the compression branch never initializes calg->alg_key_len. IPComp carries no key and the allocation only reserves sizeof(struct xfrm_algo) (i.e. no room for a key), so the field is left containing uninitialized slab data. calg->alg_key_len is later used as a length by xfrm_algo_clone() when an IPComp state is cloned during XFRM_MSG_MIGRATE: xfrm_state_migrate() xfrm_state_clone_and_setup() x->calg = xfrm_algo_clone(orig->calg); kmemdup(orig, xfrm_alg_len(orig)); where xfrm_alg_len() returns sizeof(*alg) + (alg_key_len + 7) / 8. With a non-zero garbage alg_key_len, kmemdup() reads past the end of the 68-byte calg object. Adding an IPComp SA via PF_KEY and then migrating it triggers (net-next, KASAN, init_on_alloc=0): BUG: KASAN: slab-out-of-bounds in kmemdup_noprof+0x44/0x60 Read of size 4164 at addr ff11000025a74980 by task diag2/9287 CPU: 3 UID: 0 PID: 9287 Comm: diag2 7.1.0-rc6-g903db046d557 #1 Call Trace: <TASK> dump_stack_lvl+0x10e/0x1f0 print_report+0xf7/0x600 kasan_report+0xe4/0x120 kasan_check_range+0x105/0x1b0 __asan_memcpy+0x23/0x60 kmemdup_noprof+0x44/0x60 xfrm_state_migrate+0x70a/0x1da0 xfrm_migrate+0x753/0x18a0 xfrm_do_migrate+0xb47/0xf10 xfrm_user_rcv_msg+0x411/0xb50 netlink_rcv_skb+0x158/0x420 xfrm_netlink_rcv+0x71/0x90 netlink_unicast+0x584/0x850 netlink_sendmsg+0x8b0/0xdc0 ____sys_sendmsg+0x9f7/0xb90 ___sys_sendmsg+0x134/0x1d0 __sys_sendmsg+0x16d/0x220 do_syscall_64+0x116/0x7d0 entry_SYSCALL_64_after_hwframe+0x77/0x7f </TASK> Allocated by task 9287: kasan_save_stack+0x33/0x60 kasan_save_track+0x14/0x30 __kasan_kmalloc+0xaa/0xb0 pfkey_add+0x2652/0x2ea0 pfkey_process+0x6d0/0x830 pfkey_sendmsg+0x42c/0x850 __sys_sendto+0x461/0x4b0 __x64_sys_sendto+0xe0/0x1c0 do_syscall_64+0x116/0x7d0 entry_SYSCALL_64_after_hwframe+0x77/0x7f The buggy address belongs to the object at ff11000025a74980 which belongs to the cache kmalloc-96 of size 96 The buggy address is located 0 bytes inside of allocated 68-byte region [ff11000025a74980, ff11000025a749c4) Depending on the uninitialized value the same field can instead request an oversized kmemdup() allocation and make the migration clone fail. The XFRM netlink path is not affected: verify_one_alg() rejects an XFRMA_ALG_COMP attribute shorter than xfrm_alg_len(), so a calg added via XFRM_MSG_NEWSA is always self-consistent. Initialize calg->alg_key_len to 0, matching the aalg/ealg branches.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: fix use-after-free on marvell probe failure Make sure to stop any TX URBs submitted during Marvell OOB wakeup configuration on later probe failures to avoid use-after-free in the completion callback. This issue was reported by Sashiko while reviewing a fix for a wakeup source leak in the btusb probe errors paths.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: btusb: fix use-after-free on registration failure Make sure to release the sibling interfaces in case controller registration fails to avoid use-after-free and double-free when they are eventually disconnected. This issue was reported by Sashiko while reviewing a fix for a wakeup source leak in the btusb probe errors paths.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ACPI: CPPC: Suppress UBSAN warning caused by field misuse The definition of reg->access_width changes depending on the reg->space_id type. Type ACPI_ADR_SPACE_PLATFORM_COMM uses access_width to indicate the PCC region, which can result in a UBSAN if the value is greater than 4. For example: UBSAN: shift-out-of-bounds in drivers/acpi/cppc_acpi.c:1090:9 shift exponent 32 is too large for 32-bit type 'int' CPU: 61 UID: 0 PID: 1220 Comm: (udev-worker) Not tainted 7.0.10-201.fc44.aarch64 #1 PREEMPT(lazy) Hardware name: To be filled by O.E.M. Call trace: ...(trimming) ubsan_epilogue+0x10/0x48 __ubsan_handle_shift_out_of_bounds+0xdc/0x1e0 cpc_write+0x4d0/0x670 cppc_set_perf+0x18c/0x490 cppc_cpufreq_cpu_init+0x1c8/0x380 [cppc_cpufreq] ... (trimming) Lets fix this by validating the region type, as well as whether access_width has a value. Then since we are returning bit_width directly for ACPI_ADR_SPACE_PLATFORM_COMM, drop the code correcting the size.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Unconditionally recompute CR8 intercept on PPR update The TPR_THRESHOLD field in the VMCS is used by VMX to induce VM exits when the guest's virtual TPR falls under the specified threshold, allowing KVM to inject previously masked interrupts. KVM handles these VM exits in handle_tpr_below_threshold(). Commit eb90f3417a0c ("KVM: vmx: speed up TPR below threshold vmexits") optimized this function by calling apic_update_ppr() instead of raising KVM_REQ_EVENT. apic_update_ppr() then raises KVM_REQ_EVENT if there is a pending, deliverable interrupt. However, if there are no new interrupts pending, apic_update_ppr() does not issue the request. Thus, kvm_lapic_update_cr8_intercept() and vmx_update_cr8_intercept() are not called before VM entry, which results in a high, stale TPR_THRESHOLD. This is problematic due to the following sentence in 28.2.1.1 "VM-Execution Control Fields" in the SDM: The following check is performed if the "use TPR shadow" VM-execution control is 1 and the "virtualize APIC accesses" and "virtual-interrupt delivery" VM-execution controls are both 0: the value of bits 3:0 of the TPR threshold VM-execution control field should not be greater than the value of bits 7:4 of VTPR. This error condition is typically not observed when KVM runs on a bare metal system because modern processors support APICv, which enables virtual-interrupt delivery, and which KVM uses when possible. This causes the processor to no longer generate TPR-below-threshold exits and to no longer check TPR_THRESHOLD on entry. However, when running on older platforms, or under nested virtualization on a hypervisor that does not support virtual-interrupt delivery and enforces this check (like Hyper-V) this can cause a VM entry failure with hardware error 0x7, as seen in [1]. Call kvm_lapic_update_cr8_intercept() if apic_update_ppr() does not find a deliverable interrupt (and thus does not raise KVM_REQ_EVENT). Remove calls to kvm_lapic_update_cr8_intercept() on paths that end up in apic_update_ppr(), as they now become redundant. This ensures that any path that updates the guest's PPR also figures out if KVM needs to wait for a TPR change (using TPR_THRESHOLD on VMX or CR8 intercepts on SVM).


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/smc: fix UAF in smc_cdc_rx_handler() by pinning the socket smc_cdc_rx_handler() looks up the connection by token under the link group's conns_lock, drops the lock, and then dereferences conn and the smc_sock derived from it, ending in sock_hold(&smc->sk) inside smc_cdc_msg_recv(). No reference is held across the lock release. The only reference pinning the socket while the connection is discoverable in the link group is taken in smc_lgr_register_conn() (sock_hold) and dropped in __smc_lgr_unregister_conn() (sock_put), both under conns_lock. Once the handler drops conns_lock, a concurrent close() -> smc_release() -> smc_conn_free() -> smc_lgr_unregister_conn() can drop that reference and free the smc_sock, so the handler's later sock_hold() runs on freed memory: WARNING: lib/refcount.c:25 at refcount_warn_saturate Workqueue: rxe_wq do_work refcount_warn_saturate (lib/refcount.c:25) smc_cdc_msg_recv (net/smc/smc_cdc.c:430) smc_cdc_rx_handler (net/smc/smc_cdc.c:502) smc_wr_rx_tasklet_fn (net/smc/smc_wr.c:445) tasklet_action_common (kernel/softirq.c:938) handle_softirqs (kernel/softirq.c:622) Kernel panic - not syncing: panic_on_warn set Only SMC-R is affected. The SMC-D receive tasklet is stopped by tasklet_kill(&conn->rx_tsklet) in smc_conn_free() before the connection is unregistered, so it cannot run concurrently with the free. Take the socket reference while still holding conns_lock, so the registration reference can no longer be the last one, and drop it once the handler is done.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: asymmetric_keys - fix OOB read in pefile_digest_pe_contents pefile_digest_pe_contents() computes the trailing-data hash length as pelen - (hashed_bytes + certs_size). A crafted PE can make the addition exceed pelen, causing the unsigned subtraction to underflow to ~4 GiB. This is passed to crypto_shash_update() which reads out of bounds and panics on unmapped vmalloc guard pages. BUG: unable to handle page fault for address: ffffc900038d8000 Oops: Oops: 0000 [#1] SMP KASAN NOPTI RIP: 0010:sha256_blocks_generic (lib/crypto/sha256.c:152) Call Trace: <TASK> __sha256_update (lib/crypto/sha256.c:208) crypto_sha256_update (crypto/sha256.c:142) verify_pefile_signature (crypto/asymmetric_keys/verify_pefile.c:436) kexec_kernel_verify_pe_sig (kernel/kexec_file.c:151) __do_sys_kexec_file_load (kernel/kexec_file.c:406) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) </TASK> Kernel panic - not syncing: Fatal exception Validate that the addition does not overflow and the result does not exceed pelen before the subtraction. Return -ELIBBAD on failure.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: usb: net1080: validate packet_len before pad-byte access in rx_fixup For an even packet_len, net1080_rx_fixup() reads the pad byte at skb->data[packet_len] before the skb->len != packet_len check further down, and packet_len is only bounded against NC_MAX_PACKET. A malicious NetChip 1080 device can send a short frame advertising a large even packet_len (e.g. 0x4000), so the pad-byte read lands past the end of the skb: BUG: KASAN: slab-out-of-bounds in net1080_rx_fixup Read of size 1 at addr ffff8880106c83c6 by task ksoftirqd/0/14 ... net1080_rx_fixup (drivers/net/usb/net1080.c:384) usbnet_bh (drivers/net/usb/usbnet.c:1589) process_one_work (kernel/workqueue.c:3322) bh_worker (kernel/workqueue.c:3708) tasklet_action (kernel/softirq.c:965) handle_softirqs (kernel/softirq.c:622) ... Reject the frame when packet_len >= skb->len before reading.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: sctp: validate STALE_COOKIE cause length before reading staleness When an ERROR chunk with a STALE_COOKIE cause is received in the COOKIE_ECHOED state, sctp_sf_do_5_2_6_stale() reads the 4-byte Measure of Staleness that follows the cause header: err = (struct sctp_errhdr *)(chunk->skb->data); stale = ntohl(*(__be32 *)((u8 *)err + sizeof(*err))); err is the first cause in the chunk, not the STALE_COOKIE cause that caused the dispatch, and nothing guarantees the staleness field is present. sctp_walk_errors() only requires a cause to be as long as the 4-byte header, so for a STALE_COOKIE cause of length 4 the read runs past the cause, and for a minimal ERROR chunk past skb->tail. The value is echoed to the peer in the Cookie Preservative of the reply INIT, leaking uninitialized memory. sctp_sf_cookie_echoed_err() already walks to the STALE_COOKIE cause, so check its length there and pass it to sctp_sf_do_5_2_6_stale(), which reads that cause instead of the first one. A STALE_COOKIE cause too short to hold the staleness field is discarded. The read is reachable by any peer that can drive an association into COOKIE_ECHOED, including an unprivileged process using a raw SCTP socket in a user and network namespace.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: psample: fix info leak in PSAMPLE_ATTR_DATA psample open codes nla_put() presumably to avoid wiping the data with 0s just to override it with packet data. This open coding is missing clearing the pad, however, each netlink attr is padded to 4B and data_len may not be divisible by 4B.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: nVMX: Hide shadow VMCS right after VMCLEAR free_nested() frees the shadow VMCS while vmcs01 still points to it. But because it is asynchronous with respect to loaded_vmcs_clear(), the vCPU might migrate before the pointer is cleared and __loaded_vmcs_clear() may then execute VMCLEAR. The VMCS needs to stay attached until its explicit VMCLEAR completes, but then it can be hidden and the page safely freed.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: btrfs: reject free space cache with more entries than pages When loading a v1 free space cache, __load_free_space_cache() takes num_entries and num_bitmaps straight from the on-disk btrfs_free_space_header. That header is stored in the tree_root under a key with type 0, which the tree-checker has no case for, so neither count is validated before the load trusts it. The load loops num_entries times and maps the next page whenever the current one runs out, going through io_ctl_check_crc() -> io_ctl_map_page(), which does io_ctl->pages[io_ctl->index++]. But pages[] is allocated in io_ctl_init() from the cache inode's i_size, not from num_entries: num_pages = DIV_ROUND_UP(i_size_read(inode), PAGE_SIZE); io_ctl->pages = kcalloc(num_pages, sizeof(struct page *), GFP_NOFS); So if num_entries claims more records than the pages can hold, io_ctl->index runs off the end of pages[]. The write side never hits this because io_ctl_add_entry() and io_ctl_add_bitmap() both stop once io_ctl->index >= io_ctl->num_pages; the read side just never had the same check. To trigger it, take a clean cache (num_entries = <N> here), set num_entries in the header to 0x10000, and fix up the leaf checksum so it still passes the tree-checker. The cache inode has i_size = 65536, so num_pages is 16 and pages[] is a 16-pointer (kmalloc-128) array. The load now tries to read 65536 entries, io_ctl->index walks up to 16, and pages[16] is read past the array: BUG: KASAN: slab-out-of-bounds in io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565) Read of size 8 at addr ffff88800c833a80 by task kworker/u8:3/58 io_ctl_check_crc (fs/btrfs/free-space-cache.c:420 fs/btrfs/free-space-cache.c:565) __load_free_space_cache (fs/btrfs/free-space-cache.c:655 fs/btrfs/free-space-cache.c:820) load_free_space_cache (fs/btrfs/free-space-cache.c:1017) caching_thread (fs/btrfs/block-group.c:880) btrfs_work_helper (fs/btrfs/async-thread.c:312) process_one_work worker_thread kthread ret_from_fork free-space-cache.c:420 is io_ctl_map_page(), inlined into io_ctl_check_crc() at line 565, which is why that is the frame KASAN names. The out-of-bounds slot is then treated as a struct page and handed to crc32c(), so the bad read turns into a GP fault. Add the missing check to io_ctl_check_crc(), which is where both the entry loop and the bitmap loop end up. When num_entries is too large the load now fails like any corrupt cache: __load_free_space_cache() drops it and rebuilds the free space from the extent tree, so a valid cache is never rejected.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfrm: fix sk_dst_cache double-free in xfrm_user_policy() xfrm_user_policy() clears the socket dst cache with __sk_dst_reset(), i.e. the non-atomic __sk_dst_set(sk, NULL): it reads sk_dst_cache with rcu_dereference_protected(), stores NULL and dst_release()s the old dst. That is only safe if no other thread modifies sk_dst_cache concurrently. For a connected UDP socket that does not hold: the transmit fast path (udp_sendmsg -> sk_dst_check -> sk_dst_reset) resets the cache locklessly with an atomic xchg(). A per-socket policy change racing a send can make both sides observe the same old dst and each dst_release() it, dropping the socket's single reference twice and freeing the xfrm_dst bundle while it is still referenced: BUG: KASAN: slab-use-after-free in dst_release Write of size 4 at addr ffff88801897b6c0 by task exploit/155 Call Trace: ... dst_release (... ./include/linux/rcuref.h:109) xfrm_user_policy (./include/net/sock.h:2239 ./include/net/sock.h:2256 net/xfrm/xfrm_state.c:3053) do_ip_setsockopt (net/ipv4/ip_sockglue.c:1347) ip_setsockopt (net/ipv4/ip_sockglue.c:1417) do_sock_setsockopt (net/socket.c:2368) __sys_setsockopt (net/socket.c:2393) __x64_sys_setsockopt (net/socket.c:2396) do_syscall_64 (arch/x86/entry/syscall_64.c:94) entry_SYSCALL_64_after_hwframe (arch/x86/entry/entry_64.S:121) Reachable by an unprivileged user via a user+network namespace. Use the atomic sk_dst_reset() so the cache is cleared and released with a single xchg(): whichever side wins releases the dst once, the other sees NULL and does nothing. Behaviour is otherwise unchanged.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix a use-after-free problem in rxe_mmap rxe_mmap() removes a rxe_mmap_info struct from the pending_mmaps list and releases pending_lock while the struct's kref is still at 1: list_del_init(&ip->pending_mmaps); spin_unlock_bh(&rxe->pending_lock); /* ref == 1, no lock held */ ret = remap_vmalloc_range(vma, ip->obj, 0); /* walks PTEs */ [...] rxe_vma_open(vma); /* kref_get, ref -> 2 */ remap_vmalloc_range_partial() walks PTEs without any lock. A concurrent DESTROY_CQ ioctl on another CPU calls: kref_put(&q->ip->ref, rxe_mmap_release) /* ref 1->0 */ vfree(ip->obj) /* clears vmalloc PTEs mid-walk */ kfree(ip) /* frees rxe_mmap_info */ This yields: 1. Kernel crash, vmalloc_to_page() returns NULL when vfree wins the per-PTE race -> vm_insert_page(NULL) -> GPF in validate_page_before_insert 2. Page UAF, vmalloc_to_page() reads a stale PTE before vfree clears it. User VMA holds a PTE to a free'd page which might eventually get reallocated later by vmalloc which allows the attacker to get a clean page-level UAF. It is worth noting that even though a page-level UAF is possible given the strong primitive, it is statistically very difficult to achieve given the very short time window (after the last insert_page and before the kref_get). The call trace are as below: Oops: general protection fault, probably for non-canonical address 0xdffffc0000000001: 0000 [#1] SMP KASAN NOPTI KASAN: null-ptr-deref in range [0x0000000000000008-0x000000000000000f] CPU: 0 UID: 1000 PID: 413 Comm: poc Not tainted 7.0.0-rc5-dirty #28 PREEMPT(lazy) Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014 RIP: 0010:validate_page_before_insert+0x32/0x300 Code: e5 41 57 41 56 49 89 fe 41 55 41 54 53 48 89 f3 e8 93 b5 a3 ff 48 8d 7b 08 48 b8 00 00 00 00 00 fc ff df 48 89 fa 48 c1 ea 03 <80> 3c 02 00 0f 85 7b 02 00 00 4c 8b 63 08 31 ff 4d 89 e5 41 83 e5 RSP: 0018:ffff88811b15f2f0 EFLAGS: 00000202 RAX: dffffc0000000000 RBX: 0000000000000000 RCX: 0000000000000000 RDX: 0000000000000001 RSI: 0000000000000000 RDI: 0000000000000008 RBP: ffff88811b15f318 R08: 0000000000000000 R09: 0000000000000000 R10: 0000000000000000 R11: 0000000000000000 R12: ffff8881181eee00 R13: 0000000000000000 R14: ffff8881181eee00 R15: ffff8881181eee20 FS: 00007b1e000f76c0(0000) GS:ffff8884268e0000(0000) knlGS:0000000000000000 CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033 CR2: 00007b1e00a24ac0 CR3: 0000000116eb3000 CR4: 00000000000006f0 Call Trace: <TASK> insert_page+0x8f/0x190 ? __pfx_insert_page+0x10/0x10 ? kasan_save_alloc_info+0x38/0x60 vm_insert_page+0x2e7/0x400 remap_vmalloc_range_partial+0x212/0x3e0 remap_vmalloc_range+0x6e/0xb0 ? __kasan_check_write+0x14/0x30 rxe_mmap+0x2e9/0x5d0 ib_uverbs_mmap+0x1ad/0x2c0 __mmap_region+0x12c2/0x2ad0 ? __pfx___mmap_region+0x10/0x10 ? __sanitizer_cov_trace_switch+0x58/0xb0 ? mas_prev_slot+0x360/0x39c0 ? __sanitizer_cov_trace_switch+0x58/0xb0 ? mas_next_slot+0x1e5b/0x2f40 ? __sanitizer_cov_trace_cmp8+0x18/0x30 ? unmapped_area_topdown+0x4dd/0x610 ? kfree+0x1b1/0x440 ? free_cpumask_var+0x16/0x30 ? __kasan_slab_free+0x7d/0xa0 ? __sanitizer_cov_trace_cmp8+0x18/0x30 mmap_region+0x2e6/0x3c0 do_mmap+0xa3e/0x12a0 ? __pfx_do_mmap+0x10/0x10 ? __kasan_check_write+0x14/0x30 ? down_write_killable+0xba/0x160 ? __pfx_down_write_killable+0x10/0x10 ? __sanitizer_cov_trace_cmp4+0x16/0x30 vm_mmap_pgoff+0x2d4/0x4a0 ? __pfx_vm_mmap_pgoff+0x10/0x10 ? fget+0x1bf/0x270 ksys_mmap_pgoff+0x40c/0x690 ? __sanitizer_cov_trace_const_cmp4+0x16/0x30 ? __pfx_ksys_mmap_pgoff+0x10/0x10 ? __kasan_check_write+0x14/0x30 ? _raw_spin_trylock+0xbb/0x130 ? __pfx__raw_spin_trylock+0x10/0x10 __x64_sys_mmap+0x135/0x1e0 x64_sys_c ---truncated---


