OESA-2021-1003

Source
https://www.openeuler.org/en/security/security-bulletins/detail/?id=openEuler-SA-2021-1003
Import Source
https://repo.openeuler.org/security/data/osv/OESA-2021-1003.json
JSON Data
https://api.test.osv.dev/v1/vulns/OESA-2021-1003
Upstream
Published
2021-02-04T11:02:33Z
Modified
2025-08-12T05:05:01.914850Z
Summary
kernel security update
Details

The Linux Kernel, the operating system core itself.

Security Fix(es):

A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local attacker with permission to monitor perf events to corrupt memory and possibly escalate privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.(CVE-2020-14351)

An issue was discovered in the Linux kernel through 5.9.1, as used with Xen through 4.14.x. drivers/xen/events/events_base.c allows event-channel removal during the event-handling loop (a race condition). This can cause a use-after-free or NULL pointer dereference, as demonstrated by a dom0 crash via events for an in-reconfiguration paravirtualized device, aka CID-073d0552ead5.(CVE-2020-27675)

A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is to data confidentiality.(CVE-2020-25656)

Improper access control in BlueZ may allow an unauthenticated user to potentially enable information disclosure via adjacent access.(CVE-2020-12352)

A locking issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/tty_jobctrl.c allows a use-after-free attack against TIOCSPGRP, aka CID-54ffccbf053b.(CVE-2020-29661)

A flaw was found in the way RTAS handled memory accesses in userspace to kernel communication. On a locked down (usually due to Secure Boot) guest system running on top of PowerVM or KVM hypervisors (pseries platform) a root like local user could use this flaw to further increase their privileges to that of a running kernel.(CVE-2020-27777)

A locking inconsistency issue was discovered in the tty subsystem of the Linux kernel through 5.9.13. drivers/tty/ttyio.c and drivers/tty/ttyjobctrl.c may allow a read-after-free attack against TIOCGSID, aka CID-c8bcd9c5be24.(CVE-2020-29660)

An issue was discovered in the Linux kernel through 5.10.1, as used with Xen through 4.14.x. The Linux kernel PV block backend expects the kernel thread handler to reset ring->xenblkd to NULL when stopped. However, the handler may not have time to run if the frontend quickly toggles between the states connect and disconnect. As a consequence, the block backend may re-use a pointer after it was freed. A misbehaving guest can trigger a dom0 crash by continuously connecting / disconnecting a block frontend. Privilege escalation and information leaks cannot be ruled out. This only affects systems with a Linux blkback.(CVE-2020-29569)

A flaw was found in the JFS filesystem code. This flaw allows a local attacker with the ability to set extended attributes to panic the system, causing memory corruption or escalating privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.(CVE-2020-27815)

A vulnerability was found in Linux Kernel where in the spkttyioreceivebuf2() function, it would dereference spkttyio_synth without checking whether it is NULL or not, and may lead to a NULL-ptr deref crash.(CVE-2020-27830)

Database specific
{
    "severity": "High"
}
References

Affected packages

openEuler:20.03-LTS / kernel

Package

Name
kernel
Purl
pkg:rpm/openEuler/kernel&distro=openEuler-20.03-LTS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.19.90-2101.1.0.0055.oe1

Ecosystem specific

{
    "x86_64": [
        "bpftool-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "bpftool-debuginfo-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-debuginfo-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-debugsource-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-devel-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-source-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-tools-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-tools-debuginfo-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-tools-devel-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "perf-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "perf-debuginfo-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "python2-perf-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "python2-perf-debuginfo-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "python3-perf-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "python3-perf-debuginfo-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "bpftool-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "bpftool-debuginfo-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-debuginfo-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-debugsource-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-devel-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-source-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-tools-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-tools-debuginfo-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-tools-devel-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "perf-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "perf-debuginfo-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "python2-perf-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "python2-perf-debuginfo-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "python3-perf-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "python3-perf-debuginfo-4.19.90-2101.1.0.0055.oe1.x86_64.rpm"
    ],
    "src": [
        "kernel-4.19.90-2101.1.0.0055.oe1.src.rpm",
        "kernel-4.19.90-2101.1.0.0055.oe1.src.rpm"
    ],
    "aarch64": [
        "bpftool-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "bpftool-debuginfo-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-debuginfo-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-debugsource-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-devel-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-source-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-tools-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-tools-debuginfo-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-tools-devel-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "perf-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "perf-debuginfo-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "python2-perf-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "python2-perf-debuginfo-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "python3-perf-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "python3-perf-debuginfo-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "bpftool-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "bpftool-debuginfo-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-debuginfo-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-debugsource-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-devel-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-source-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-tools-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-tools-debuginfo-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-tools-devel-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "perf-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "perf-debuginfo-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "python2-perf-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "python2-perf-debuginfo-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "python3-perf-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "python3-perf-debuginfo-4.19.90-2101.1.0.0055.oe1.aarch64.rpm"
    ]
}

openEuler:20.03-LTS-SP1 / kernel

Package

Name
kernel
Purl
pkg:rpm/openEuler/kernel&distro=openEuler-20.03-LTS-SP1

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.19.90-2101.1.0.0055.oe1

Ecosystem specific

{
    "x86_64": [
        "bpftool-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "bpftool-debuginfo-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-debuginfo-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-debugsource-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-devel-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-source-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-tools-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-tools-debuginfo-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "kernel-tools-devel-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "perf-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "perf-debuginfo-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "python2-perf-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "python2-perf-debuginfo-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "python3-perf-4.19.90-2101.1.0.0055.oe1.x86_64.rpm",
        "python3-perf-debuginfo-4.19.90-2101.1.0.0055.oe1.x86_64.rpm"
    ],
    "src": [
        "kernel-4.19.90-2101.1.0.0055.oe1.src.rpm"
    ],
    "aarch64": [
        "bpftool-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "bpftool-debuginfo-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-debuginfo-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-debugsource-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-devel-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-source-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-tools-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-tools-debuginfo-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "kernel-tools-devel-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "perf-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "perf-debuginfo-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "python2-perf-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "python2-perf-debuginfo-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "python3-perf-4.19.90-2101.1.0.0055.oe1.aarch64.rpm",
        "python3-perf-debuginfo-4.19.90-2101.1.0.0055.oe1.aarch64.rpm"
    ]
}