[Forgot Password]
Login  Register Subscribe

30480

 
 

423868

 
 

254802

 
 

909

 
 

198617

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2020:3503-1 -- SLES kernel-default, kernel-syms

ID: oval:org.secpod.oval:def:89000502Date: (C)2021-02-22   (M)2024-05-22
Class: PATCHFamily: unix




The SUSE Linux Enterprise 12 SP3 kernel was updated to receive various security and bug fixes. The following security bugs were fixed: - CVE-2020-25705: A flaw in the way reply ICMP packets are limited in was found that allowed to quickly scan open UDP ports. This flaw allowed an off-path remote user to effectively bypassing source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software and services that rely on UDP source port randomization are indirectly affected as well. Kernel versions may be vulnerable to this issue . - CVE-2020-25668: Fixed a use-after-free in con_font_op . - CVE-2020-25656: Fixed a concurrency use-after-free in vt_do_kdgkb_ioctl . - CVE-2020-14351: Fixed a race in the perf_mmap_close function . - CVE-2020-8694: Restricted energy meter to root access . - CVE-2020-12352: Fixed an information leak when processing certain AMP packets aka quot;BleedingToothquot; . - CVE-2020-25645: Fixed an issue which traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted . - CVE-2020-14381: Fixed a use-after-free in the fast user mutex wait operation, which could have lead to memory corruption and possibly privilege escalation . - CVE-2020-25212: Fixed A TOCTOU mismatch in the NFS client code which could have been used by local attackers to corrupt memory . - CVE-2020-14390: Fixed an out-of-bounds memory write leading to memory corruption or a denial of service when changing screen size . - CVE-2020-25643: Fixed a memory corruption and a read overflow which could have caused by improper input validation in the ppp_cp_parse_cr function . - CVE-2020-25641: Fixed a zero-length biovec request issued by the block subsystem could have caused the kernel to enter an infinite loop, causing a denial of service . - CVE-2020-26088: Fixed an improper CAP_NET_RAW check in NFC socket creation could have been used by local attackers to create raw sockets, bypassing security mechanisms . - CVE-2020-0432: Fixed an out of bounds write due to an integer overflow . - CVE-2020-0431: Fixed an out of bounds write due to a missing bounds check . - CVE-2020-0427: Fixed an out of bounds read due to a use after free . - CVE-2020-0404: Fixed a linked list corruption due to an unusual root cause . - CVE-2020-25284: Fixed an incomplete permission checking for access to rbd devices, which could have been leveraged by local attackers to map or unmap rbd block devices . - CVE-2019-19063: Fixed two memory leaks in the rtl_usb_probe function in drivers/net/wireless/realtek/rtlwifi/usb.c, which could have allowed an attacker to cause a denial of service . - CVE-2019-6133: In PolicyKit , the quot;start timequot; protection mechanism can be bypassed because fork is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c . - CVE-2017-18204: Fixed a denial of service in the ocfs2_setattr function of fs/ocfs2/file.c . The following non-security bugs were fixed: - hv: vmbus: Add timeout to vmbus_wait_for_unload . - hyperv_fb: disable superfluous VERSION_WIN10_V5 case . - hyperv_fb: Update screen_info after removing old framebuffer . - mm, numa: fix bad pmd by atomically check for pmd_trans_huge when marking page tables prot_numa . - net/packet: fix overflow in tpacket_rcv . - ocfs2: give applications more IO opportunities during fstrim . - video: hyperv: hyperv_fb: Obtain screen resolution from Hyper-V host . - video: hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver . - video: hyperv: hyperv_fb: Use physical memory for fb on HyperV Gen 1 VMs . - x86/kexec: Use up-to-dated screen_info copy to fill boot params . - xen/blkback: use lateeoi irq binding . - xen-blkfront: switch kcalloc to kvcalloc for large array allocation . - xen: do not reschedule in preemption off sections . - xen/events: add a new quot;late EOIquot; evtchn framework . - xen/events: add a proper barrier to 2-level uevent unmasking . - xen/events: avoid removing an event channel while handling it . - xen/events: block rogue events for some time . - xen/events: defer eoi in case of excessive number of events . - xen/events: do not use chip_data for legacy IRQs . - xen/events: fix race in evtchn_fifo_unmask . - xen/events: switch user event channels to lateeoi model . - xen/events: use a common cpu hotplug hook for event channels . - xen/netback: use lateeoi irq binding . - xen/pciback: use lateeoi irq binding . - xen/scsiback: use lateeoi irq binding . - xen uses irqdesc::irq_data_common::handler_data to store a per interrupt XEN data pointer which contains XEN specific information . Special Instructions and Notes: Please reboot the system after installing this update.

Platform:
SUSE Linux Enterprise Server 12 SP3
Product:
kernel-default
kernel-syms
Reference:
SUSE-SU-2020:3503-1
CVE-2017-18204
CVE-2019-19063
CVE-2019-6133
CVE-2020-0404
CVE-2020-0427
CVE-2020-0431
CVE-2020-0432
CVE-2020-12352
CVE-2020-14351
CVE-2020-14381
CVE-2020-14390
CVE-2020-25212
CVE-2020-25284
CVE-2020-25641
CVE-2020-25643
CVE-2020-25645
CVE-2020-25656
CVE-2020-25668
CVE-2020-25705
CVE-2020-26088
CVE-2020-8694
CVE    21
CVE-2020-0432
CVE-2017-18204
CVE-2020-0404
CVE-2020-0427
...

© SecPod Technologies