MGASA-2021-0192

Source
https://advisories.mageia.org/MGASA-2021-0192.html
Import Source
https://advisories.mageia.org/MGASA-2021-0192.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2021-0192
Related
Published
2021-04-18T14:50:05Z
Modified
2022-02-17T18:21:47Z
Summary
Updated kernel packages fix security vulnerabilities
Details

This kernel update is based on upstream 5.10.30 and fixes at least the following security issues:

nfc: fix refcount leak in llcpsockbind() (CVE-2020-25670)

nfc: fix refcount leak in llcpsockconnect() (CVE-2020-25671)

nfc: fix memory leak in llcpsockconnect() (CVE-2020-25672)

firewire: nosy: Fix a use-after-free bug in nosy_ioctl() (CVE-2021-3483)

BPF JIT compilers in the Linux kernel through 5.11.12 have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context (CVE-2021-29154).

KVM: SVM: load control fields from VMCB12 before checking them (CVE-2021-29657).

It also adds the following fixes: - x86/fpu/64: Don't FNINIT in kernelfpubegin() - Revert "iommu/amd: Fix performance counter initialization" - iommu/amd: Remove performance counter pre-initialization test - hwmon: (amdenergy) Add AMD family 19h model 30h x86 match - hwmon: (amdenergy) Use unified function to read energy data - hwmon: (amd_energy) Restore visibility of energy counters

For other upstream fixes, see the referenced changelogs.

References
Credits

Affected packages

Mageia:8 / kernel

Package

Name
kernel
Purl
pkg:rpm/mageia/kernel?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.10.30-1.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / kmod-virtualbox

Package

Name
kmod-virtualbox
Purl
pkg:rpm/mageia/kmod-virtualbox?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.1.18-24.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / kmod-xtables-addons

Package

Name
kmod-xtables-addons
Purl
pkg:rpm/mageia/kmod-xtables-addons?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.13-40.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:7 / kernel

Package

Name
kernel
Purl
pkg:rpm/mageia/kernel?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.10.30-1.mga7

Ecosystem specific

{
    "section": "core"
}

Mageia:7 / kmod-virtualbox

Package

Name
kmod-virtualbox
Purl
pkg:rpm/mageia/kmod-virtualbox?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.1.18-14.mga7

Ecosystem specific

{
    "section": "core"
}

Mageia:7 / kmod-xtables-addons

Package

Name
kmod-xtables-addons
Purl
pkg:rpm/mageia/kmod-xtables-addons?distro=mageia-7

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.13-20.mga7

Ecosystem specific

{
    "section": "core"
}