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: libceph: fix two unsafe bare decodes in decode_lockers() decode_lockers() in cls_lock_client.c contains two bare decode operations that allow a malicious or compromised OSD to trigger slab-out-of-bounds reads: 1. ceph_decode_32(p) at the num_lockers field has no preceding bounds check. ceph_start_decoding() accepts struct_len=0 as valid -- the internal ceph_decode_need(p, end, 0, bad) always passes -- so when an OSD sends struct_len=0, ceph_start_decoding() returns success with p == end. The immediately following bare ceph_decode_32(p) then reads 4 bytes past the validated buffer boundary. The garbage value is passed directly to kzalloc_objs() as the locker count. The sibling function decode_watchers() in osd_client.c already uses ceph_decode_32_safe() after its own ceph_start_decoding() call. decode_lockers() was the only site using the bare variant. 2. ceph_decode_8(p) after the decode_locker() loop has no preceding bounds check. If an OSD crafts num_lockers such that the loop advances p exactly to end, the subsequent bare ceph_decode_8(p) reads one byte past the validated buffer boundary. The result is passed directly into *type, which is used as a lock type discriminator by callers, giving an OSD-controlled one-byte OOB read with direct influence over the lock type field. Fix both by replacing bare operations with their safe variants: ceph_decode_32(p) -> ceph_decode_32_safe(p, end, *num_lockers, err_inval) ceph_decode_8(p) -> ceph_decode_8_safe(p, end, *type, err_free_lockers) The goto targets differ intentionally: err_inval: is a new label returning -EINVAL directly. It is used for the pre-allocation failure path where *lockers is not yet allocated and must not be passed to ceph_free_lockers(). err_free_lockers: is the existing label. It is used for the post-allocation failure path where *lockers is allocated and must be freed. ret is set to -EINVAL before ceph_decode_8_safe() so that err_free_lockers returns the correct error code on bounds violation. Without this, err_free_lockers would return a stale ret value (0 from the successful decode_locker() loop), silently swallowing the error. -EINVAL is correct for both failure paths. The data received from the OSD is structurally malformed. -ENOMEM would misrepresent the failure class to callers and to stable@ backporters triaging error paths. Attacker model: a malicious or compromised OSD in a multi-tenant Ceph deployment can trigger this against any kernel client that issues the lock.get_info class method (e.g. during RBD exclusive lock acquisition). [ idryomov: trim changelog, formatting ]


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: SVM: Bump asid_generation on CPU online to avoid ASID collision after hotplug If a vCPU stays scheduled out (or blocked) while the last pCPU it ran on goes through a hotplug cycle (online->offline->online), and the vCPU then resumes execution on the same pCPU, then it is possible for it to run with an ASID that has now been assigned to a different vCPU, resulting in stale TLB translations being used. svm_enable_virtualization_cpu() resets asid_generation to 1 and sets next_asid to max_asid + 1 on every CPU online event, including hotplug cycles. Because next_asid starts beyond the pool boundary, the first call to new_asid() after an online event always wraps the pool, incrementing asid_generation to 2 and assigning ASIDs starting from min_asid. Consider two vCPUs from different VMs, vCPU-A pinned to CPU-X holding asid_generation=2 and ASID=N from before the hotplug event: 1. CPU-X goes offline and back online: asid_generation resets to 1, next_asid = max_asid + 1. 2. One or more vCPUs migrate to CPU-X and call new_asid(), wrapping the pool and consuming ASIDs starting from min_asid. Eventually vCPU-B from a different VM is assigned asid_generation=2, ASID=N - the same ASID that vCPU-A held before the hotplug. 3. vCPU-A enters pre_svm_run() on CPU-X: current_vmcb->cpu is unchanged so the migration branch is skipped. Its saved asid_generation=2 matches sd->asid_generation=2, so the generation check silently passes and vCPU-A continues running with ASID=N - the same ASID just freshly assigned to vCPU-B. Both vCPUs from different VMs now run on CPU-X with the same ASID, causing them to share NPT TLB entries and producing stale translations. The collision manifests as a KVM internal error (Suberror: 1, emulation failure). The NPT page fault reports a faulting GPA far outside the VM's physical memory range - a sign of stale TLB translations being used. KVM falls back to instruction emulation, which fails on FPU/XSave instructions (XRSTOR, STMXCSR) that the emulator does not implement. Fix this by incrementing asid_generation instead of resetting it to 1 in svm_enable_virtualization_cpu(). On module load, asid_generation starts at 0 (memset) and the increment produces 1, identical to the old behaviour. On subsequent hotplug cycles the generation advances beyond any value a vCPU previously observed on this CPU, so the generation check in pre_svm_run() reliably forces new_asid() on every vCPU after every hotplug cycle.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu/gfx9: replace BUG_ON() with WARN_ON() There's no need to crash the kernel for these cases. (cherry picked from commit b71604f8685b0eba07866f4e8dc30f93e1931054)


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: tipc: clear sock->sk on the failed-insert path in tipc_sk_create() When tipc_sk_create() fails to insert the new socket (tipc_sk_insert() returns non-zero), its error path frees the sk with sk_free() but leaves sock->sk pointing at the freed object: if (tipc_sk_insert(tsk)) { sk_free(sk); pr_warn("Socket create failed; port number exhausted\n"); return -EINVAL; } This is harmless for plain socket(): the syscall layer clears sock->ops before releasing, so tipc_release() is never called. It is not harmless on the accept() path. tipc_accept() creates the pre-allocated child socket with tipc_sk_create(net, new_sock, 0, kern); on failure it leaves new_sock->sk dangling and new_sock->ops non-NULL, and do_accept() then fput()s the new file, so __sock_release() -> tipc_release() runs lock_sock(new_sock->sk) on the freed sk -- a use-after-free write of the sk_lock spinlock. tipc_release() already guards this exact "failed accept() releases a pre-allocated child" case with "if (sk == NULL) return 0;", but the guard is bypassed because tipc_sk_create() left sock->sk non-NULL (dangling) rather than NULL. Clear sock->sk on the failed-insert path so the existing tipc_release() NULL check fires and the use-after-free is avoided. The tipc_sk_insert() failure is reached when the per-netns socket rhashtable hits its max_size (tsk_rht_params.max_size = 1048576, ~2M elements) -- i.e. once a netns holds ~2M TIPC sockets every insert returns -E2BIG. BUG: KASAN: slab-use-after-free in lock_sock_nested (net/core/sock.c:3839) Write of size 8 at addr ffff8880047cdc38 by task init/1 lock_sock_nested (net/core/sock.c:3839) tipc_release (net/tipc/socket.c:638) __sock_release (net/socket.c:710) sock_close (net/socket.c:1501) __fput (fs/file_table.c:512) Allocated by task 1: sk_alloc (net/core/sock.c:2308) tipc_sk_create (net/tipc/socket.c:487) tipc_accept (net/tipc/socket.c:2744) do_accept (net/socket.c:2034) Freed by task 1: __sk_destruct (net/core/sock.c:2391) tipc_sk_create (net/tipc/socket.c:504) tipc_accept (net/tipc/socket.c:2744) do_accept (net/socket.c:2034)


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: pppoe: reload header pointer after dev_hard_header() pppoe_sendmsg() saves a pointer to the PPPoE header before calling dev_hard_header(). Device header callbacks are allowed to reallocate the skb head, invalidating pointers into it. This can happen when a send is blocked in copy_from_user() while the first non-Ethernet port is added to an empty team device. The team's delegated GRE header callback then expands the skb head. PPPoE subsequently writes six bytes through the stale pointer into the freed head. Reload the PPPoE header through the skb's network-header offset after device header creation. pskb_expand_head() updates that offset when it relocates the head.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: openvswitch: fix GSO userspace truncation underflow OVS_ACTION_ATTR_TRUNC currently stores a delta from the original skb length in OVS_CB(skb)->cutlen. When a later userspace action segments a GSO skb, queue_gso_packets() reuses that delta for each smaller segment. A segment can then reach queue_userspace_packet() with cutlen greater than skb->len, underflowing the length passed to skb_zerocopy(). Store the maximum preserved length instead and bound each consumer against the current skb length. Use U32_MAX as the no-truncation sentinel so the value remains valid if skb geometry changes before a consumer handles it.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: gve: fix Rx queue stall on alloc failure When the system is under extreme memory pressure, page allocations can fail during the Rx buffer refill loop. If the number of buffers posted to hardware falls below a critical low threshold and the refill loop exits due to allocation failures, the queue can stall: 1. The device drops incoming packets because there are no descriptors. 2. Since no packets are processed, no Rx completions are generated. 3. Because no completions occur, NAPI is never scheduled, preventing the refill loop from running again even after memory is freed. This results in a permanent queue stall. Resolve this by introducing a starvation recovery timer for each Rx queue. If the number of buffers posted to hardware falls below a critical low threshold, start a timer to periodically reschedule NAPI. Once NAPI runs and successfully refills the queue above the threshold, the timer is not rescheduled. The threshold is set to 32 because a single maximum-sized Receive Segment Coalescing (RSC) packet can consume up to 19 descriptors in the Rx path. Lower thresholds (such as 8 or 16) would be insufficient to process a complete maximum-sized RSC packet, risking packet drops or unexpected hardware behavior under memory pressure. Setting the threshold to 32 guarantees a safe margin to handle at least one full RSC packet.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/af_iucv: fix NULL deref in afiucv_hs_callback_syn() afiucv_hs_callback_syn() allocates the child socket with GFP_ATOMIC. If the allocation fails, nsk is NULL. The connection-refused path is entered when the listen state check fails, the accept backlog is full, or nsk is NULL. The code unconditionally calls iucv_sock_kill(nsk) in that path. iucv_sock_kill() does not accept a NULL socket pointer and immediately dereferences sk via sock_flag(sk, SOCK_ZAPPED). When nsk is NULL, calling iucv_sock_kill(nsk) results in a NULL pointer dereference. Only call iucv_sock_kill() when a child socket was successfully allocated.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: slip: serialize receive against buffer reallocation sl_realloc_bufs() replaces rbuff and updates buffsize while holding sl->lock. slip_receive_buf() reads those fields and writes through rbuff without holding the lock. An MTU change can therefore race with receive processing. An MTU shrink can expose the new smaller rbuff with the old larger bound, causing an out-of-bounds write. A receive callback which already loaded the old rbuff can instead continue writing after that buffer has been freed. Serialize receive processing with sl_realloc_bufs() by holding sl->lock while consuming each receive batch.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: libceph: remove debugfs files before client teardown ceph_destroy_client() tears down the monitor client before removing the per-client debugfs files. A concurrent read of the monmap debugfs file can enter monmap_show() after ceph_monc_stop() has freed monc->monmap, triggering a use-after-free. Remove the debugfs files before stopping the OSD and monitor clients. debugfs_remove() drains active handlers and prevents new accesses, so the debugfs callbacks can no longer race the rest of client teardown.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: libceph: reject zero bucket types in crush_decode CRUSH bucket type 0 is reserved for devices. The mapper relies on that invariant and uses type 0 to identify leaf devices. If crush_decode() accepts a bucket with type 0, a malformed CRUSH map can make the mapper treat a negative bucket ID as a device and pass it to is_out(), which then indexes the OSD weight array with a negative value. Reject zero bucket types while decoding the CRUSH map so the invalid state never reaches the mapper.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: libceph: Reject monmaps advertising zero monitors A message of type CEPH_MSG_MON_MAP contains a monmap that is sent from a monitor to the client. This monmap contains information about the existing monitors in the cluster. Currently, a monmap indicating that there are zero monitors in the cluster is treated as valid. However, it is impossible to have zero monitors in the cluster and still receive a valid monmap from a monitor. Therefore, such a monmap must be corrupted and should be treated as invalid. Furthermore, a monmap with a monitor count of zero can subsequently crash the client when attempting to open a session with a monitor in __open_session(). This happens because the "BUG_ON(monc->monmap->num_mon < 1)" assertion in pick_new_mon() is triggered. This patch extends a check in ceph_monmap_decode() to also reject arriving mon_maps with num_mon == 0 rather than only with num_mon > CEPH_MAX_MON. [ idryomov: drop "log output for unusual values of num_mon" part ]


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: libceph: refresh auth->authorizer_buf{,_len} after authorizer update ceph_x_create_authorizer() caches au->buf->vec.iov_base and au->buf->vec.iov_len in struct ceph_auth_handshake. These cached values are then used by the messenger connect code when sending the authorizer. ceph_x_update_authorizer() can rebuild the authorizer when a newer service ticket is available. If the rebuilt authorizer no longer fits in the existing buffer, ceph_x_build_authorizer() drops its reference to au->buf and allocates a new one. If this is the final reference, ceph_buffer_put() frees the old ceph_buffer and its vec.iov_base, but auth->authorizer_buf still points at that freed memory. A subsequent msgr1 reconnect can therefore queue the stale pointer and trigger a KASAN slab-use-after-free in _copy_from_iter() while tcp_sendmsg() copies the authorizer. Refresh auth->authorizer_buf and auth->authorizer_buf_len after a successful authorizer rebuild so the messenger sends the current buffer.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: libceph: Fix multiplication overflow in decode_new_up_state_weight() If a message of type CEPH_MSG_OSD_MAP contains a (maliciously) corrupted osdmap, out-of-bounds memory accesses may occur in decode_new_up_state_weight(). This happens because the bounds check for the new_state part is based on calculating its length depending on a len value read from the incoming message. This calculation may overflow leading to an incorrect bounds check. Subsequently, out-of-bounds reads may occur when decoding this part. This patch switches the multiplication to use check_mul_overflow() to abort processing the osdmap if an overflow occurred. Therefore, osdmaps/messages containing large values for len that result in a multiplication overflow are treated as invalid. [ idryomov: rename new_state_len -> new_state_item_size, formatting ]


