SUSE-SU-2022:0362-1
Vulnerability Summary
Timeline
Description
Security update for the Linux Kernel The SUSE Linux Enterprise 12 SP3 LTSS kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-25020: Fixed an overflow in the BPF subsystem due to a mishandling of a long jump over an instruction sequence where inner instructions require substantial expansions into multiple BPF instructions. This affects kernel/bpf/core.c and net/core/filter.c (bnc#1193575). - CVE-2019-0136: Fixed insufficient access control in the Intel(R) PROSet/Wireless WiFi Software driver that may have allowed an unauthenticated user to potentially enable denial of service via adjacent access (bnc#1193157). - CVE-2020-35519: Fixed out-of-bounds memory access in x25_bind in net/x25/af_x25.c. A bounds check failure allowed a local attacker with a user account on the system to gain access to out-of-bounds memory, leading to a system crash or a leak of internal kernel information (bnc#1183696). - CVE-2021-0935: Fixed possible out of bounds write in ip6_xmit of ip6_output.c due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation (bnc#1192032). - CVE-2021-28711: Fixed issue with xen/blkfront to harden blkfront against event channel storms (XSA-391) (bsc#1193440). - CVE-2021-28712: Fixed issue with xen/netfront to harden netfront against event channel storms (XSA-391) (bsc#1193440). - CVE-2021-28713: Fixed issue with xen/console to harden hvc_xen against event channel storms (XSA-391) (bsc#1193440). - CVE-2021-28715: Fixed issue with xen/netback to do not queue unlimited number of packages (XSA-392) (bsc#1193442). - CVE-2021-33098: Fixed improper input validation in the Intel(R) Ethernet ixgbe driver that may have allowed an authenticated user to potentially cause denial of service via local access (bnc#1192877). - CVE-2021-3564: Fixed double-free memory corruption in the Linux kernel HCI device initialization subsystem that could have been used by attaching malicious HCI TTY Bluetooth devices. A local user could use this flaw to crash the system (bnc#1186207). - CVE-2021-39648: Fixed possible disclosure of kernel heap memory due to a race condition in gadget_dev_desc_UDC_show of configfs.c. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation (bnc#1193861). - CVE-2021-39657: Fixed out of bounds read due to a missing bounds check in ufshcd_eh_device_reset_handler of ufshcd.c. This could lead to local information disclosure with System execution privileges needed (bnc#1193864). - CVE-2021-4002: Fixed incorrect TLBs flush in hugetlbfs after huge_pmd_unshare (bsc#1192946). - CVE-2021-4083: Fixed a read-after-free memory flaw inside the garbage collection for Unix domain socket file handlers when users call close() and fget() simultaneouslyand can potentially trigger a race condition (bnc#1193727). - CVE-2021-4149: Fixed btrfs unlock newly allocated extent buffer after error (bsc#1194001). - CVE-2021-4155: Fixed XFS map issue when unwritten blocks in XFS_IOC_{ALLOC,FREE}SP just like fallocate (bsc#1194272). - CVE-2021-4197: Use cgroup open-time credentials for process migraton perm checks (bsc#1194302). - CVE-2021-4202: Fixed NFC race condition by adding NCI_UNREG flag (bsc#1194529). - CVE-2021-43976: Fixed insufficient access control in drivers/net/wireless/marvell/mwifiex/usb.c that allowed an attacker who connect a crafted USB device to cause denial of service (bnc#1192847). - CVE-2021-45095: Fixed refcount leak in pep_sock_accept in net/phonet/pep.c (bnc#1193867). - CVE-2021-45485: Fixed information leak in the IPv6 implementation in net/ipv6/output_core.c (bnc#1194094). - CVE-2021-45486: Fixed information leak inside the IPv4 implementation caused by very small hash table (bnc#1194087). - CVE-2022-0330: Fixed flush TLBs before releasing backing store (bsc#1194880). The following non-security bugs were fixed: - fget: clarify and improve __fget_files() implementation (bsc#1193727). - hv_netvsc: Fix the queue_mapping in netvsc_vf_xmit() (bsc#1193507). - hv_netvsc: Set needed_headroom according to VF (bsc#1193507). - kprobes: Limit max data_size of the kretprobe instances (bsc#1193669). - memstick: rtsx_usb_ms: fix UAF - moxart: fix potential use-after-free on remove path (bsc1194516). - net/x25: fix a race in x25_bind() (networking-stable-19_03_15). - net: mana: Add RX fencing (bsc#1193507). - net: mana: Allow setting the number of queues while the NIC is down (bsc#1193507). - net: mana: Fix spelling mistake 'calledd' -> 'called' (bsc#1193507). - net: mana: Fix the netdev_err()'s vPort argument in mana_init_port() (bsc#1193507). - net: mana: Improve the HWC error handling (bsc#1193507). - net: mana: Support hibernation and kexec (bsc#1193507). - net: mana: Use kcalloc() instead of kzalloc() (bsc#1193507). - recordmcount.pl: fix typo in s390 mcount regex (bsc#1192267). - recordmcount.pl: look for jgnop instruction as well as bcrl on s390 (bsc#1192267). - ring-buffer: Protect ring_buffer_reset() from reentrancy (bsc#1179960). - tty: hvc: replace BUG_ON() with negative return value (git-fixes). - xen-netfront: do not assume sk_buff_head list is empty in error handling (git-fixes). - xen-netfront: do not use ~0U as error return value for xennet_fill_frags() (git-fixes). - xen/blkfront: do not take local copy of a request from the ring page (git-fixes). - xen/blkfront: do not trust the backend response data blindly (git-fixes). - xen/blkfront: read response from backend only once (git-fixes). - xen/netfront: disentangle tx_skb_freelist (git-fixes). - xen/netfront: do not bug in case of too many frags (bnc#1012382). - xen/netfront: do not cache skb_shinfo() (bnc#1012382). - xen/netfront: do not read data from request on the ring page (git-fixes). - xen/netfront: do not trust the backend response data blindly (git-fixes). - xen/netfront: read response from backend only once (git-fixes). - xen: sync include/xen/interface/io/ring.h with Xen's newest version (git-fixes).
Affected Systems
- suse•kernel-default&distro=HPE Helion OpenStack 8
< 4.4.180-94.153.1
- suse•kernel-default&distro=SUSE Linux Enterprise High Availability Extension 12 SP3
< 4.4.180-94.153.1
- suse•kernel-default&distro=SUSE Linux Enterprise Server 12 SP3-BCL
< 4.4.180-94.153.1
- suse•kernel-default&distro=SUSE Linux Enterprise Server 12 SP3-LTSS
< 4.4.180-94.153.1
- suse•kernel-default&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP3
< 4.4.180-94.153.1
- suse•kernel-default&distro=SUSE OpenStack Cloud 8
< 4.4.180-94.153.1
- suse•kernel-default&distro=SUSE OpenStack Cloud Crowbar 8
< 4.4.180-94.153.1
- suse•kernel-source&distro=HPE Helion OpenStack 8
< 4.4.180-94.153.1
- suse•kernel-source&distro=SUSE Linux Enterprise Server 12 SP3-BCL
< 4.4.180-94.153.1
- suse•kernel-source&distro=SUSE Linux Enterprise Server 12 SP3-LTSS
< 4.4.180-94.153.1
