[Forgot Password]
Login  Register Subscribe

30481

 
 

423868

 
 

255116

 
 

909

 
 

198683

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2022:2377-1 -- SLES kernel

ID: oval:org.secpod.oval:def:89046775Date: (C)2022-07-20   (M)2024-05-22
Class: PATCHFamily: unix




The SUSE Linux Enterprise 12 SP5 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2022-29900, CVE-2022-29901: Fixed the RETBLEED attack, a new Spectre like Branch Target Buffer attack, that can leak arbitrary kernel information . - CVE-2022-1679: Fixed a use-after-free in the Atheros wireless driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages . - CVE-2022-20132: Fixed out of bounds read due to improper input validation in lg_probe and related functions of hid-lg.c . - CVE-2022-1012: Fixed information leak caused by small table perturb size in the TCP source port generation algorithm . - CVE-2022-33981: Fixed use-after-free in floppy driver - CVE-2022-20141: Fixed a possible use after free due to improper locking in ip_check_mc_rcu . - CVE-2021-4157: Fixed an out of memory bounds write flaw in the NFS subsystem, related to the replication of files with NFS. A user could potentially crash the system or escalate privileges on the system . - CVE-2022-20154: Fixed a use after free due to a race condition in lock_sock_nested of sock.c. This could lead to local escalation of privilege with System execution privileges needed . - CVE-2020-26541: Enforce the secure boot forbidden signature database protection mechanism. - CVE-2022-2318: Fixed a use-after-free vulnerabilities in the timer handler in net/rose/rose_timer.c that allow attackers to crash the system without any privileges . - CVE-2022-26365, CVE-2022-33740, CVE-2022-33741, CVE-2022-33742: Fixed multiple potential data leaks with Block and Network devices when using untrusted backends . The following non-security bugs were fixed: - audit: fix a race condition with the auditd tracking code . - block: bio-integrity: Advance seed correctly for larger interval sizes . - bnxt_en: Remove the setting of dev_port . - bonding: fix bond_neigh_init . - dm crypt: Avoid percpu_counter spinlock contention in crypt_page_alloc . - drbd: fix duplicate array initializer . - drbd: remove assign_p_sizes_qlim . - drbd: use bdev_alignment_offset instead of queue_alignment_offset . - drbd: use bdev based limit helpers in drbd_send_sizes . - exec: Force single empty string when argv is empty . - ext4: fix bug_on ext4_mb_use_inode_pa . - ext4: fix bug_on in __es_tree_search . - ext4: fix bug_on in ext4_writepages . - ext4: fix overhead calculation to account for the reserved gdt blocks . - ext4: fix race condition between ext4_write and ext4_convert_inline_data . - ext4: fix symlink file size not match to file content . - ext4: fix use-after-free in ext4_rename_dir_prepare . - ext4: force overhead calculation if the s_overhead_cluster makes no sense . - ext4: limit length to bitmap_maxbytes - blocksize in punch_hole . - ext4: make variable count signed . - fs-writeback: writeback_sb_inodes Recalculate "wrote" according skipped pages . - i915_vma: Rename vma_lookup to i915_vma_lookup . - ibmvnic: Properly dispose of all skbs during a failover . - init: Initialize noop_backing_dev_info early . - inotify: show inotify mask flags in proc fdinfo . - Input: bcm5974 - set missing URB_NO_TRANSFER_DMA_MAP urb flag . - Input: elan_i2c - fix regulator enable count imbalance after suspend/resume . - Input: elan_i2c - move regulator_[en|dis]able out of elan_[en|dis]able_power . - Input: omap4-keypad - fix pm_runtime_get_sync error checking . - iomap: iomap_write_failed fix . - kvm: fix wrong exception emulation in check_rdtsc . - kvm: i8254: remove redundant assignment to pointer s . - KVM: LAPIC: Prevent setting the tscdeadline timer if the lapic is hw disabled . - KVM: s390: vsie/gmap: reduce gmap_rmap overhead . - KVM: x86: Allocate new rmap and large page tracking when moving memslot . - KVM: x86: always stop emulation on page fault . - KVM: x86: clear stale x86_emulate_ctxt-intercept value . - KVM: x86: clflushopt should be treated as a no-op by emulation . - kvm: x86/cpuid: Only provide CPUID leaf 0xA if host has architectural PMU . - KVM: x86: Do not force set BSP bit when local APIC is managed by userspace . - KVM: x86: do not modify masked bits of shared MSRs . - KVM: x86/emulator: Defer not-present segment check in __load_segment_descriptor . - KVM: x86: Fix emulation in writing cr8 . - KVM: x86: Fix off-by-one error in kvm_vcpu_ioctl_x86_setup_mce . - KVM: x86: Fix potential put_fpu w/o load_fpu on MPX platform . - KVM: x86: Fix x86_decode_insn return when fetching insn bytes fails . - KVM: x86: Free wbinvd_dirty_mask if vCPU creation fails . - kvm: x86: Improve emulation of CPUID leaves 0BH and 1FH . - KVM: x86: Inject #GP if guest attempts to toggle CR4.LA57 in 64-bit mode . - KVM: x86: Manually calculate reserved bits when loading PDPTRS . - KVM: x86: Manually flush collapsible SPTEs only when toggling flags . - KVM: x86: Migrate the PIT only if vcpu0 is migrated, not any BSP . - KVM: x86/mmu: Treat invalid shadow pages as obsolete . - KVM: x86: Refactor prefix decoding to prevent Spectre-v1/L1TF attacks . - KVM: x86: Remove spurious clearing of async #PF MSR . - KVM: x86: Remove spurious kvm_mmu_unload from vcpu destruction path . - KVM: x86: remove stale comment from struct x86_emulate_ctxt . - KVM: x86: set ctxt-have_exception in x86_decode_insn . - kvm: x86: skip populating logical dest map if apic is not sw enabled . - KVM: x86: Trace the original requested CPUID function in kvm_cpuid . - KVM: x86: Update vCPU"s hv_clock before back to guest when tsc_offset is adjusted . - md: bcache: check the return value of kzalloc in detached_dev_do_request . - md: fix an incorrect NULL check in does_sb_need_changing . - md: fix an incorrect NULL check in md_reload_sb . - md/raid0: Ignore RAID0 layout if the second zone has only one device . - mm: add vma_lookup, update find_vma_intersection comments . - net/mlx5: Avoid double free of root ns in the error flow path . - net/mlx5e: Replace reciprocal_scale in TX select queue function . - net/mlx5e: Switch to Toeplitz RSS hash by default . - net/mlx5: Fix auto group size calculation . - net: qed: Disable aRFS for NPAR and 100G . - net: qede: Disable aRFS for NPAR and 100G . - net: stmmac: update rx tail pointer register to fix rx dma hang issue . - NFSD: Fix possible sleep during nfsd4_release_lockowner . - NFS: Further fixes to the writeback error handling . - PCI/ACPI: Allow D3 only if Root Port can signal and wake from D3 . - PCI: Tidy comments . - platform/chrome: cros_ec_proto: Send command again when timeout occurs . - powerpc/idle: Fix return value of __setup handler . - powerpc/perf: Fix the threshold compare group constraint for power9 . - powerpc/rtas: Allow ibm,platform-dump RTAS call with null buffer address . - qed: Enable automatic recovery on error condition . - raid5: introduce MD_BROKEN . - s390: fix detection of vector enhancements facility 1 vs. vector packed decimal facility . - s390: fix strrchr implementation . - s390/ftrace: fix ftrace_update_ftrace_func implementation . - s390/gmap: do not unconditionally call pte_unmap_unlock in __gmap_zap . - s390/gmap: validate VMA in __gmap_zap . - s390/mm: fix VMA and page table handling code in storage key handling functions . - s390/mm: validate VMA in PGSTE manipulation functions . - scsi: dc395x: Fix a missing check on list iterator . - scsi: ufs: qcom: Add a readl to make sure ref_clk gets enabled . - scsi: ufs: qcom: Fix ufs_qcom_resume . - SUNRPC: Fix the calculation of xdr-end in xdr_get_next_encode_buffer . - target: remove an incorrect unmap zeroes data deduction . - tracing: Fix return value of trace_pid_write . - usb: musb: Fix missing of_node_put in omap2430_probe . - USB: serial: option: add Quectel BG95 modem . - USB: storage: karma: fix rio_karma_init return . - usb: usbip: add missing device lock on tweak configuration cmd . - usb: usbip: fix a refcount leak in stub_probe . - video: fbdev: clcdfb: Fix refcount leak in clcdfb_of_vram_setup - writeback: Avoid skipping inode writeback . - writeback: Fix inode-i_io_list not be protected by inode-i_lock error . Special Instructions and Notes: Please reboot the system after installing this update.

Platform:
SUSE Linux Enterprise Server 12 SP5
Product:
kernel
Reference:
SUSE-SU-2022:2377-1
CVE-2020-26541
CVE-2021-4157
CVE-2022-1012
CVE-2022-1679
CVE-2022-20132
CVE-2022-20141
CVE-2022-20154
CVE-2022-2318
CVE-2022-26365
CVE-2022-29900
CVE-2022-29901
CVE-2022-33740
CVE-2022-33741
CVE-2022-33742
CVE-2022-33981
CVE    15
CVE-2022-20132
CVE-2021-4157
CVE-2022-1012
CVE-2022-2318
...

© SecPod Technologies