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: libceph: bound pg_{temp,upmap,upmap_items} length to CEPH_PG_MAX_SIZE __decode_pg_temp() decodes an user-controlled length but only rejects values large enough to overflow the allocation; it does not bound it to CEPH_PG_MAX_SIZE. The helper backs both pg_temp and pg_upmap decoding, and apply_upmap()/get_temp_osds() later copy the decoded list into the fixed-size on-stack array struct ceph_osds.osds[CEPH_PG_MAX_SIZE]. A monitor that sends an OSDMap with a pg_temp/pg_upmap entry longer than 32 thus causes a stack out-of-bounds write. An OSD set for a single PG can never exceed CEPH_PG_MAX_SIZE, so reject longer entries at decode time. The bound is well below the old overflow threshold, so it also covers the allocation-size overflow the previous check guarded against. BUG: KASAN: stack-out-of-bounds in ceph_pg_to_up_acting_osds Write of size 4 ... by task exploit kasan_report (mm/kasan/report.c:595) ceph_pg_to_up_acting_osds (net/ceph/osdmap.c:2617 net/ceph/osdmap.c:2833) calc_target (net/ceph/osd_client.c:1638) __submit_request (net/ceph/osd_client.c:2394) ceph_osdc_start_request (net/ceph/osd_client.c:2490) ceph_osdc_call (net/ceph/osd_client.c:5164) rbd_dev_image_probe (drivers/block/rbd.c:6899) do_rbd_add (drivers/block/rbd.c:7138) ... kernel BUG at net/ceph/osdmap.c:2670! [ idryomov: do the same in __decode_pg_upmap_items() ]


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: Fix session UAF in set_termios rfcomm_tty_set_termios() tests dlc->session without rfcomm_mutex and later passes the pointer to rfcomm_send_rpn(). The latter dereferences both session->initiator and session->sock. Meanwhile, krfcommd can unlink the DLC and free the session while holding rfcomm_mutex. The race can proceed as follows: TTY ioctl task krfcommd -------------- -------- load dlc->session enter rfcomm_send_rpn() lock rfcomm_mutex clear dlc->session free session unlock rfcomm_mutex read session->initiator KASAN reported: BUG: KASAN: slab-use-after-free in rfcomm_send_rpn+0x297/0x2a0 Read of size 4 at addr ffff88810012a850 by task poc/92 Call Trace: rfcomm_send_rpn+0x297/0x2a0 rfcomm_tty_set_termios+0x50d/0x850 tty_set_termios+0x596/0x950 set_termios+0x46a/0x6e0 tty_mode_ioctl+0x152/0xbd0 tty_ioctl+0x915/0x1240 __x64_sys_ioctl+0x134/0x1c0 Allocated by task 92: rfcomm_session_add+0x9e/0x2e0 rfcomm_dlc_open+0x8b1/0xe00 rfcomm_dev_activate+0x85/0x1a0 rfcomm_tty_open+0x90/0x280 Freed by task 68: kfree+0x131/0x3c0 rfcomm_session_del+0x119/0x180 rfcomm_run+0x737/0x4710 Add rfcomm_dlc_send_rpn(), which holds rfcomm_mutex while it verifies that the DLC is still attached and sends the RPN frame. Have the TTY path use the helper and drop its unlocked session check. This keeps the session valid through both the frame construction and socket send.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: fix NULL dereference when the AP has HT-cap but no HT-oper mwifiex_tdls_add_ht_oper() gates its follow-the-AP-bandwidth path on bss_desc->bcn_ht_cap being present, but then dereferences a different pointer, bss_desc->bcn_ht_oper: if (ISSUPP_CHANWIDTH40(priv->adapter->hw_dot_11n_dev_cap) && bss_desc->bcn_ht_cap && ISALLOWED_CHANWIDTH40(bss_desc->bcn_ht_oper->ht_param)) bcn_ht_cap and bcn_ht_oper are populated independently while parsing the associated AP's beacon in mwifiex_update_bss_desc_with_ie(): an AP that advertises an HT Capabilities element but no HT Operation element leaves bcn_ht_cap non-NULL and bcn_ht_oper NULL. Setting up a TDLS link to a peer while associated to such an AP then dereferences the NULL bcn_ht_oper and crashes the kernel. Every other bcn_ht_oper user in the driver NULL-checks it first. Guard on the pointer that is actually dereferenced. Found by 0sec automated security-research tooling (https://0sec.ai).


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: ath6kl: fix use-after-free in aggr_reset_state() The aggr_reset_state() function uses timer_delete() (non-synchronous) for the aggregation timer before proceeding to delete TID state and before the structure is freed by callers like aggr_module_destroy(). If the timer callback (aggr_timeout) is executing when aggr_reset_state() is called, the callback will continue to access aggr_conn fields like rx_tid[] and stat[] which may be freed immediately after by kfree(aggr_info->aggr_conn) in aggr_module_destroy(). Additionally, the timer callback can re-arm itself via mod_timer() while aggr_reset_state() is running, creating a more complex race condition. Use timer_delete_sync() instead to ensure any running timer callback has completed before returning.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: close a re-opened queue timer in the destructor queue_delete() closes the queue timer, then frees it. snd_seq_timer_close() clears q->timer->timeri. snd_use_lock_sync() then drains borrowers, and snd_seq_timer_delete() frees q->timer. A borrower can re-open the timer inside that window. A SET_QUEUE_CLIENT that took a queueptr() use_lock reference before the queue was unlinked runs snd_seq_timer_open() after the close. Open refuses re-open only while timeri is set, and the close just cleared it, so it re-opens timeri. snd_seq_timer_delete() does not close that instance. Its snd_seq_timer_stop() is a no-op, because running was cleared first. So it frees q->timer with the instance still live. The queue is freed next. The instance stays on the global timer with callback_data pointing at the freed queue. A non-owner START on the unlocked queue arms it. The next tick derefs the freed queue in snd_seq_timer_interrupt(). Reachable by an unprivileged user with access to /dev/snd/seq. No CAP and no queue ownership required. Close any lingering instance in the destructor. There, ->timeri can no longer change: the queue is unlinked and all use_lock borrowers have drained, so no snd_seq_queue_use() can re-open it. Close it before clearing q->timer. snd_timer_close() waits for any in-flight snd_seq_timer_interrupt() to finish, and that callback still reads q->timer (via snd_seq_check_queue()), so q->timer must stay valid until it drains.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: fix bo->pin leaking in amdgpu_bo_create_reserved amdgpu_bo_create_reserved() only allocates a new BO when *bo_ptr (struct amdgpu_bo **bo_ptr as input parameter) is NULL, it simply skips creation when *bo_ptr is non-NULL. But it unconditionally reserves, pins, gart allocates and maps the BO afterwards. When the same non-NULL BO pointer is passed in again, for example firmware buffers that live in adev and are re-loaded on every resume / cp_resume / start under AMDGPU_FW_LOAD_DIRECT, amdgpu_bo_pin() just increases pin_count unconditionally, however the matching teardown only unpins once, so pin_count never drops to zero, so TTM is not able to move, swap or evict a BO, causing BO leaks. This commit fixes this issue by only pinning the bo once at creation, and repeated calls no longer take additional pin references. (cherry picked from commit 3ddc0ae76202c447b6aec61e907b852bc94671cf)


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Release VFCT ACPI table reference amdgpu_acpi_vfct_bios() fetches the VFCT table with acpi_get_table() but never releases it. acpi_get_table() takes a reference on the table (incrementing its validation_count and mapping it on the 0->1 transition); without a paired acpi_put_table() the mapping is leaked on every call, whether or not a matching VBIOS image is found. Route all exit paths after the table is acquired through a common acpi_put_table(). The VBIOS image is copied out with kmemdup() before the table is released, so it remains valid for the caller. (cherry picked from commit ca5988682b4cba4cd125a0fa99b2de1239164ae4)


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/dp/mst: fix OOB reads on 2-byte fields in sideband reply parsers Three sideband reply parsers read 16-bit fields as: val = (raw->msg[idx] << 8) | (raw->msg[idx+1]); and check bounds only after the fact. When idx == raw->curlen, raw->msg[idx+1] reads one byte past the received message data into the following struct fields (curchunk_len, curchunk_idx, curlen). Affected functions: - drm_dp_sideband_parse_enum_path_resources_ack() full_payload_bw_number and avail_payload_bw_number fields - drm_dp_sideband_parse_allocate_payload_ack() allocated_pbn field - drm_dp_sideband_parse_query_payload_ack() allocated_pbn field Fix by using a single combined check (idx + 2 > curlen) before each 2-byte read. Since the check is strictly tighter than idx > curlen, no separate step is needed. [added fixes tag]


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/dp/mst: fix buffer overflows in sideband chunk accumulation drm_dp_sideband_append_payload() has three related bugs when processing device-provided sideband reply data: 1. Zero-length curchunk_len underflow: msg_len is a 6-bit field taken directly from the DP sideband header. If a device sends msg_len=0, curchunk_len is set to zero. The condition (curchunk_idx >= curchunk_len) is immediately true, and curchunk_len-1 wraps to 255 (u8 underflow). drm_dp_msg_data_crc4() reads 255 bytes from chunk[48], then memcpy() writes 255 bytes into msg[], both far out of bounds. 2. chunk[48] overflow: curchunk_len can reach 63 (6-bit field). chunk[] is only 48 bytes. Multi-iteration payload assembly appends 16-byte blocks until curchunk_idx reaches curchunk_len, writing up to 15 bytes past the end of chunk[] into msg[]. 3. msg[256] overflow: each chunk contributes (curchunk_len-1) bytes to msg[]. No check ensures curlen + (curchunk_len-1) stays within msg[256], so the memcpy can spill into adjacent struct fields. All three are reachable from any DP MST device that can forge sideband reply messages on a physical connection.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/dp/mst: fix OOB reads in remote DPCD/I2C sideband reply parsers drm_dp_sideband_parse_remote_dpcd_read() reads num_bytes from the raw message and then unconditionally does: memcpy(bytes, &raw->msg[idx], num_bytes); without checking that idx + num_bytes <= raw->curlen. raw->msg[] is 256 bytes; if a malicious or misbehaving MST hub sets num_bytes larger than the remaining payload, the memcpy reads past the received data into whatever follows in raw->msg[]. drm_dp_sideband_parse_remote_i2c_read_ack() has the same flaw (noted with a /* TODO check */ comment since the code was introduced). Fix both functions by using a single combined check (idx + num_bytes > curlen) before each memcpy. Since num_bytes is u8, it is always >= 0, so this strictly subsumes the simpler idx > curlen form and no separate step is needed. [added missing fixes tag]


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: bpf, sockmap: Fix cork use-after-free in tcp_bpf_sendmsg() tcp_bpf_sendmsg() keeps msg_tx across sk_stream_wait_memory(), which drops and reacquires the socket lock. Its error path tries to decide whether msg_tx names the local temporary message by comparing it with the current value of psock->cork. This comparison is unsafe when two threads send on the same socket: Thread A Thread B msg_tx = psock->cork sk_msg_alloc() fails sk_stream_wait_memory() releases the socket lock acquires the socket lock completes the cork psock->cork = NULL frees the cork reacquires the socket lock msg_tx != psock->cork sk_msg_free(msg_tx) The stale cork is therefore mistaken for the local temporary message and freed again. KASAN reported: BUG: KASAN: slab-use-after-free in sk_msg_free+0x49/0x50 Read of size 4 at addr ffff88810c908800 by task poc/90 Call Trace: sk_msg_free+0x49/0x50 tcp_bpf_sendmsg+0x14f5/0x1cc0 __sys_sendto+0x32c/0x3a0 __x64_sys_sendto+0xdb/0x1b0 Allocated by task 89: __kasan_kmalloc+0x8f/0xa0 tcp_bpf_sendmsg+0x16b3/0x1cc0 Freed by task 91: __kasan_slab_free+0x43/0x70 kfree+0x131/0x3c0 tcp_bpf_sendmsg+0xec3/0x1cc0 msg_tx can only name the stack-local tmp or the shared cork. Check for tmp directly so a changed psock->cork cannot turn a shared message into an apparent local one.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: tipc: fix integer overflow in tipc_recvmsg() and tipc_recvstream() In tipc_recvmsg(), the copy length is computed as: copy = min_t(int, dlen - offset, buflen); buflen is size_t but min_t(int, ...) casts it to int. When buflen exceeds INT_MAX (e.g. 0xFFFFFFFF via io_uring provided buffers), it wraps negative, wins the comparison, and the negative copy length propagates to simple_copy_to_iter() where int-to-size_t promotion makes it SIZE_MAX, triggering a WARN_ON. tipc_recvstream() has the same pattern. Kernel panic - not syncing: kernel: panic_on_warn set ... RIP: 0010:simple_copy_to_iter+0x9e/0xd0 (net/core/datagram.c:521) Call Trace: __skb_datagram_iter+0x123/0x8b0 (net/core/datagram.c:402) skb_copy_datagram_iter+0x77/0x1a0 (net/core/datagram.c:534) tipc_recvmsg+0x3d7/0xe80 (net/tipc/socket.c:1934) io_recvmsg+0x47e/0xda0 Fix by changing min_t(int, ...) to min_t(size_t, ...) in both functions. The result is always <= (dlen - offset), which is bounded by TIPC maximum message size (0x1ffff bytes), so the implicit narrowing on assignment to int copy is always safe.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: vmxnet3: fix BUG_ON in vmxnet3_get_hdr_len() for Geneve packets vmxnet3_get_hdr_len() assumes gdesc->rcd.v4/v6/tcp always describe the outer header, but for a Geneve-encapsulated packet the device can set them based on the inner header instead, signalled by the VMXNET3_RCD_HDR_INNER_SHIFT bit in the completion descriptor. Since the function never skips the outer encapsulation, this mismatch triggers: - BUG_ON(hdr.ipv4->protocol != IPPROTO_TCP), because the outer protocol is UDP (Geneve), not TCP. - BUG_ON(hdr.eth->h_proto != ...), when the tunnel's outer and inner IP versions differ (e.g. outer IPv6/inner IPv4 or vice versa). Check VMXNET3_RCD_HDR_INNER_SHIFT up front and bail out, since the function cannot locate the inner header it would need to parse. Also convert the remaining BUG_ON()s in this function to return 0 defensively.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: sctp: auth: verify auth requirement when auth_chunk is NULL sctp_auth_chunk_verify() returns true unconditionally when chunk->auth_chunk is NULL, silently skipping authentication. This is incorrect when: 1. skb_clone() failed in the BH receive path, leaving auth_chunk NULL. In sctp_endpoint_bh_rcv() asoc is NULL for new connections, so the early sctp_auth_recv_cid() check cannot catch this. 2. No AUTH chunk precedes COOKIE-ECHO, so skb_clone() is never called and auth_chunk remains NULL. Fix by checking sctp_auth_recv_cid() when auth_chunk is NULL: if authentication is required, return false to drop the chunk; otherwise continue normally.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: tipc: fix infinite loop in __tipc_nl_compat_dumpit cmd->dumpit callback can return a negative errno, causing an infinite loop due to the while(len) condition. As the loop never terminates, genl_mutex is never released, and other tasks waiting on it starve in D state. Check dumpit's return value, propagate it and jump to err_out on error.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: sctp: validate stream count in sctp_process_strreset_inreq() When processing a RESET_IN_REQUEST from a peer, sctp_process_strreset_inreq() derives the stream count from the parameter length but does not check whether the resulting RESET_OUT_REQUEST would exceed SCTP_MAX_CHUNK_LEN. The OUT request header (sctp_strreset_outreq, 16 bytes) is 8 bytes larger than the IN request header (sctp_strreset_inreq, 8 bytes). Generally, the IP payload is bounded to 65535 bytes, so the stream list cannot be large enough to trigger the overflow. However, on interfaces with MTU > 65535 (e.g., loopback with IPv6 jumbograms), a stream list that fits within the incoming IN parameter can cause a __u16 overflow in sctp_make_strreset_req() when computing the OUT request size, leading to an undersized skb allocation and a kernel BUG: net/core/skbuff.c:207 skb_panic net/core/skbuff.c:2625 skb_put net/sctp/sm_make_chunk.c:1535 sctp_addto_chunk net/sctp/sm_make_chunk.c:3695 sctp_make_strreset_req net/sctp/stream.c:655 sctp_process_strreset_inreq The local setsockopt path validates the generated reset request size. However, for an incoming-only reset, it accounts for the smaller IN request even though the peer must generate an OUT request with the same stream list. Such a request cannot be completed successfully by the peer. Reject peer IN requests whose corresponding OUT request would exceed SCTP_MAX_CHUNK_LEN. Also tighten the local check so it does not send an IN request that would require an oversized OUT request from the peer.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: sctp: fix auth_chunk_list capacity check in sctp_auth_ep_add_chunkid sctp_auth_ep_add_chunkid() uses SCTP_NUM_CHUNK_TYPES (20) as the capacity limit for ep->auth_chunk_list, allowing it to hold up to 20 chunk entries (param_hdr.length up to 24). However, the copy destination asoc->c.auth_chunks in struct sctp_cookie is only SCTP_AUTH_MAX_CHUNKS (16) entries (20 bytes). When more than 16 chunks are added, sctp_association_init() memcpy overflows the destination by up to 4 bytes. Fix by using SCTP_AUTH_MAX_CHUNKS as the capacity limit, matching the destination capacity.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Bound the early ACPI HID map The ivrs_acpihid command-line parser appends entries to a fixed four-element early_acpihid_map array. Unlike the sibling IOAPIC and HPET parsers, it does not reject a fifth entry before incrementing the map size. Check the capacity at the common found label before parsing the HID and UID or writing the entry.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: nfp: Check resource mutex allocation nfp_cpp_resource_find() allocates a CPP mutex handle for the matching resource-table entry and then reports success. nfp_resource_try_acquire() immediately passes that handle to nfp_cpp_mutex_trylock(). However, nfp_cpp_mutex_alloc() returns NULL on failure. If that happens for a matching table entry, the resource lookup still returns success and the following trylock dereferences a NULL mutex pointer while opening the resource. nfp_resource_acquire() already treats failure to allocate the table mutex as -ENOMEM. Do the same for the resource mutex and fail the lookup before publishing the rest of the resource handle. This issue was found by a static analysis checker and confirmed by manual source review.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: iommu/amd: Wait for completion instead of returning early in iommu_completion_wait() need_sync is a per-IOMMU flag shared by all domains and devices behind that IOMMU. It is set whenever a command is queued with sync == true and cleared when a completion-wait (CWAIT) command is queued. However, a cleared need_sync only means that a covering CWAIT has been queued, not that all previously queued commands have actually completed in hardware. iommu_completion_wait() read need_sync locklessly and returned early when it was false. This breaks the "block until all previously queued commands have completed" contract in a multi-CPU scenario: CPU2: queue inv-B => need_sync = true CPU1: queue CWAIT(N); need_sync = false; then wait_on_sem(N) CPU2: read need_sync == false => return 0 (no wait!) CPU2 returns without waiting for any sequence number even though its inv-B may not have completed yet (CWAIT(N), queued after inv-B, has not been signaled). CPU2 then proceeds to, for example, free page-table pages while the IOMMU can still walk stale translations, opening a use-after-free window. This is a logical race in the meaning of the flag, not a memory-visibility issue, so barriers alone do not help. Fix it without losing the optimization of avoiding redundant CWAIT commands: take iommu->lock before testing need_sync, and when it is false do not return early but wait for the last allocated sequence number (cmd_sem_val). Since need_sync == false implies no sync command was queued after the last CWAIT, that CWAIT is FIFO-ordered after every not-yet-completed command, so waiting for its sequence number guarantees all prior commands (possibly queued by another CPU) have completed. The common path with pending work is unchanged and no extra hardware command is issued.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/packet: avoid fanout hook re-registration after unregister packet_set_ring() temporarily detaches a socket from packet delivery while reconfiguring its ring. It records the previous running state, clears po->num, unregisters the protocol hook when needed, drops po->bind_lock, and later restores po->num and re-registers the hook from the saved was_running value. That unlocked window can race with NETDEV_UNREGISTER. The notifier can observe the socket as not running, skip __unregister_prot_hook(), and invalidate the per-socket binding by setting po->ifindex to -1 and clearing po->prot_hook.dev. A one-member fanout group can still retain its shared fanout hook device pointer. When packet_set_ring() resumes, re-registering solely from the stale was_running state can re-add the fanout hook after the device has been unregistered. Treat po->ifindex == -1 as an invalidated binding after reacquiring po->bind_lock. This is distinct from ifindex 0, the normal unbound/wildcard state: ifindex -1 marks an existing device binding that was invalidated when the device was unregistered. Restore po->num as before, but do not re-register the hook if device unregister already detached the socket.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: fix buffer overflow in rx_stream failover path The failover continuation in carl9170_rx_stream() copies the full tlen from the second USB transfer instead of capping at rx_failover_missing bytes. When both transfers are near maximum size, the total exceeds the 65535-byte failover SKB, triggering skb_over_panic. Limit the copy size to the missing byte count. [Fix checkpatch CHECK:PARENTHESIS_ALIGNMENT]