- suse•kernel-source&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP3
< 4.4.180-94.153.1
- suse•kernel-source&distro=SUSE OpenStack Cloud 8
< 4.4.180-94.153.1
- suse•kernel-source&distro=SUSE OpenStack Cloud Crowbar 8
< 4.4.180-94.153.1
- suse•kernel-syms&distro=HPE Helion OpenStack 8
< 4.4.180-94.153.1
- suse•kernel-syms&distro=SUSE Linux Enterprise Server 12 SP3-BCL
< 4.4.180-94.153.1
- suse•kernel-syms&distro=SUSE Linux Enterprise Server 12 SP3-LTSS
< 4.4.180-94.153.1
- suse•kernel-syms&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP3
< 4.4.180-94.153.1
- suse•kernel-syms&distro=SUSE OpenStack Cloud 8
< 4.4.180-94.153.1
- suse•kernel-syms&distro=SUSE OpenStack Cloud Crowbar 8
< 4.4.180-94.153.1
- suse•kgraft-patch-SLE12-SP3_Update_42&distro=HPE Helion OpenStack 8
< 1-4.3.1
- suse•kgraft-patch-SLE12-SP3_Update_42&distro=SUSE Linux Enterprise Server 12 SP3-LTSS
< 1-4.3.1
- suse•kgraft-patch-SLE12-SP3_Update_42&distro=SUSE Linux Enterprise Server for SAP Applications 12 SP3
< 1-4.3.1
- suse•kgraft-patch-SLE12-SP3_Update_42&distro=SUSE OpenStack Cloud 8
< 1-4.3.1
- suse•kgraft-patch-SLE12-SP3_Update_42&distro=SUSE OpenStack Cloud Crowbar 8
< 1-4.3.1
References (51)
- https://www.suse.com/support/update/announcement/2022/suse-su-20220362-1/
- https://bugzilla.suse.com/1012382
- https://bugzilla.suse.com/1179960
- https://bugzilla.suse.com/1183696
- https://bugzilla.suse.com/1186207
- https://bugzilla.suse.com/1192032
- https://bugzilla.suse.com/1192267
- https://bugzilla.suse.com/1192847
- https://bugzilla.suse.com/1192877
- https://bugzilla.suse.com/1192946
- https://bugzilla.suse.com/1193157
- https://bugzilla.suse.com/1193440
- https://bugzilla.suse.com/1193442
- https://bugzilla.suse.com/1193507
- https://bugzilla.suse.com/1193575
- https://bugzilla.suse.com/1193669
- https://bugzilla.suse.com/1193727
- https://bugzilla.suse.com/1193861
- https://bugzilla.suse.com/1193864
- https://bugzilla.suse.com/1193867
- https://bugzilla.suse.com/1194001
- https://bugzilla.suse.com/1194087
- https://bugzilla.suse.com/1194094
- https://bugzilla.suse.com/1194272
- https://bugzilla.suse.com/1194302
- https://bugzilla.suse.com/1194516
- https://bugzilla.suse.com/1194529
- https://bugzilla.suse.com/1194880
- https://www.suse.com/security/cve/CVE-2018-25020
- https://www.suse.com/security/cve/CVE-2019-0136
- https://www.suse.com/security/cve/CVE-2020-35519
- https://www.suse.com/security/cve/CVE-2021-0935
- https://www.suse.com/security/cve/CVE-2021-28711
- https://www.suse.com/security/cve/CVE-2021-28712
- https://www.suse.com/security/cve/CVE-2021-28713
- https://www.suse.com/security/cve/CVE-2021-28715
- https://www.suse.com/security/cve/CVE-2021-33098
- https://www.suse.com/security/cve/CVE-2021-3564
- https://www.suse.com/security/cve/CVE-2021-39648
- https://www.suse.com/security/cve/CVE-2021-39657
- https://www.suse.com/security/cve/CVE-2021-4002
- https://www.suse.com/security/cve/CVE-2021-4083
- https://www.suse.com/security/cve/CVE-2021-4149
- https://www.suse.com/security/cve/CVE-2021-4155
- https://www.suse.com/security/cve/CVE-2021-4197
- https://www.suse.com/security/cve/CVE-2021-4202
- https://www.suse.com/security/cve/CVE-2021-43976
- https://www.suse.com/security/cve/CVE-2021-45095
- https://www.suse.com/security/cve/CVE-2021-45485
- https://www.suse.com/security/cve/CVE-2021-45486
- https://www.suse.com/security/cve/CVE-2022-0330