MGASA-2021-0574

Source
https://advisories.mageia.org/MGASA-2021-0574.html
Import Source
https://advisories.mageia.org/MGASA-2021-0574.json
JSON Data
https://api.test.osv.dev/v1/vulns/MGASA-2021-0574
Related
Published
2021-12-21T23:27:37Z
Modified
2022-02-17T18:21:47Z
Summary
Updated kernel packages fix security vulnerabilities
Details

This kernel update is based on upstream 5.15.10 and fixes at least the following security issues:

A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call close() and fget() simultaneously and can potentially trigger a race condition. This flaw allows a local user to crash the system or escalate their privileges on the system (CVE-2021-4083).

An attacker can access kernel memory bypassing valid buffer boundaries by exploiting implementation of control request handlers in the following usb gadgets - rndis, hid, uac1, uac1_legacy and uac2. Processing of malicious control transfer requests with unexpectedly large wLength lacks assurance that this value does not exceed the buffer size. Due to this fact one is capable of reading and/or writing (depending on particular case) up to 65k of kernel memory. Devices implementing affected usb device gadget classes may be affected by buffer overflow vulnerabilities resulting in information disclosure, denial of service or execution of arbitrary code in kernel context (CVE-2021-39685).

In the Linux kernel through 5.15.2, hwatlutilsfwrpcwait in drivers/net/ ethernet/aquantia/atlantic/hwatl/hwatlutils.c allows an attacker (who can introduce a crafted device) to trigger an out-of-bounds write via a crafted length value (CVE-2021-43975).

In addition to the upstream changes, we also have added the following fixes: - [Bug 29704] Kernel 5.15.4 + Nouveau = flickering Plasma DE - [Bug 29711] Firefox under plasma doesn't display gui with kernel 5.15.4 and other gui issues. - [Bug 29760] Kernel 5.15.x breaks bluetooth on Lifebook A555 - Add AHCI support for ASM1062+JBM575 cards - fget: clarify and improve _fgetfiles() implementation - drm/i915/gen11: Moving WAs to iclgtworkarounds_init() - HID: holtek: fix mouse probing - iwlwifi: add new killer devices to the driver - iwlwifi: add new device id 7F70 - iwlwifi: pcie: fix killer name matching for AX200 - iwlwifi: pcie: remove two duplicate PNJ device entries - iwlwifi: add missing entries for Gf4 with So and SoF - iwlwifi: swap 1650i and 1650s killer struct names - iwlwifi: add new Qu-Hr device - iwlwifi: add new ax1650 killer device - rtw88: 8821c: support RFE type4 wifi NIC - rtw88: 8821c: correct 2.4G tx power for type 2/4 NIC - rtw88: 8821c: disable the ASPM of RTL8821CE as it causes systems to hang

For other upstream fixes, see the referenced changelogs.

References
Credits

Affected packages

Mageia:8 / kernel

Package

Name
kernel
Purl
pkg:rpm/mageia/kernel?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
5.15.10-1.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / kmod-virtualbox

Package

Name
kmod-virtualbox
Purl
pkg:rpm/mageia/kmod-virtualbox?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
6.1.30-1.5.mga8

Ecosystem specific

{
    "section": "core"
}

Mageia:8 / kmod-xtables-addons

Package

Name
kmod-xtables-addons
Purl
pkg:rpm/mageia/kmod-xtables-addons?distro=mageia-8

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
3.18-1.38.mga8

Ecosystem specific

{
    "section": "core"
}