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: carl9170: bound memcpy length in cmd callback to prevent OOB read When the firmware sends a command response with a length mismatch, carl9170_cmd_callback() logs the mismatch and calls carl9170_restart() but then falls through to memcpy(ar->readbuf, buffer + 4, len - 4). Since len comes from the firmware and can exceed ar->readlen, this copies more data than the readbuf was allocated for. Bound the memcpy to min(len - 4, ar->readlen) so that the response is still completed -- avoiding repeated restarts from queued garbage -- while preventing an overread past the response buffer.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: watchdog: pretimeout: Fix UAF in watchdog_unregister_governor() When a watchdog governor is unregistered, it updates existing watchdog devices that were using this governor by falling back to `default_gov`. If the governor being unregistered is currently set as `default_gov`, the `default_gov` is never cleared. This leads to 2 use-after-free issues: 1. New watchdog devices registered after this point will inherit the dangling `default_gov`. 2. Existing watchdog devices using the unregistered governor will have their `wdd->gov` reassigned to the dangling `default_gov`. Fix the UAF by clearing `default_gov` if it matches the governor being unregistered.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: ath9k: hif_usb: don't dereference hif_dev after re-arming firmware request ath9k_hif_request_firmware() re-arms an asynchronous firmware load via request_firmware_nowait(), passing hif_dev as the completion context, and then still dereferences hif_dev: dev_info(&hif_dev->udev->dev, "ath9k_htc: Firmware %s requested\n", hif_dev->fw_name); The re-armed callback ath9k_hif_usb_firmware_cb() runs on the "events" workqueue and, when the firmware is missing, walks the retry chain into ath9k_hif_usb_firmware_fail() -> complete_all(&hif_dev->fw_done). That releases the wait_for_completion(&hif_dev->fw_done) in a concurrent ath9k_hif_usb_disconnect(), which then kfree()s hif_dev. The trailing dev_info() in the frame that re-armed the request can therefore read freed memory (hif_dev->udev, the first field of struct hif_device_usb): BUG: KASAN: slab-use-after-free in ath9k_hif_request_firmware Read of size 8 ... by task kworker/... ath9k_hif_request_firmware ath9k_hif_usb_firmware_cb drivers/net/wireless/ath/ath9k/hif_usb.c:1247 request_firmware_work_func Allocated by ...: ath9k_hif_usb_probe drivers/net/wireless/ath/ath9k/hif_usb.c Freed by ...: ath9k_hif_usb_disconnect -> kfree drivers/net/wireless/ath/ath9k/hif_usb.c The fw_done barrier only makes disconnect wait for the firmware chain to *terminate*; it does not protect the outer ath9k_hif_request_firmware() frame that re-armed the request and keeps touching hif_dev afterwards. Drop the post-request dev_info(): it is the only use of hif_dev after the async request is armed, and it is purely informational (the dev_err() on the failure path runs only when request_firmware_nowait() did not arm a callback, so hif_dev is still alive there). This was first reported by syzbot as a single, non-reproduced crash that was later auto-obsoleted, and was independently rediscovered by the reFuzz fuzzer, which produced a C reproducer (USB-gadget connect/disconnect of an ath9k_htc device whose firmware download fails). The vulnerable code is unchanged and still present in v7.1-rc6, where the slab-use-after-free reproduces under KASAN once the (sub-microsecond) race window is widened.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/iucv: take a reference on the socket found in afiucv_hs_rcv() afiucv_hs_rcv() looks up the destination socket under iucv_sk_list.lock, drops the lock, and then passes the socket to the afiucv_hs_callback_*() handlers without holding a reference. AF_IUCV sockets are not RCU-protected and are freed synchronously by iucv_sock_kill() -> sock_put(), so a concurrent close can free the socket in the window between read_unlock() and the handler, which then dereferences freed memory (for example sk->sk_data_ready() in afiucv_hs_callback_syn()). Take a reference with sock_hold() while the socket is still on the list and release it with sock_put() once the handler has run.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ppp: defer channel free to an RCU grace period to fix pppol2tp RX UAF pppol2tp_recv() runs in the L2TP UDP-encap softirq RX path: l2tp_udp_encap_recv() -> l2tp_recv_common() -> pppol2tp_recv() -> ppp_input(&po->chan) It runs under rcu_read_lock() holding only an l2tp_session reference and takes NO reference on the internal PPP channel (struct channel, chan->ppp) that ppp_input() dereferences. The pppox socket is SOCK_RCU_FREE, so 'po' and the embedded ppp_channel are RCU-safe. But the internal struct channel is a separate allocation that ppp_release_channel() frees with a plain kfree(): close(data socket) -> pppol2tp_release() -> pppox_unbind_sock() -> ppp_unregister_channel() -> ppp_release_channel() -> kfree(pch) For a channel that is bound (PPPIOCGCHAN) but not attached to a ppp unit (no PPPIOCCONNECT, pch->ppp == NULL) and not bridged, teardown skips both ppp_disconnect_channel()'s synchronize_net() and ppp_unbridge_channels()'s synchronize_rcu(), so the kfree() has no grace period. rcu_read_lock() in pppol2tp_recv() does not protect against a plain kfree(), so an in-flight ppp_input() on one CPU can dereference the channel just freed by close() on another CPU. The bug is reachable by an unprivileged user. Defer the channel free to an RCU callback via call_rcu() so the grace period fences any in-flight ppp_input(). The disconnect and unbridge teardown paths already fence with synchronize_net()/synchronize_rcu(); call_rcu() does the same here without stalling the close() path.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: mac80211: free AP_VLAN bc_buf SKBs outside IRQ lock ieee80211_do_stop() removes AP_VLAN packets from the parent AP ps->bc_buf while holding ps->bc_buf.lock with IRQs disabled. It then calls ieee80211_free_txskb() before dropping the lock. ieee80211_free_txskb() is not just a passive SKB release. For SKBs with TX status state it can report a dropped frame through cfg80211/nl80211, and that path can reach netlink tap transmit. This is the same reason the pending queue cleanup in ieee80211_do_stop() already unlinks SKBs under the queue lock and frees them after IRQ state is restored. The buggy scenario involves two paths, with each column showing the order within that path: AP_VLAN management TX: AP_VLAN stop: 1. attach ACK-status state 1. clear the running state 2. queue a multicast SKB on 2. take ps->bc_buf.lock with IRQs parent ps->bc_buf disabled 3. unlink the AP_VLAN SKB 4. call ieee80211_free_txskb() Unlink matching AP_VLAN SKBs from ps->bc_buf under the existing lock, but move them to a local free queue. Drop the lock and restore IRQ state before calling ieee80211_free_txskb(). WARNING: kernel/softirq.c:430 at __local_bh_enable_ip


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: libertas: fix memory leak in helper_firmware_cb() helper_firmware_cb() neglects to free the single-stage firmware image after a successful async load, leading to a memory leak in the USB firmware-download path. Fix this memory leak by calling release_firmware() immediately after lbs_fw_loaded() returns. The bug was first flagged by an experimental analysis tool we are developing for kernel memory-management bugs while analyzing v6.13-rc1. The tool is still under development and is not yet publicly available. Manual inspection confirms that the bug is still present in the current wireless tree. An x86_64 allyesconfig build showed no new warnings. As we do not have compatible Libertas USB hardware for exercising this firmware-download path, no runtime testing was able to be performed.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: IB/mad: Drop unmatched RMPP responses before reassembly Kernel-handled RMPP receive processing starts reassembly for active DATA responses before the response is matched to an outstanding send. The normal match happens later, after ib_process_rmpp_recv_wc() has either assembled a complete message or consumed the segment. That ordering lets an unsolicited response that routes to a kernel RMPP agent by the high TID bits allocate or extend RMPP receive state before the full TID and source address are checked against a real request. A reordered burst can therefore reach the receive-side insertion path even though the response would not match any send. For kernel-handled RMPP DATA responses, require the existing ib_find_send_mad() match before entering RMPP reassembly. The matcher already checks the full TID, management class and source address/GID against the agent wait, backlog and in-flight send lists. If there is no match, drop the response without creating RMPP state. This leaves the RMPP window behavior unchanged and only rejects responses that have no corresponding request.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfrm: fix stale skb->prev after async crypto steals a GSO segment skb_gso_segment() leaves the segment list head with ->prev pointing at the last segment, an invariant validate_xmit_skb_list() relies on when it sets its tail pointer (tail = skb->prev). When validate_xmit_xfrm() walks a GSO list and some segments are stolen by async crypto (->xmit() returns -EINPROGRESS), those segments are unlinked from the list but the head ->prev is never updated. If the last segment is the one stolen, the returned head still has ->prev pointing at it, even though it is now owned by the crypto engine and may be freed. validate_xmit_skb_list() later does tail->next = skb, writing through that stale pointer -- a use-after-free. Repoint skb->prev at the last retained segment before returning.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: x86/mmu: Fix use-after-free on vendor module reload mmu_destroy_caches() destroys pte_list_desc_cache and mmu_page_header_cache, but leaves both pointers unchanged. The pointers live in kvm.ko, and therefore survive when a vendor module is unloaded while kvm.ko remains loaded. If creation of pte_list_desc_cache fails during a subsequent vendor module load, its assignment sets pte_list_desc_cache to NULL and the error path calls mmu_destroy_caches(). mmu_page_header_cache still points to the cache destroyed during the preceding vendor module unload. Passing that stale pointer to kmem_cache_destroy() causes a slab use-after-free. Reproduce the issue on a v7.1.3 kernel with CONFIG_KASAN=y, CONFIG_KASAN_GENERIC=y, CONFIG_KVM=m, and CONFIG_KVM_INTEL=m. A one-shot test hook forces pte_list_desc_cache to NULL on the second invocation of kvm_mmu_vendor_module_init(): 1. Load kvm.ko and kvm-intel.ko, creating both caches. 2. Unload only kvm_intel, leaving kvm.ko loaded. 3. Reload kvm_intel and force initialization through the -ENOMEM path. KASAN reports: BUG: KASAN: slab-use-after-free in kvm_mmu_vendor_module_init+0x5b/0x170 [kvm] ... kmem_cache_destroy+0x21/0x1d0 kvm_mmu_vendor_module_init+0x5b/0x170 [kvm] ... Allocated by task 16817: __kmem_cache_create_args+0x12c/0x3b0 __kmem_cache_create.constprop.0+0xb6/0xf0 [kvm] kvm_mmu_vendor_module_init+0x13b/0x170 [kvm] ... Freed by task 16820: kmem_cache_destroy+0x117/0x1d0 kvm_mmu_vendor_module_exit+0x21/0x30 [kvm] Clear both pointers immediately after destroying their caches so that the stored state reflects the caches' lifetime and repeated cleanup is safe. With the fix applied, the same injected vendor module reload fails with -ENOMEM as expected and produces no KASAN report.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: vxlan: require CAP_NET_ADMIN in the device netns for changelink A tunnel changelink() operates on at most two netns, dev_net(dev) and the sticky underlay netns vxlan->net. They differ once the device is created in or moved to a netns other than the one the request runs in. The rtnl changelink path checks CAP_NET_ADMIN only against dev_net(dev), so a caller privileged there but not in vxlan->net can rewrite a vxlan device whose underlay lives in vxlan->net. vxlan_changelink() validates and applies the new configuration against vxlan->net (vxlan_config_validate(vxlan->net, ...)) and can reopen the underlay socket in that netns, so the same reasoning as the tunnel changelink series applies here. Gate vxlan_changelink() with rtnl_dev_link_net_capable(), at the top of the op before any attribute is parsed, matching ipgre_changelink() and the rest of the "require CAP_NET_ADMIN in the device netns for changelink" series. Found by 0sec automated security-research tooling (https://0sec.ai).


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: libceph: bound get_version reply decode to front len handle_get_version_reply() uses msg->front_alloc_len as the decode boundary for MON_GET_VERSION_REPLY. That is the size of the reused reply buffer, not the number of bytes actually received. A truncated reply can therefore pass ceph_decode_need() and decode the second u64 from stale tail bytes left in the buffer by an earlier message, causing an uninitialized memory read. Use msg->front.iov_len as the receive-side decode boundary, matching other libceph reply handlers and limiting decoding to the bytes that were actually read from the wire.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: btrfs: free mapping node on duplicate reloc root insert __add_reloc_root() allocates a mapping_node before inserting it into rc->reloc_root_tree. If rb_simple_insert() finds an existing entry, it returns the existing rb_node and leaves the newly allocated node unlinked. The error path then returns -EEXIST without freeing the new node. Since the node was never inserted into reloc_root_tree, the later cleanup in put_reloc_control() cannot find it either. Free the newly allocated node before returning -EEXIST. The callers currently assert that -EEXIST should not happen, so this is a defensive cleanup for an unexpected duplicate insert path. If the path is ever reached, the local allocation should still be released.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: x86/bugs: Make Safe-RET robust against interrupt injection An attacker injecting interrupts while the Safe-RET mitigation executes on machines affected by SRSO can neutralize the safe return sequence, potentially leading to data leakage through speculative execution. Fixup register state as if the Safe-RET sequence executed successfully by "emulating" it, in a manner of speaking, and avoid executing a RET instruction after returning from the interrupt.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: macb: drop in-flight Tx SKBs on close The MACB driver has since forever leaked the outgoing SKBs that have not yet been marked as completed. They live in queue->tx_skb which gets freed without remorse nor checking. macb_free_consistent() gets called in a few codepaths, but only close will trigger the added expressions. In macb_open() and macb_alloc_consistent() failure cases, queues' tx_skb just got allocated and are empty.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipvs: reset full ip_vs_seq structs in ip_vs_conn_new Commit 9a05475cebdd ("ipvs: avoid kmem_cache_zalloc in ip_vs_conn_new") changed ip_vs_conn_new() to allocate an ip_vs_conn object with kmem_cache_alloc(). The function then initializes many fields explicitly, but only resets in_seq.delta and out_seq.delta in the two struct ip_vs_seq members. That leaves init_seq and previous_delta uninitialized. This is normally harmless while the corresponding IP_VS_CONN_F_IN_SEQ or IP_VS_CONN_F_OUT_SEQ flag is clear. For connections learned from a sync message, however, ip_vs_proc_conn() preserves those flags from IP_VS_CONN_F_BACKUP_MASK and passes opt=NULL when the message omits IPVS_OPT_SEQ_DATA. In that case the new connection can be hashed with SEQ flags set but with the rest of in_seq/out_seq still containing stale slab data. When a packet for such a connection is later handled by an IPVS application helper, vs_fix_seq() and vs_fix_ack_seq() use previous_delta and init_seq to rewrite TCP sequence numbers. A malformed sync message can therefore make forwarded packets carry stale slab bytes in their TCP seq/ack numbers, and can also corrupt the forwarded TCP flow. Reset both struct ip_vs_seq members completely before publishing the connection. This matches the existing "reset struct ip_vs_seq" comment and keeps the sequence-adjustment gates inactive unless valid sequence data is installed later.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_multiq: Replace direct dequeue call with peek and qdisc_dequeue_peeked multiq_dequeue() takes a packet from a band's child with a direct ->dequeue() call after multiq_peek() peeked it. When the child is non-work-conserving the peek stashes the skb in the child's gso_skb, so the direct dequeue returns a different skb and orphans the stash, desyncing the child's qlen/backlog. With a qfq child reached through a peeking parent (e.g. tbf) this re-enters the child on an emptied list and dereferences NULL, panicking the kernel from softirq on ordinary egress. Take the packet through qdisc_dequeue_peeked(), as sch_prio already does and as sch_red and sch_sfb were just fixed to do. The helper is a no-op when the child has no stash, so a work-conserving child is unaffected.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: scsi: target: core: Fix iSCSI ISID use-after-free in REGISTER AND MOVE core_scsi3_emulate_pro_register_and_move() maps the PERSISTENT RESERVE OUT parameter list with transport_kmap_data_sg() and parses the destination TransportID with target_parse_pr_out_transport_id(). For an iSCSI TransportID (FORMAT CODE 01b), iscsi_parse_pr_out_transport_id() returns the ISID in iport_ptr as a raw pointer into that mapped buffer. The function then unmaps the buffer with transport_kunmap_data_sg() before dereferencing iport_ptr in strcmp(), __core_scsi3_locate_pr_reg() and core_scsi3_alloc_registration(). When the parameter list spans more than one page (PARAMETER LIST LENGTH > 4096), transport_kmap_data_sg() uses vmap() and transport_kunmap_data_sg() does vunmap(), so the kernel virtual address backing iport_ptr is torn down and every subsequent dereference is a use-after-free read of the unmapped region. Keep the parameter list mapped until iport_ptr is no longer needed: drop the early transport_kunmap_data_sg() and unmap once on the success path, right before returning. The error paths already unmap through the existing "if (buf) transport_kunmap_data_sg(cmd)" at the out: label, which now runs on every post-map error exit because buf is no longer cleared early. Only reads of the mapping happen while spinlocks are held; the map and unmap calls remain outside any lock. The sibling caller core_scsi3_decode_spec_i_port() already uses the buffer before unmapping it and is left unchanged.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: scsi: target: Bound PR-OUT TransportID parsing to the received buffer core_scsi3_decode_spec_i_port() and core_scsi3_emulate_register_and_move() hand the raw PERSISTENT RESERVE OUT parameter buffer to target_parse_pr_out_transport_id() without telling it how many bytes are valid. For an iSCSI TransportID (FORMAT CODE 01b), iscsi_parse_pr_out_transport_id() locates the ",i,0x" ISID separator with an unbounded strstr() (and on the error path prints the name with a further unbounded "%s"). An initiator can submit a TransportID whose iSCSI name contains neither a ",i,0x" substring nor a NUL terminator, filling the parameter list to its end, so the scan runs off the end of the buffer. When the parameter list spans more than one page the buffer is a multi-page vmap (transport_kmap_data_sg()), so the over-read walks into the trailing vmalloc guard page and oopses (KASAN: vmalloc-out-of-bounds in strstr). It is reachable by any fabric that delivers a PR OUT to a device exported through an iSCSI TPG, including a guest via vhost-scsi. Pass the number of received bytes down to the parser and validate the iSCSI TransportID's own self-described length (ADDITIONAL LENGTH + 4) once, up front: reject it if it is below the spc4r17 minimum or larger than the received buffer, then bound the separator search, the ISID walk and the name copy by that length. This is the length check the callers already perform after the parse (core_scsi3_decode_spec_i_port() compares tid_len against tpdl, core_scsi3_emulate_register_and_move() validates it against data_length), moved ahead of the scan. Also drop the unbounded "%s" of the unterminated name. Add per-format explicit name-length checks before copying into i_str, rather than silently truncating with min_t: for FORMAT CODE 00b reject if the descriptor body (tid_len - 4 bytes) cannot fit in i_str[TRANSPORT_IQN_LEN]; for FORMAT CODE 01b reject if the name portion (from &buf[4] up to the separator) cannot fit. Both checks make the bounds intent explicit at each format branch. While here, also reject a FORMAT CODE 01b TransportID whose ",i,0x" separator sits at the very end of the descriptor: that leaves an empty ISID and points the returned port nexus pointer at buf + tid_len, one past the descriptor, which the registration code (__core_scsi3_locate_pr_reg(), __core_scsi3_alloc_registration()) then dereferences as the ISID string -- the same over-read of the parameter buffer for a malformed descriptor.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: scsi: xen: scsiback: Free the command tag on the TMR submit-failure path scsiback_device_action() obtains a command tag in scsiback_get_pend_req() and submits a task-management request with target_submit_tmr(). When target_submit_tmr() fails it returns < 0 and scsiback jumps to the err: label, which sends a response but frees nothing, leaking the tag. Impact: a pvSCSI guest can leak the command tags of a LUN's session, stopping the LUN, by issuing VSCSIIF_ACT_SCSI_ABORT or RESET requests whenever target_submit_tmr() fails. transport_generic_free_cmd() cannot be used here. By the time target_submit_tmr() returns an error it has already run __target_init_cmd() (so se_cmd->cmd_kref is one, not zero), and on its target_get_sess_cmd() error path it has freed se_cmd->se_tmr_req via core_tmr_release_req() while leaving SCF_SCSI_TMR_CDB set and the pointer dangling. Letting the command release run target_free_cmd_mem() would then double-free se_tmr_req. Use the same helper, which returns just the tag, on this path too.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: dm thin metadata: fix metadata snapshot consistency on commit failure __reserve_metadata_snap() and __release_metadata_snap() modify the superblock's held_root directly in the block_manager's buffer. If the subsequent metadata commit fails, the held_root gets flushed to disk through the abort_transaction path, resulting in inconsistent metadata. Reproducer 1: __reserve_metadata_snap() 1. Create a 2 MiB metadata device and make the region after the 14th block inaccessible, to trigger metadata commit failure in the subsequent reserve_metadata_snap operation. The 14th block will be the shadow destination for the index block. dmsetup create tmeta --table "0 112 linear /dev/sdc 0 112 3984 error" 2. Create a 16 MiB thin-pool dmsetup create tdata --table "0 32768 zero" dd if=/dev/zero of=/dev/mapper/tmeta bs=4k count=1 dmsetup create tpool --table "0 32768 thin-pool /dev/mapper/tmeta \ /dev/mapper/tdata 128 0 1 skip_block_zeroing" 3. Take a metadata snapshot to trigger metadata commit failure and transaction abort. However, the held_root is written to disk, breaking metadata consistency. dmsetup message tpool 0 "reserve_metadata_snap" thin_check v1.2.2 result: Bad reference count for metadata block 6. Expected 2, but space map contains 1. Bad reference count for metadata block 7. Expected 2, but space map contains 1. Bad reference count for metadata block 13. Expected 1, but space map contains 0. Reproducer 2: __release_metadata_snap() 1. Create a 2 MiB metadata device and make the region after the 16th block inaccessible, to trigger metadata commit failure in the subsequent release_metadata_snap operation. The 16th block will be the shadow destination for the index block. dmsetup create tmeta --table "0 128 linear /dev/sdc 0 128 3968 error" 2. Create a 16 MiB thin-pool dmsetup create tdata --table "0 32768 zero" dd if=/dev/zero of=/dev/mapper/tmeta bs=4k count=1 dmsetup create tpool --table "0 32768 thin-pool /dev/mapper/tmeta \ /dev/mapper/tdata 128 0 1 skip_block_zeroing" 3. Reserve then release the metadata snapshot, to trigger metadata commit failure and transaction abort. The held_root gets removed from the on-disk superblock, causing inconsistent metadata. dmsetup message tpool 0 "reserve_metadata_snap" dmsetup message tpool 0 "release_metadata_snap" thin_check v1.2.2 result: Bad reference count for metadata block 6. Expected 1, but space map contains 2. Bad reference count for metadata block 7. Expected 1, but space map contains 2. 1 metadata blocks have leaked. Fix by deferring the held_root update to commit time. Additionally, move the existing-snapshot check in __reserve_metadata_snap before the shadow operation to avoid unnecessary work. In __release_metadata_snap, clear pmd->held_root before btree deletion so partial failure leaks blocks rather than leaving a stale reference, and unlock the snapshot block before decrementing its refcount.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: tpm: Make the TPM character devices non-seekable The TPM character devices expose a sequential command/response interface, but their open handlers leave FMODE_PREAD and FMODE_PWRITE enabled. After a command leaves a response pending, pread(fd, buf, 16, 0x1400) passes 0x1400 as *off to tpm_common_read(). The transfer length is bounded by response_length, but the offset is used unchecked when forming data_buffer + *off. A sufficiently large offset therefore causes an out-of-bounds heap read through copy_to_user() and, if the copy succeeds, an out-of-bounds zero-write through the following memset(). Positional I/O does not provide coherent semantics for this interface. An arbitrary pread offset cannot represent how much of a response has been consumed sequentially. The write callback always stores a command at the start of data_buffer, while pwrite() does not update file->f_pos and can leave the sequential read cursor stale. Call nonseekable_open() from both open handlers. This removes FMODE_PREAD and FMODE_PWRITE, causing positional reads and writes to fail with -ESPIPE before reaching the TPM callbacks, and explicitly marks the files non-seekable. Normal read() and write() continue to use the existing sequential f_pos cursor, leaving the response state machine unchanged. Tested on Linux 6.12 with KASAN and a swtpm TPM2 device: - sequential partial reads returned the complete response - pread() and preadv() with offset 0x1400 returned -ESPIPE - pwrite() and pwritev() with offset zero returned -ESPIPE - the pending response remained intact after the rejected operations - a subsequent normal command/response cycle completed normally - no KASAN report was produced.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xen/gntdev: fix error handling in ioctl When gntdev_ioctl_map_grant_ref() fails to copy the operation result back to userspace after successfully adding the mapping to the list, the error path returns -EFAULT without releasing the reference acquired by gntdev_alloc_map(). The mapping remains in priv->maps with a refcount of 1, causing a memory leak and a dangling list entry. Additionally, gntdev_add_map() may modify map->index to avoid overlap with existing mappings. Therefore, the index returned to userspace must be obtained after gntdev_add_map() completes. Fix this by holding the mutex across gntdev_add_map(), retrieving the correct index, and copy_to_user(). If copy_to_user() fails, remove the mapping from the list and release the reference while still holding the lock. Fix these issues by properly handling all error cases.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: i2c: imx: fix locked bus on SMBus block-read of 0 (atomic) SMBus 3.1 6.5.7 allows a Block Read byte count of 0, but the atomic (polling) path rejects it as -EPROTO. Worse, it returns without a NACK+STOP: the next receive cycle has already started, so the target keeps holding SDA and the bus stays stuck until a power cycle for this i2c controller. Reading I2DR to obtain the count likewise arms the next byte on the count > I2C_SMBUS_BLOCK_MAX path, which also returned -EPROTO directly and left the bus held. Handle both: NACK the in-flight dummy byte (TXAK) and extend msgs->len so the existing last-byte handling emits STOP; the dummy byte is discarded. A count of 0 is a valid empty block read; a count above I2C_SMBUS_BLOCK_MAX is still reported as -EPROTO, but only after the bus has been released. The interrupt-driven path has the same flaw from a later commit and is fixed separately, as it carries a different Fixes: tag and stable range.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ocfs2: avoid moving extents to occupied clusters For non-auto OCFS2_IOC_MOVE_EXT operations, userspace supplies a physical me_goal. ocfs2_move_extent() initializes new_phys_cpos from that goal and expects ocfs2_probe_alloc_group() to replace it with a free run in the target block group. The probe currently leaves *phys_cpos unchanged if the scan reaches the end of the group without finding a free run. An occupied goal at the last bit can therefore survive the probe and be passed to __ocfs2_move_extent(), which copies file data into a cluster still owned by another inode before the bitmap is updated. When the probe does find a free run, it also subtracts move_len from the ending bit. The start of an N-bit run ending at i is i - N + 1, so the current calculation can report the bit immediately before the free run. Clear *phys_cpos before scanning and use the correct free-run start. Callers already treat a zero result as -ENOSPC, so failed probes no longer continue with an occupied caller-controlled goal.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_nat_sip: reload possible stale data pointer quoting sashiko: ------------------------------------------------------------------------ [..] noticed a potential memory bug and header corruption involving the SIP NAT helper. In net/netfilter/nf_nat_sip.c:nf_nat_sip(): if (skb_ensure_writable(skb, skb->len)) { nf_ct_helper_log(skb, ct, "cannot mangle packet"); return NF_DROP; } uh = (void *)skb->data + protoff; uh->dest = ct_sip_info->forced_dport; if (!nf_nat_mangle_udp_packet(skb, ct, ctinfo, protoff, 0, 0, NULL, 0)) { If a cloned or fragmented SKB is reallocated by skb_ensure_writable(), the old data buffer is freed. However, nf_nat_sip() fails to update *dptr to point to the new buffer. It also appears to use nf_nat_mangle_udp_packet() on what could be a TCP packet, which would overwrite the sequence number with a checksum update. ------------------------------------------------------------------------ nf_conntrack_sip linerizes skbs, hence no fragmented skb can be seen. But clones are possible, so rebuild dptr. Disable nf_nat_mangle_udp_packet() branch for TCP streams. It doesn't look like this can ever happen, else we should have received bug reports about this, so just check the conntrack is UDP and drop otherwise. The calling conntrack_sip set ->forced_dport for SIP_HDR_VIA_UDP messages, so I don't think this is ever expected to be true for a TCP stream.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: Move kvm_io_bus_get_dev() locking responsibilities to callers kvm_io_bus_get_dev() returns a device that is only matched by the address, and nothing else. This can cause a lifetime issue if the matched device is not the expected type, as by the time the caller can introspect the object, it might be gone (the srcu lock having been dropped). Given that there is only a single user of this helper, the simplest option is to move the locking responsibility to the caller, which can keep the srcu lock held for as long as it wants. Note that this aligns with other kvm_io_bus*() helpers, which already require the srcu lock to be held by the callers.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: KVM: x86: Ignore pending PV EOI if the vCPU has since disabled PV EOIs Ignore KVM's internal "service pending PV EOI" request if the vCPU has disabled PV EOIs since the request was made. Asserting that PV EOIs are enabled can fail if reading guest memory in pv_eoi_get_user() fails, i.e. if pv_eoi_test_and_clr_pending() bails early, *and* the vCPU also disables PV EOIs. kernel BUG at arch/x86/kvm/lapic.c:3338! Oops: invalid opcode: 0000 [#1] SMP CPU: 4 UID: 1000 PID: 890 Comm: pv_eoi_test Not tainted 7.0.0-d585aa5894d8-vm #337 PREEMPT Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 0.0.0 02/06/2015 RIP: 0010:kvm_lapic_sync_from_vapic+0x12b/0x140 [kvm] Call Trace: <TASK> kvm_arch_vcpu_ioctl_run+0x1075/0x1c30 [kvm] kvm_vcpu_ioctl+0x2d5/0x980 [kvm] __x64_sys_ioctl+0x8a/0xd0 do_syscall_64+0xb5/0xb40 entry_SYSCALL_64_after_hwframe+0x4b/0x53 </TASK> Modules linked in: kvm_intel kvm irqbypass ---[ end trace 0000000000000000 ]---


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: ife: require ETH_HLEN to be pullable in ife_decode() ife decode may return after making only the outer IFE header and metadata pullable. The caller then passes the decapsulated packet to eth_type_trans(), which expects the inner Ethernet header to be accessible from the linear data area. With a malformed IFE frame, the inner Ethernet header may still be shorter than ETH_HLEN in the linear area, which can lead to a crash in the original code. Fix this by extending the pull check in ife_decode() so that the inner Ethernet header is also guaranteed to be pullable before returning.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: atm: reject out-of-range traffic classes in QoS validation Reject ATM traffic classes above ATM_ANYCLASS in check_tp(). SO_ATMQOS stores the supplied QoS after check_qos() succeeds, so accepting larger values leaves invalid traffic_class values in vcc->qos. That bad state later reaches pvc_info(), which indexes class_name[] with vcc->qos.{rx,tp}.traffic_class. Values above ATM_ANYCLASS cause an out-of-bounds read when /proc/net/atm/pvc is read. Tighten the existing QoS validation so invalid traffic_class values are rejected at the point where user supplied QoS is accepted.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv4: igmp: Fix potential UAF in igmp_gq_start_timer() A race condition exists between device teardown (inetdev_destroy) and incoming IGMP query processing (igmp_rcv), leading to a Use-After-Free in the IGMP timer callback. During device destruction, inetdev_destroy() drops the primary reference to in_device, which can drop its refcount to 0. The actual freeing of in_device memory is deferred via RCU (using call_rcu()). Concurrently, igmp_rcv() runs under RCU read lock and obtains the in_device pointer. Because the memory is RCU-protected, CPU-0 can safely dereference in_device even if its refcount has hit 0. However, if CPU-0 calls igmp_gq_start_timer() and re-arms the timer, it attempts to acquire a reference using in_dev_hold(). This increments the refcount from 0 to 1, triggering a "refcount_t: addition on 0" warning. Since the in_device memory is still scheduled to be freed after the RCU grace period (as the free callback does not check the refcount again), the device is freed while the timer is still armed. When the timer expires, it accesses the freed memory, causing a kernel panic. Fix this by using refcount_inc_not_zero() (via a new helper in_dev_hold_safe()) to prevent acquiring a reference if the device is already being destroyed. If the refcount is 0, we do not arm the timer. A similar issue in IPv6 MLD is fixed in a subsequent patch.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: qede: fix off-by-one in BD ring consumption on build_skb failure qede_rx_build_skb() and qede_tpa_rx_build_skb() do not check for a NULL return from qede_build_skb(). When it returns NULL under memory pressure, the functions still consume a BD from the ring before returning NULL. The callers then recycle additional BDs, resulting in one extra BD being consumed (off-by-one). This desynchronizes the BD ring, which can corrupt DMA page reference counts and lead to SLUB freelist corruption. Commit 4e910dbe3650 ("qede: confirm skb is allocated before using") added a NULL check inside qede_build_skb() to prevent a NULL pointer dereference, but did not address the missing NULL checks in the callers, making this off-by-one reachable. Fix this by adding NULL checks for the return value of qede_build_skb() in both qede_rx_build_skb() and qede_tpa_rx_build_skb(), returning NULL immediately before any BD ring manipulation.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: bridge: stp: Fix a potential use-after-free when deleting a bridge The three STP timers are not supposed to be armed while the bridge is administratively down. They are synchronously deactivated when the bridge is put administratively down and the various call sites check for 'IFF_UP' before arming them. This check is missing from br_topology_change_detection() and it is possible to engineer a situation in which the topology change timer is armed while the bridge is administratively down, resulting in a use-after-free [1] when the bridge is deleted. Fix by adding the missing check and for good measures synchronously shutdown the three timers when the bridge is deleted. [1] ODEBUG: free active (active state 0) object: ffff88811662b9b0 object type: timer_list hint: br_topology_change_timer_expired (net/bridge/br_stp_timer.c:120) WARNING: lib/debugobjects.c:629 at debug_print_object+0x1bc/0x450, CPU#9: ip/359


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipv4: fib: Don't ignore error route in local/main tables. When CONFIG_IP_MULTIPLE_TABLES is enabled but no rule is added, fib_lookup() performs route lookup directly on two tables. Since the first lookup does not properly bail out, the result of an error route in the merged local/main table could be overwritten by another route in the default table: # unshare -n # ip link set lo up # ip route add 192.168.0.0/24 dev lo table 253 # ip route add unreachable 192.168.0.0/24 # ip route get 192.168.0.1 192.168.0.1 dev lo table default uid 0 cache <local> Once a random rule is added, the error route is respected: # ip rule add table 0 # ip rule del table 0 # ip route get 192.168.0.1 RTNETLINK answers: No route to host Let's fix the inconsistent behaviour.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfrm: validate selector family and prefixlen during match syzbot reported a shift-out-of-bounds in xfrm_selector_match() due to AF_UNSPEC selector with large prefixlen (e.g. 128) matched against IPv4 flow (when XFRM_STATE_AF_UNSPEC is set). Fix this by: - Rejecting mismatched families in xfrm_selector_match. - Returning false in addr4_match if prefixlen > 32. - Returning false in addr_match if prefixlen > 128 (prevents overflow).


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xprtrdma: Fix bcall rep leak and unbounded peek rpcrdma_is_bcall() decodes a reply's first words to decide whether the frame is a backchannel call. Two issues in that decode path let a short or malformed reply leak the receive buffer and drain the Receive queue. First, the speculative peek p = xdr_inline_decode(xdr, 0); /* five p++ reads follow */ asks xdr_inline_decode() for zero bytes, which returns xdr->p without consulting xdr->end. The five subsequent __be32 reads can then walk up to 20 bytes past the wire payload into stale regbuf contents and misclassify the reply as a backchannel call. Second, after the post-peek p = xdr_inline_decode(xdr, 3 * sizeof(*p)); if (unlikely(!p)) return true; the short-header arm returns true without calling rpcrdma_bc_receive_call(). The contract with the caller is that a true return transfers ownership of rep to the backchannel path: rpcrdma_reply_handler() if (rpcrdma_is_bcall(r_xprt, rep)) return; /* bare return, skips out_post */ ... out_post: rpcrdma_post_recvs(r_xprt, credits + ...); Because rpcrdma_bc_receive_call() never ran, no one took rep, but rpcrdma_reply_handler still bare-returns past rpcrdma_rep_put() and rpcrdma_post_recvs(). The rep, with its persistently DMA-mapped receive buffer, is orphaned on rb_all_reps and freed only at transport teardown. This completion reposts nothing, so its slot is reclaimed only when a later forward-channel reply reaches out_post and rpcrdma_post_recvs() allocates a fresh rep to backfill; absent that traffic the Receive queue drains and the peer's Sends draw RNR NAKs. Fix by consulting xdr->end after the zero-length peek so the five __be32 reads cannot run unless 20 bytes of wire payload remain. A byte-precise comparison against xdr->end is required because a non-4-aligned receive rounds the stream's word count up past the true payload. Also return false from the short-header arm so the reply falls through the normal out_norqst cleanup chain (rpcrdma_rep_put() plus rpcrdma_post_recvs()).


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: PCI: Check ROM header and data structure addr before accessing We meet a crash when running stress-ng on x86_64 machine: BUG: unable to handle page fault for address: ffa0000007f40000 RIP: 0010:pci_get_rom_size+0x52/0x220 Call Trace: <TASK> pci_map_rom+0x80/0x130 pci_read_rom+0x4b/0xe0 kernfs_file_read_iter+0x96/0x180 vfs_read+0x1b1/0x300 Our analysis reveals that the ROM space's start address is 0xffa0000007f30000, and size is 0x10000. Because of broken ROM space, before calling readl(pds), the pds's value is 0xffa0000007f3ffff, which is already pointed to the ROM space end, invoking readl() would read 4 bytes therefore cause an out-of-bounds access and trigger a crash. Fix this by adding image header and data structure checking. We also found another crash on arm64 machine: Unable to handle kernel paging request at virtual address ffff8000dd1393ff Mem abort info: ESR = 0x0000000096000021 EC = 0x25: DABT (current EL), IL = 32 bits SET = 0, FnV = 0 EA = 0, S1PTW = 0 FSC = 0x21: alignment fault The call trace is the same with x86_64, but the crash reason is that the data structure addr is not aligned with 4, and arm64 machine report "alignment fault". Fix this by adding alignment checking. [bhelgaas: shorten function names, wrap comments]


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: tcp: ipv6: clamp default adverting MSS to avoid GSO_BY_FRAGS (0xFFFF) When MTU is large, ip6_default_advmss() can return IPV6_MAXPLEN (65535). This is interpreted by TCP as mss_clamp, allowing the MSS to reach 65535. However, 0xFFFF is also used as a magic value GSO_BY_FRAGS in the kernel. If a TCP packet with gso_size=0xFFFF is passed to skb_segment(), it will be mistakenly treated as GSO_BY_FRAGS, leading to a NULL pointer dereference because local TCP packets do not use frag_list. Fix this by returning min(IPV6_MAXPLEN, GSO_BY_FRAGS - 1) (65534) from ip6_default_advmss() when MTU is large. Also update the stale comment in ip6_default_advmss() which suggested that IPV6_MAXPLEN is returned to mean "any MSS".


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: tipc: fix UAF in tipc_l2_send_msg() Syzbot reported a slab-use-after-free in ipvlan_hard_header() when called from tipc_l2_send_msg(). The root cause is that tipc_disable_l2_media() calls synchronize_net() while b->media_ptr is still valid. This allows concurrent RCU readers to obtain the device pointer after synchronize_net() has finished. The pointer is cleared later in bearer_disable(), but without any subsequent synchronization, allowing the device to be freed while still in use by readers. Fix this by clearing b->media_ptr in tipc_disable_l2_media() before calling synchronize_net(). This is safe to do now because the call order in bearer_disable() was reversed in 0d051bf93c06 ("tipc: make bearer packet filtering generic") to call tipc_node_delete_links() (which needs the pointer) before disable_media(). https: //lore.kernel.org/netdev/6a2c1007.428ffe26.258b27.015d.GAE@google.com/T/#u


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: avoid stale FIFO cells during resize snd_seq_fifo_resize() still needs to publish the replacement pool before it waits for FIFO users. A blocking snd_seq_read() holds f->use_lock while it sleeps, so concurrent senders must be able to queue to the new pool and wake that reader instead of failing against a closing old pool. However, snd_seq_fifo_event_in() duplicates an event before it takes f->lock, and snd_seq_read() can dequeue a cell and later call snd_seq_fifo_cell_putback() if copy_to_user() or snd_seq_expand_var_event() fails. If resize swaps f->pool and detaches oldhead in between, either path can relink an old-pool cell after the snapshot. That stale cell sits outside the drained oldhead list, keeps oldpool->counter elevated, and can leave snd_seq_pool_delete() waiting for the retired pool to drain. Keep the existing swap-before-wait ordering in snd_seq_fifo_resize(), but reject stale cells before any FIFO relink. Revalidate event-in cells under f->lock and retry them against the published replacement pool, and free stale putback cells instead of linking them back into the FIFO. The buggy scenario involves two paths, with each column showing the order within that path: resize path: relink path: 1. Allocate newpool. 1. Take f->use_lock. 2. Swap f->pool to newpool and 2. Duplicate or dequeue an old-pool detach oldhead. cell before oldpool closes. 3. Mark oldpool closing and 3. Reach a later relink point after wait for FIFO users. resize published newpool. 4. Free oldhead and delete 4. Relink the old-pool cell after oldpool. resize detached oldhead. 5. Drop f->use_lock. The reproducer reports a resize ioctl blocked in the expected pool teardown path: signal: resize iteration=98 target_pool=4 exceeded 250ms (elapsed=251ms) diagnostic: resize_tid=651 wchan=snd_seq_pool_done diagnostic: resize_tid=651 stack= snd_seq_pool_done+0x5b/0x140 snd_seq_pool_delete+0x7a/0x90 snd_seq_fifo_resize+0x193/0x1e0 snd_seq_ioctl_set_client_pool+0x214/0x260 snd_seq_ioctl+0x119/0x540 __x64_sys_ioctl+0xd1/0x120 do_syscall_64+0xbb/0x2f0 entry_SYSCALL_64_after_hwframe+0x77/0x7f A second run with larger pools hit the same target path: signal: resize iteration=32 target_pool=64 exceeded 250ms (elapsed=251ms) diagnostic: resize_tid=663 wchan=snd_seq_pool_done diagnostic: resize_tid=663 stack= snd_seq_pool_done+0x5b/0x140 snd_seq_pool_delete+0x7a/0x90 snd_seq_fifo_resize+0x193/0x1e0 snd_seq_ioctl_set_client_pool+0x214/0x260 snd_seq_ioctl+0x119/0x540 __x64_sys_ioctl+0xd1/0x120 do_syscall_64+0xbb/0x2f0 entry_SYSCALL_64_after_hwframe+0x77/0x7f


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: mana: initialize gdma queue id to INVALID_QUEUE_ID mana_gd_create_mana_wq_cq() leaves queue->id as 0 (from kzalloc_obj()) until mana_create_wq_obj() assigns the firmware-returned id. If creation fails before that, cleanup calls mana_gd_destroy_cq() with id 0, NULLing gc->cq_table[0] and silently breaking whichever real CQ owns that slot. Initialize queue->id to INVALID_QUEUE_ID right after allocation, matching mana_gd_create_eq(). The existing (id >= max_num_cqs) guard then short-circuits cleanly.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: power: supply: core: fix supplied_from allocations If dts property power-supplies has multiple values, then accessing to psy->supplied_from[i-1] in __power_supply_populate_supplied_from will overrun supplied_from array.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: Fix kernel heap address leak in bounce_error_event() The comment above bounce_error_event() documents that user clients should receive SNDRV_SEQ_EVENT_BOUNCE with the original event embedded as variable-length data, while kernel clients should receive SNDRV_SEQ_EVENT_KERNEL_ERROR with a quoted kernel pointer. However, the implementation unconditionally uses SNDRV_SEQ_EVENT_KERNEL_ERROR with data.quote.event set to the raw struct snd_seq_event pointer for all clients. When a bounce error event is delivered to a USER_CLIENT via snd_seq_read(), the kernel heap address in data.quote.event is exposed to userspace through copy_to_user() in the fixed-length branch. This is a distinct leak path from the one addressed by commit 705dd6dcbc0e ("ALSA: seq: Clear variable event pointer on read"), which sanitizes data.ext.ptr in the variable-length branch of snd_seq_read(). The bounce_error_event() leak uses fixed-length events that take the else branch where no sanitization occurs. Differentiate the bounce event by client type. For USER_CLIENT, send SNDRV_SEQ_EVENT_BOUNCE with SNDRV_SEQ_EVENT_LENGTH_VARIABLE and data.ext pointing to the original event. The variable-length path in snd_seq_event_dup() copies the event data into chained cells, and snd_seq_expand_var_event() copies only the content -- never the pointer -- to userspace. For KERNEL_CLIENT, keep the existing SNDRV_SEQ_EVENT_KERNEL_ERROR behavior with the quoted pointer.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: crypto: cavium/cpt - fix DMA cleanup using wrong loop index The sg_cleanup error path used list[i] instead of list[j] when unmapping DMA buffers, leaking successfully mapped entries and repeatedly unmapping the failed one.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Release the HW-provided UAR index rather than the SW one Free the UAR index returned by the hardware.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/mlx5: Fix undefined shift of user RQ WQE size set_rq_size() computes the RQ WQE size as "1 << rq_wqe_shift" based on the user-provided rq_wqe_shift, which is only checked to be greater than 32, so shifts of 32 are still accepted. A shift of 31 also overflows a signed integer, leading to undefined behavior. Use check_shl_overflow() to compute the RQ WQE size and reject any invalid values.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_core: Fix UAF in hci_unregister_dev() hci_unregister_dev() does not disable cmd_timer and ncmd_timer before the hci_dev structure is freed. If a timeout fires during device teardown, the callback dereferences freed memory (including the hdev->reset function pointer), leading to a use-after-free. Add disable_delayed_work_sync() calls alongside the existing disable_work_sync() calls to ensure both timers are fully quiesced before teardown proceeds.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/nldev: Fix locking when accessing mr->pd Sashiko points out that, due to rereg_mr, the PD is actually variable and all the touches in nldev are racy. Use mr->device instead of mr->pd->device. Getting the PD restrack ID is more tricky. To avoid disturbing all the happy paths, add an rdma_restrack_sync() operation which is sort of like flush_workqueue() or synchronize_irq(): after it returns, all the old nldev touches to the mr are gone and everything sees the new PD. This makes it safe to reach into the PD pointer.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: wcn36xx: fix heap overflow from oversized firmware HAL response The firmware response dispatcher copies all synchronous HAL responses into the 4096-byte hal_buf without validating the response length. A response exceeding WCN36XX_HAL_BUF_SIZE causes a heap buffer overflow with firmware-controlled content. Add a bounds check on the response length.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Copy WQE to local buffer in non-SRQ receive path For non-SRQ QPs, the responder reads WQE fields directly from the shared queue buffer mapped into userspace. This allows a malicious user to modify fields like num_sge or sge entries while the kernel is processing the WQE, leading to out-of-bounds reads in rxe_resp_check_length() and copy_data(). Introduce get_recv_wqe() that validates num_sge and copies the WQE to a kernel-local buffer before processing, matching the approach already used for SRQ WQEs in get_srq_wqe(). The srq_wqe buffer is reused since SRQ and non-SRQ paths are mutually exclusive per QP.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/rxe: Fix TOCTOU heap overflow in get_srq_wqe get_srq_wqe() reads wqe->dma.num_sge from the shared receive queue buffer, which is mapped into userspace. It validates num_sge against max_sge, but then re-reads the same field to calculate the memcpy size. A concurrent userspace thread can modify num_sge between validation and use, causing a heap buffer overflow when copying the WQE into qp->resp.srq_wqe. Read num_sge into a local variable and use it for both the bounds check and the size calculation.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net/sched: cls_bpf: prevent unbounded recursion in offload rollback Quan Sun reported [1] a stack overflow in cls_bpf_offload_cmd(). Reproducer on netdevsim: add a skip_sw cls_bpf filter, set the bpf_tc_accept debugfs knob to 0, then `tc filter replace`. The replace calls tc_setup_cb_replace() which fails. cls_bpf_offload_cmd() then swaps prog/oldprog and recursively calls itself to roll back. But bpf_tc_accept=0 makes the rollback fail too, which triggers yet another rollback frame with the same arguments, and so on until the stack is exhausted. bpf_tc_accept is just a convenient knob for the reproducer. Any driver whose tc_setup_cb_replace() fails twice in a row can hit the same loop, so this is not a netdevsim-only issue. Two ways to fix it: 1) Have the rollback call tc_setup_cb_add() on oldprog instead of re-entering cls_bpf_offload_cmd(). 2) Mark the rollback frame with a flag and skip a second-level rollback from inside it. Go with (2). It is the smaller change and keeps the original behaviour: the rollback still goes through tc_setup_cb_replace(), so the driver gets one real chance to restore its state. If that attempt also fails, we just return the original error instead of recursing. [1]: https://lore.kernel.org/bpf/ce5a6005-3c5e-4696-9e05-eba9461dc860@std.uestc.edu.cn/T/#u


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ALSA: seq: oss: Fix UAF at handling events with embedded SysEx data The OSS sequencer processes the input MIDI bytes into a sequencer event to be dispatched later (in snd_seq_oss_midi_putc() called from snd_seq_oss_process_event()). When it's a SysEx data, the event record contains data.ext.ptr pointer to the original SysEx bytes, and the referred data is copied into the pool afterwards at dispatching. The problem is that, if the sequencer port gets closed concurrently before the dispatch, the OSS sequencer core also releases the resources (in snd_seq_oss_midi_check_exit_port()), while the pending event may hold a stale pointer, eventually leading to a UAF at a later dispatch. Fortunately, there is already a refcounting mechanism (snd_use_lock_t) for the OSS MIDI device access, and for addressing the issue above, we just need to extend the refcount until the event gets dispatched. This patch extends snd_seq_oss_process_event() to give back the refcount object, which is in turn released after calling the sequencer dispatcher with the given event in the caller side. According to the original report, KASAN report as below: KASAN slab-use-after-free in snd_seq_event_dup+0x40c/0x470 RIP: 0033:0x7f2cb66a6340 Read of size 6 Call trace: dump_stack_lvl+0x73/0xb0 (?:?) print_report+0xd1/0x650 (?:?) srso_alias_return_thunk+0x5/0xfbef5 (?:?) __virt_addr_valid+0x1a7/0x340 (?:?) kasan_complete_mode_report_info+0x64/0x200 (?:?) kasan_report+0xf7/0x130 (?:?) snd_seq_event_dup+0x40c/0x470 (?:?) kasan_check_range+0x10c/0x1c0 (?:?) __asan_memcpy+0x27/0x70 (?:?) snd_seq_event_dup+0x9/0x470 (?:?) snd_seq_client_enqueue_event+0x139/0x240 (?:?) _raw_spin_unlock_irqrestore+0x4b/0x60 (?:?) snd_seq_kernel_client_enqueue+0x102/0x120 (?:?) snd_seq_oss_write+0x416/0x4e0 (?:?) apparmor_file_permission+0x20/0x30 (?:?) odev_write+0x3b/0x60 (?:?) vfs_write+0x1ce/0x850 (?:?) lock_release+0xc8/0x2a0 (?:?) __kasan_check_write+0x18/0x20 (?:?) __mutex_unlock_slowpath+0x129/0x510 (?:?) ksys_write+0xe1/0x180 (?:?) mutex_unlock+0x16/0x20 (?:?) odev_ioctl+0x65/0xc0 (?:?) __x64_sys_write+0x46/0x60 (?:?) x64_sys_call+0x7d/0x20d0 (?:?) do_syscall_64+0xc1/0x360 (arch/x86/entry/syscall_64.c:87) entry_SYSCALL_64_after_hwframe+0x77/0x7f (?:?)


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: vxlan: Fix potential null-ptr-deref in vxlan_gro_prepare_receive(). udp_tunnel_sock_release() could set sk->sk_user_data to NULL while vxlan_gro_prepare_receive() is running. Let's check if rcu_dereference_sk_user_data() is NULL after skb_gro_remcsum_init().


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix memory leak in radeon_ring_restore() on lock failure radeon_ring_restore() takes ownership of the data buffer allocated by radeon_ring_backup(). The caller (radeon_gpu_reset()) only frees it in the non-restore branch; in the restore branch it relies on radeon_ring_restore() to free it. If radeon_ring_lock() fails, the function returned early without calling kvfree(data), leaking the ring backup buffer on every GPU reset that fails at the lock stage. During repeated GPU resets this causes cumulative kernel memory exhaustion. Free data before returning the error.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/radeon: fix integer overflow in radeon_align_pitch() radeon_align_pitch() has the same kind of overflow issue as the old amdgpu helper: both the alignment round-up add and the final 'aligned * cpp' calculation can overflow signed int. If that wraps, radeon_mode_dumb_create() can end up returning an invalid pitch or creating a zero-sized dumb buffer. Fix this by using check_add_overflow() for the alignment round-up and check_mul_overflow() for the final pitch calculation, returning 0 on overflow. Also reject zero pitch and size in radeon_mode_dumb_create(). Found via AST-based call-graph analysis using sqry.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/vc4: Supply the overflow slot size in BPOS, not the whole bin BO size vc4_overflow_mem_work() points BPOA at a 512KB slot inside the 16MB binner BO, but writes the size of the whole BO to BPOS. On every binner out-of-memory event the PTB is therefore authorized to write tile lists across all the other slots (which may hold the tile state, tile alloc and overflow memory of in-flight jobs) and, for any slot but the first, past the end of the binner BO into unrelated CMA memory. Since CMA pages are recycled into page cache and user allocations, this is arbitrary memory corruption by GPU DMA. In practice it shows up as GPU hangs with corrupted control list pointers, userspace heap corruption, a GPU that stays permanently wedged after the first hang, and occasional full system crashes, whenever a job overflows the initial binner slot. The bug dates back to the conversion from a dedicated overflow BO (where writing the full BO size was correct) to the slotted binner BO.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: pktgen: fix proc entry use-after-free pktgen_change_name() replaces pkt_dev->entry while holding t->if_lock. pktgen_remove_device() removes the same entry before _rem_dev_from_if_list() takes that lock. This allows the following interleaving: CPU 0 (NETDEV_CHANGENAME) CPU 1 (kpktgend) if_lock(t) proc_remove(pkt_dev->entry) proc_remove(pkt_dev->entry) pkt_dev->entry = proc_create_data(...) if_unlock(t) The kthread can pass the stale proc_dir_entry to proc_remove() after the rename path has freed it. A reproducer with a widened race window reports: BUG: KASAN: slab-use-after-free in proc_remove+0x78/0x80 Read of size 8 at addr ffff8881478fea70 by task kpktgend_0/67 Call Trace: proc_remove+0x78/0x80 pktgen_remove_device.isra.0+0x11c/0x4c0 pktgen_thread_worker+0x1214/0x6bc0 kthread+0x2c6/0x3b0 Allocated by task 95: __proc_create+0x204/0x790 proc_create_data+0x72/0xe0 pktgen_thread_write+0xd61/0x1510 Freed by task 28: kmem_cache_free+0xcb/0x3d0 proc_free_inode+0x5b/0x80 rcu_core+0x50a/0x1850 The buggy address belongs to the object at ffff8881478fea00 which belongs to the cache proc_dir_entry of size 192 Move proc_remove() into the if_lock-protected list removal helper. Keep it before list_del_rcu() to preserve the ordering required by add_device(). The rename path must then finish replacing the entry before removal, or it observes that the device is no longer on the list.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: mm/huge_memory: unlock i_mmap_rwsem before releasing after-split folios __folio_split() keeps dereferencing the mapping after the split: shmem_uncharge(mapping->host) and remap_page() while the folios are still frozen/locked, and i_mmap_unlock_read(mapping) at the very end, after the after-split folios have been unlocked and freed. Nothing holds an inode reference across that. The split relies on @folio -- which the beyond-EOF drop loop never removes, as it starts at folio_next(folio) -- staying locked and in the page cache to hold off eviction. But the unlock loop unlocks @folio before i_mmap_unlock_read() runs. If the caller's @lock_at is a tail beyond EOF, as memory_failure() passes when splitting a poisoned tail of a shmem THP that reaches past i_size during truncation, it too is gone from the page cache; so once @folio is unlocked no locked, in-cache folio pins the inode, and a concurrent final iput() can evict and RCU-free it before i_mmap_unlock_read() touches i_mmap_rwsem: BUG: KASAN: slab-use-after-free in __up_read+0x634/0x790 i_mmap_unlock_read include/linux/fs.h:537 [inline] __folio_split+0x732/0x1640 mm/huge_memory.c:4100 try_to_split_thp_page+0xab/0x390 mm/memory-failure.c:1675 memory_failure+0x1394/0x26e0 mm/memory-failure.c:2470 Freed by task 4601: shmem_free_in_core_inode+0x54/0xb0 mm/shmem.c:5177 evict+0x57f/0xac0 fs/inode.c:870 Do every mapping dereference while @folio still pins the inode: drop i_mmap_rwsem right after remap_page(), before the loop that unlocks and frees the after-split folios, and clear @mapping so the exit path does not unlock it again. shmem_uncharge() and remap_page() already run before that point, so after this nothing past the unlock loop touches the inode or the mapping. This is now a rule the split depends on, alongside keeping @folio frozen until the page cache is updated: no inode or mapping dereference once the after-split folios start being unlocked.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: wifi: mwifiex: use the subframe length when parsing A-MSDU TDLS frames mwifiex_11n_dispatch_amsdu_pkt() splits an A-MSDU with ieee80211_amsdu_to_8023s() and walks the resulting subframes. For each subframe it passes the subframe data pointer to mwifiex_process_tdls_action_frame(), but pairs it with skb->len, the length of the A-MSDU parent, instead of rx_skb->len: rx_skb = __skb_dequeue(&list); rx_hdr = (struct rx_packet_hdr *)rx_skb->data; if (ISSUPP_TDLS_ENABLED(priv->adapter->fw_cap_info) && ntohs(rx_hdr->eth803_hdr.h_proto) == ETH_P_TDLS) { mwifiex_process_tdls_action_frame(priv, (u8 *)rx_hdr, skb->len); } The parent is not a valid description of that buffer, and may not be valid memory at all. ieee80211_amsdu_to_8023s() ends with if (!reuse_skb) dev_kfree_skb(skb); and it only sets reuse_skb when the parent is linear, is not a head_frag, and is being consumed as the *last* subframe. So when the parent does not qualify for reuse it has already been freed, and the read of skb->len is a use-after-free. When it is reused, skb->len is the length of the last subframe, applied to every earlier subframe, which over-states the buffer whenever an earlier subframe is shorter. The callee cannot absorb a wrong length, because it derives its own ceiling from the value it is given. Each frame type computes ies_len = len - sizeof(struct ethhdr) - TDLS_*_FIX_LEN; and the element walk is then bounded entirely against that ceiling, for (end = pos + ies_len; pos + 1 < end; pos += 2 + pos[1]) { u8 ie_len = pos[1]; if (pos + 2 + ie_len > end) break; so a too-large len moves end past the end of the subframe and the walk reads and copies beyond it. The A-MSDU layout is chosen by the sender, which makes the difference between the last subframe and a shorter earlier one remotely selectable. Reaching this requires TDLS support in firmware and the TDLS ethertype on the subframe. The other caller, mwifiex_process_rx_packet(), is correct: it passes a pointer and a length that describe the same region of the RX buffer. Pass rx_skb->len, the length of the subframe actually being parsed.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: igbvf: Fix leak in TX DMA error cleanup If an error is encountered while mapping TX buffers, the driver should unmap any buffers already mapped for that skb. Because count is incremented before each frag mapping, it will always match the correct number of unmappings needed when dma_error is reached. Decrementing count before the while loop in dma_error causes an off-by-one error. If any mapping was successful before an unsuccessful mapping, exactly one DMA mapping (the head) would leak. This bug was introduced by a 2010 fix for an endless loop in dma_error. All other affected drivers have already been fixed.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fou: Fix use-after-free in fou_create() fou_create() publishes struct fou through sk_user_data before adding the new FOU port to the per-netns list. If fou_add_to_port_list() fails, the error path frees fou while it is still reachable through sk_user_data. A concurrent receive can then dereference the freed object in fou_from_sock(). This ordering issue was previously noted in the linked discussion. The failure is reachable when local port 0 is requested. Each socket binds to a different ephemeral port, but fou_cfg_cmp() compares the requested port 0 and reports -EALREADY once an entry already exists. Release the tunnel socket before freeing fou so sk_user_data is cleared first, and defer reclamation with kfree_rcu() to protect concurrent RCU readers. This matches the lifetime handling in fou_release().


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: HIDP: reject frames without a transaction header hidp_recv_ctrl_frame() and hidp_recv_intr_frame() read skb->data[0] before checking that the L2CAP SDU contains a transaction header. A connected HIDP peer can send an empty basic-mode SDU and make both paths use an uninitialized byte from skb tailroom. KMSAN reports the use in hidp_session_run(), with the uninitialized value originating in __alloc_skb() through vhci_write(). The control path produces two reports and the interrupt path produces one. The byte can also be controlled by a malformed lower-layer packet. If an HCI ACL packet contains an L2CAP PDU with a declared zero-length payload followed by an extra 0x15 byte, l2cap_recv_acldata() reduces skb->len to the declared PDU length before dispatch. The current HIDP path nevertheless consumes the extra byte as HIDP_TRANS_HID_CONTROL | HIDP_CTRL_VIRTUAL_CABLE_UNPLUG and terminates the HIDP session. With this change, the same packet is discarded and a subsequent feature report request succeeds. Pull the transaction header with skb_pull_data() and discard frames that do not contain it.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: mgmt: fix UAF in pair command cancellation The pairing completion and authentication failure callbacks look up the pending MGMT_OP_PAIR_DEVICE command by walking hdev->mgmt_pending. The lookup returned a command that was still linked on the shared pending list, without keeping mgmt_pending_lock held for the later dereference and removal. A concurrent MGMT_OP_CANCEL_PAIR_DEVICE request can remove and free the same pending command before the callback uses it. The reverse race is also possible when cancel_pair_device() gets a command from pending_find() and a callback removes it before the cancel path dereferences it. This can lead to a use-after-free and a second list_del(). Make the pairing lookup helpers transfer ownership of the pending command by removing it from hdev->mgmt_pending while holding mgmt_pending_lock. The callbacks and cancel path then complete the command and free it directly, so racing paths cannot find or free the same command again. Take a temporary hci_conn reference in cancel_pair_device() because the command completion drops the reference stored in the pending command.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: pinctrl: devicetree: don't free uninitialized dev_name on error path dt_remember_or_free_map() duplicates dev_name for each map entry. If kstrdup_const() fails, dt_free_map() frees dev_name in all num_maps entries, including entries that have not been initialized. Some pinctrl drivers, including pinctrl-imx, allocate the map with kmalloc() and leave dev_name for the core to initialize. The untouched entries therefore contain uninitialized data which is passed to kfree_const(). Reproduced on qemu's mcimx6ul-evk (pinctrl-imx) with failslab injection while binding the pinctrl-consuming device, under KASAN: BUG: KASAN: double-free in dt_free_map+0x34/0xa4 Free of addr c425a900 by task init/1 kfree from dt_free_map+0x34/0xa4 dt_free_map from dt_remember_or_free_map+0x184/0x198 dt_remember_or_free_map from pinctrl_dt_to_map+0x33c/0x4c8 pinctrl_dt_to_map from create_pinctrl+0x9c/0x5c0 Initialize all dev_name fields to NULL before duplicating the device name, making the full-map cleanup safe after a partial failure.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: ISO: hold sk properly in iso_conn_ready sk deref in iso_conn_ready must be done either under conn->lock, or holding a refcount, to avoid concurrent close. conn->sk is currently accessed without either: [Task 1] [Task 2] iso_sock_release iso_conn_ready sk = conn->sk lock_sock(sk) conn->sk = NULL lock_sock(sk) release_sock(sk) iso_sock_kill(sk) UAF on sk deref Fix possible UAF by holding sk refcount in iso_conn_ready(). Also recheck after lock_sock that the socket is still valid. Adjust locking so conn->sk is cleared only under lock_sock.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: forcedeth: fix UAF of txrx_stats in nv_remove nv_remove() frees the per-CPU txrx_stats before unregister_netdev(). Until unregister completes, ndo_get_stats64, the NAPI/xmit data path, and nv_close()/drain may still access txrx_stats, leading to a use-after-free. Free the stats only after unregister_netdev().


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: net: do not send ICMP/NDISC Redirects when peer allocation fails When inet_getpeer_v4() or inet_getpeer_v6() fails to allocate a peer entry under memory pressure or tree size caps, redirect handlers previously fell back to sending un-rate-limited ICMP/NDISC Redirect messages. In IPv4, ip_rt_send_redirect() called icmp_send() directly when peer == NULL. In IPv6, ip6_forward() and ndisc_send_redirect() passed a NULL peer into inet_peer_xrlim_allow(), which returned true when peer == NULL. Because ICMP/NDISC Redirects are not part of the default global rate limit mask (sysctl_icmp_ratemask), sending redirects when peer == NULL creates an un-rate-limited ICMP packet storm. Fix this by failing closed in ip_rt_send_redirect(), ip6_forward(), and ndisc_send_redirect() when peer is NULL.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi_tcp: Bound SCSI Response data segment to the connection buffer iscsi_tcp_hdr_dissect() receives the data segment of several PDU types into the fixed-size conn->data buffer, which is allocated for ISCSI_DEF_MAX_RECV_SEG_LEN (8192) bytes. For the LOGIN_RSP, TEXT_RSP, REJECT and ASYNC_EVENT opcodes the dissect path already rejects a PDU whose DataSegmentLength exceeds that buffer. The SCSI Command Response (ISCSI_OP_SCSI_CMD_RSP) path also copies its data segment (sense/response data) into conn->data via iscsi_tcp_data_recv_prep(), but it does so without the same check. The only upstream bound on in.datalen is conn->max_recv_dlength, the initiator's advertised MaxRecvDataSegmentLength, which is commonly negotiated well above 8192 (open-iscsi defaults to 262144). A target that returns a SCSI Response with a DataSegmentLength between 8193 and max_recv_dlength therefore overflows the 8192-byte conn->data buffer. Once the same bound applies, ISCSI_OP_SCSI_CMD_RSP is handled exactly like those responses: bound the data segment, receive it into conn->data when present, and otherwise complete the PDU with no data. Fold the opcode into that case group rather than duplicating the check.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: scsi: libiscsi: Fix stale-data leak into the SCSI sense buffer iscsi_scsi_cmd_rsp() copies the sense data of a SCSI Response from the target-supplied data segment. The segment carries a 2-byte sense length followed by the sense bytes, so it must hold 2 + senselen bytes, but the bounds check only requires datalen >= senselen: senselen = get_unaligned_be16(data); if (datalen < senselen) goto invalid_datalen; memcpy(sc->sense_buffer, data + 2, min_t(uint16_t, senselen, SCSI_SENSE_BUFFERSIZE)); A target that returns a SCSI Response whose datalen equals senselen (with senselen <= SCSI_SENSE_BUFFERSIZE) makes the memcpy() from data + 2 read up to two bytes past the received data. Those bytes are stale conn->data contents and end up in the command's sense buffer, which is returned to userspace. Account for the 2-byte sense length prefix in the check.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: packet: use consistent hard_header_len in non-ring send paths packet_snd() reads dev->hard_header_len multiple times while allocating and constructing an skb. Device reconfiguration can change this value concurrently, for example through bonding device type changes. For SOCK_RAW, packet_snd() can save a larger value in reserve and later allocate headroom using a smaller value. Moving skb->data back by reserve then places it before skb->head, and the following copy from userspace can attempt an out-of-bounds write. packet_sendmsg_spkt() has the same issue because it calculates its reservation and header offset from separate reads before dropping the RCU read lock to allocate the skb. Add LL_RESERVED_SPACE_EX() for callers that already saved a header length. Read hard_header_len once in packet_snd() and use it for allocation and construction. In packet_sendmsg_spkt(), preserve the allocation-time value through the device lookup retry. The separate SOCK_DGRAM consistency problem between hard_header_len and header_ops->create is not addressed here.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: RDMA/bnxt_re: zero shared page before exposing to userspace bnxt_re_alloc_ucontext() allocates uctx->shpg via __get_free_page(GFP_KERNEL). The buddy allocator does not zero pages without __GFP_ZERO, so the page contains stale kernel data from whatever object most recently freed it. The page is then mapped into userspace via vm_insert_page() under BNXT_RE_MMAP_SH_PAGE in bnxt_re_mmap(). The driver only ever writes 4 bytes (a u32 AVID) at offset BNXT_RE_AVID_OFFT (0x10) inside bnxt_re_create_ah(); the remaining 4092 bytes of the page are exposed to userspace unsanitised, leaking kernel memory contents. Any user with access to /dev/infiniband/uverbsX on a host with a bnxt_re device (typically rdma group membership) can read this data via a single mmap() at pgoff 0 after IB_USER_VERBS_CMD_GET_CONTEXT. Other shared pages in the same file already use get_zeroed_page() correctly: drivers/infiniband/hw/bnxt_re/ib_verbs.c srq->uctx_srq_page = (void *)get_zeroed_page(GFP_KERNEL); cq->uctx_cq_page = (void *)get_zeroed_page(GFP_KERNEL); uctx->shpg is the only outlier. Bring it in line with the existing convention by switching to get_zeroed_page().


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipvs: clear IPv4 options after rebasing tunnel ICMP errors ip_vs_in_icmp() rebases an skb from the outer ICMP packet to the quoted original request before passing it to icmp_send(). However, IPCB(skb)->opt still describes the outer IPv4 header. A timestamp option in the outer header can therefore leave an offset that points into the quoted transport header after the rebase. __ip_options_echo() treats a byte at that stale location as the option length and copies it into the fixed-size option storage on the __icmp_send() stack, causing a stack out-of-bounds write. Clear the stale option metadata after resetting the network header. Keep the remaining control block fields, including the ingress interface used by the ICMP response path.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Input: evdev - fix information leak in evdev_pass_values() In evdev_pass_values(), the input_event structure is allocated on the kernel stack and populated field-by-field. However, it is never fully initialized. On architectures where struct input_event contains explicit or implicit padding (such as the 32-bit __pad field on SPARC64), these padding bytes are left uninitialized. When this event structure is subsequently passed to the client buffer and later copied to userspace, the uninitialized padding bytes leak kernel stack memory, potentially exposing sensitive information. Similar issues exist in __evdev_queue_syn_dropped and __pass_event. Fix this by explicitly zeroing the entire event structure with memset() before populating its fields. This ensures all padding bytes are cleared before the data crosses the security boundary.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: udp: fix potential use-after-free in tunnel segmentation __skb_udp_tunnel_segment() gets the UDP header before ensuring the tunnel header is in the skb head. If the pull reallocates skb->head, the saved UDP header pointer is no longer valid. Get the UDP header after the pull to avoid a potential use-after-free.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: macvlan: inherit needed_headroom and needed_tailroom from lowerdev macvlan devices inherit hard_header_len from lowerdev during macvlan_init(), but leave needed_headroom and needed_tailroom set to 0. When the underlying lowerdev requires extra headroom or tailroom for headers/trailers (e.g. macsec, ipsec, wireguard, tunnels, or veth with rx headroom), upper layers calculating packet headroom and tailroom fail to reserve sufficient space. This can result in reallocation overhead, skb headroom underflows, or KASAN slab-use-after-free crashes when dev_hard_header() / macvlan_hard_header() prepends header data or when lower devices append tailroom. Fix this by: 1. Inheriting needed_headroom and needed_tailroom from lowerdev in macvlan_init(). 2. Propagating needed_headroom and needed_tailroom updates to attached macvlans in macvlan_device_event() when receiving NETDEV_FEAT_CHANGE events.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: xfs: fix ilock leak on error in xfs_dq_get_next_id xfs_dq_get_next_id() takes the quota inode ILOCK before calling xfs_iread_extents(). If xfs_iread_extents() fails, the function returns immediately without releasing the lock, leaking the quota inode ILOCK. This can leave the quota inode locked and cause subsequent quota operations to hang. Fix this by jumping to a common unlock path on error instead of returning directly.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Input: focaltech - fix array out-of-bounds in focaltech_process_rel_packet Make finger2 (and also finger1) unsigned, so that if the finger index in the packet is 0 then subtracting 1 creates an array index which overflows above the existing check for FOC_MAX_FINGERS, as the existing comment says it should, instead of writing to state->fingers[-1].


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: fbdev: bound mode sysfs output to the sysfs buffer mode_string() uses snprintf() which can return a value larger than the remaining buffer space. show_modes() accumulates the return value into i without checking whether i has reached PAGE_SIZE, causing the offset to advance past the sysfs buffer if the modelist is long enough. Add a size parameter to mode_string() and use scnprintf() to return only the bytes actually written. Add an early return when offset already exceeds the buffer. In show_modes(), stop accumulating once the buffer is full.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: inet: frags: strip GSO state from fragments before reassembly A virtio_net_hdr (tun/tap, or AF_PACKET with PACKET_VNET_HDR) can mark an IPv4 or IPv6 fragment as GSO; nothing relates gso_type to frag_off. inet_frag_reasm_prepare()/inet_frag_reasm_finish() keep the first fragment's skb as the head of the reassembled datagram, including its shinfo->gso_size/gso_type/gso_segs, and chain the remaining fragments on frag_list with whatever linear/paged layout they arrived with. After ip_defrag() (ip_local_deliver(), nf_defrag_ipv4, ...) the reassembled skb therefore still claims to be GSO (SKB_GSO_DODGY), and the next software segmentation point - udp_rcv_segment() on local delivery, validate_xmit_skb(), or the ip_finish_output_gso() slow path - hands it to skb_segment(). skb_segment()'s frag_list walk assumes GRO-shaped input and hits one of its BUG_ON()s. Two writes to a tap by an unprivileged user in its own userns are enough: kernel BUG at net/core/skbuff.c:4899! Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI CPU: 0 UID: 1000 PID: 82 Comm: poc Not tainted 7.2.0-pentest+ #2 RIP: 0010:skb_segment+0x20ca/0x48b0 Call Trace: <TASK> __udp_gso_segment+0x29a/0x27d0 udp4_ufo_fragment+0x458/0x6c0 inet_gso_segment+0x429/0x1340 skb_mac_gso_segment+0x233/0x4f0 __skb_gso_segment+0x308/0x660 udp_queue_rcv_skb+0x440/0xad0 udp_unicast_rcv_skb+0xc7/0x2c0 udp_rcv+0x16ce/0x2260 ip_protocol_deliver_rcu+0x197/0x2d0 ip_local_deliver+0x430/0x690 ip_rcv+0x16f/0x1f0 __netif_receive_skb_one_core+0x15e/0x1c0 __netif_receive_skb+0x1e/0x110 netif_receive_skb+0xf6/0x5c0 tun_rx_batched.isra.0+0x3ab/0x790 tun_get_user+0x17c3/0x3550 tun_chr_write_iter+0xba/0x1b0 vfs_write+0x646/0x1130 </TASK> Kernel panic - not syncing: Fatal exception in interrupt This runs with BH disabled, so it is a panic rather than an oops. The same is reachable with CAP_NET_RAW in a netns where a defrag point precedes a GSO point, and from a guest whose VMM forwards virtio_net_hdr to a tap. The SKB_GSO_DODGY frag_list checks added by commit 3dcbdb134f32 ("net: gso: Fix skb_segment splat when splitting gso_size mangled skb having linear-headed frag_list") and by commit 9e4b7a99a03a ("net: gso: fix panic on frag_list with mixed head alloc types") do not cover it: page-backed heads skip them, and kmalloc heads skip them when gso_size == skb_headlen(head), which the sender controls. An skb entering a frag queue is an IP fragment by definition and cannot legitimately carry GSO state: GRO does not merge fragments and the stack segments before it fragments, so only untrusted sources are affected. This has been reachable since commit f43798c27684 ("tun: Allow GSO using virtio_net_hdr"), the first path that let userspace attach GSO metadata to an IP fragment. Reset the GSO fields of every fragment as it is queued, in inet_frag_queue_insert(), which IPv4, IPv6, nf_conntrack_reasm and 6lowpan reassembly share; then neither the head nor the frag_list members of the reassembled skb carry them (the members matter too: the ip_do_fragment()/ip6_fragment() fast paths send them out as they are). The head may remain CHECKSUM_PARTIAL; that is already accepted on receive and resolved by skb_checksum_help() in ip_do_fragment()/ip6_fragment() on forward. Tested on top of net.git (dc4b95b8fee9), x86_64: the tap reproducer above, two further IPv4 frag_list geometries that reach BUG_ON(i >= nfrags) and BUG_ON(!list_skb->head_frag), and an IPv6 fragment-header variant (udp6_ufo_fragment()) each panic the unpatched kernel; with this patch all four datagrams are delivered intact and nothing is logged.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_irc: fix parse_dcc() off-by-one OOB read parse_dcc() treats data_end as an inclusive end pointer, but its only caller passes data_limit = ib_ptr + datalen, which points one past the last valid byte. The newline search loop iterates while tmp <= data_end, so when no newline is present, *tmp is read at tmp == data_end, one byte beyond the region filled by skb_header_pointer(). irc_buffer is kmalloc'd as MAX_SEARCH_SIZE + 1 bytes and datalen is capped at MAX_SEARCH_SIZE, so the stray read does not fault. The byte is uninitialized or stale; if it contains an ASCII digit, simple_strtoul will consume it and produce a wrong DCC IP or port in the conntrack expectation. The extra allocation byte is also a fragile guard: if the cap or allocation size changes, this becomes a real out-of-bounds read. Change the loop and its post-loop check to use strict less-than, consistent with the caller's exclusive-end convention. Update the function comment accordingly.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: qede: fix out-of-bounds check for cqe->len_list[] Move index check before element access.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate one-packet flag to synced conns Synced connections can be created before their destination exists. When the destination is later added, ip_vs_bind_dest() copies connection flags from the destination into cp->flags. IP_VS_CONN_F_ONE_PACKET connections are not synced. If a synced connection inherits IP_VS_CONN_F_ONE_PACKET while it is already hashed, expiry can treat it as a one-packet connection and skip unlinking the existing conn_tab node, leaving stale hash nodes pointing at a freed struct ip_vs_conn. Drop IP_VS_CONN_F_ONE_PACKET from destination flags when binding synced connections.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: serial: amba-pl011: synchronize DMA teardown dmaengine_terminate_all() does not wait for a running callback, so the TX callback can still touch the TX buffer after it is freed. The RX poll timer reads the RX buffers without the port lock. Switch to dmaengine_terminate_sync() and delete the RX timer before freeing the buffers.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: HID: hyperv: validate initial device info bounds The Hyper-V synthetic HID host supplies SYNTH_HID_INITIAL_DEVICE_INFO messages that contain a HID descriptor followed by the report descriptor bytes. mousevsc_on_receive_device_info() trusts bLength and wDescriptorLength without checking that the received packet contains both byte ranges. A malformed host or backend message can therefore make the guest read past the received VMBus packet while copying the report descriptor. Pass the received initial-device-info size into the parser and reject descriptor lengths that exceed the packet. Impact: A malicious Hyper-V host or backend can crash a guest by sending a short initial device-info message with an oversized HID report descriptor length.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: Bluetooth: RFCOMM: take rfcomm_mutex for the deferred setup accept rfcomm_sock_recvmsg() completes a deferred setup by calling rfcomm_dlc_accept() without holding any RFCOMM lock: if (test_and_clear_bit(RFCOMM_DEFER_SETUP, &d->flags)) { rfcomm_dlc_accept(d); return 0; } and rfcomm_dlc_accept() dereferences the session on its first line: struct sock *sk = d->session->sock->sk; Every other path that touches d->session runs under rfcomm_mutex: rfcomm_dlc_open(), rfcomm_dlc_close(), rfcomm_dlc_exists(), rfcomm_dlc_send_rpn(), and the RFCOMM thread through rfcomm_process_sessions(). rfcomm_connect_ind() is even documented as "called under rfcomm_lock()". This call site is the only one that skips it. The RFCOMM_DEFER_SETUP bit looks like it serialises the accept against teardown, since __rfcomm_dlc_close() returns early when it wins the test_and_clear. But rfcomm_recv_disc() forces the state first: d->state = BT_CLOSED; __rfcomm_dlc_close(d, err); and the early return only covers BT_CONNECT, BT_CONFIG, BT_OPEN and BT_CONNECT2. With the state already BT_CLOSED that switch does not match, the bit is never consulted, and __rfcomm_dlc_close() falls through to rfcomm_dlc_unlink(), which sets d->session = NULL. So a remote DISC on a deferred dlc clears the session while leaving RFCOMM_DEFER_SETUP set. The next recvmsg() then passes the test_and_clear and dereferences a NULL session. No timing window is needed: once the DISC has been processed, the dereference is unconditional. Give rfcomm_dlc_accept() the same shape as rfcomm_dlc_open() and rfcomm_dlc_close(): an exported wrapper that takes rfcomm_mutex and re-checks the session, around a __rfcomm_dlc_accept() that the two in-core callers, which already hold the mutex, keep using. Reproduced on a KASAN + PROVE_LOCKING kernel with a BR/EDR peer emulated over /dev/vhci: the peer brings up an ACL link, opens L2CAP on the RFCOMM PSM, starts a session, opens a dlc on a channel bound with BT_DEFER_SETUP, and sends DISC after the socket is accepted. recv() on the accepted socket then hits: Oops: general protection fault KASAN: null-ptr-deref in range [0x0000000000000010-0x0000000000000017] RIP: 0010:rfcomm_dlc_accept+0x54/0x350 Call Trace: rfcomm_sock_recvmsg+0x1cd/0x230 sock_recvmsg+0x166/0x1c0 __sys_recvfrom+0x20d/0x300 0x10 is the offset of sock in struct rfcomm_session. With this patch the same run completes with recv() returning 0 and no report, and lockdep stays quiet, confirming rfcomm_mutex is still taken before lock_sock on this path as it is on the thread side.


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки

Описание

In the Linux kernel, the following vulnerability has been resolved: drm/amdgpu: Reject UVD message with invalid number of h265 refs Same change as for h264, avoids overflow later when calculating min dpb size. (cherry picked from commit a4b0720e4f1601f97f59a2be9c1b4b94fa6527d5)


Затронутые продукты
Image SLES12-SP5-GCE-BYOS:kernel-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:cluster-md-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:dlm-kmp-default-4.12.14-122.328.1
Image SLES12-SP5-GCE-SAP-BYOS:gfs2-kmp-default-4.12.14-122.328.1

Ссылки
Уязвимость SUSE-SU-2026:4282-1