SUSE-SU-2020:3501-1

Source
https://www.suse.com/support/update/announcement/2020/suse-su-20203501-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:3501-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2020:3501-1
Related
Published
2020-11-24T13:31:07Z
Modified
2020-11-24T13:31:07Z
Summary
Security update for the Linux Kernel
Details

The SUSE Linux Enterprise 12 SP2 kernel was updated to receive various security and bug fixes.

The following security bugs were fixed:

  • CVE-2020-25705: A flaw in the way reply ICMP packets are limited in was found that allowed to quickly scan open UDP ports. This flaw allowed an off-path remote user to effectively bypassing source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software and services that rely on UDP source port randomization (like DNS) are indirectly affected as well. Kernel versions may be vulnerable to this issue (bsc#1175721, bsc#1178782).
  • CVE-2020-25656: Fixed a concurrency use-after-free in vtdokdgkb_ioctl (bnc#1177766).
  • CVE-2017-18204: Fixed a denial of service in the ocfs2_setattr function of fs/ocfs2/file.c (bnc#1083244).
  • CVE-2020-14351: Fixed a race in the perfmmapclose() function (bsc#1177086).
  • CVE-2020-8694: Restricted energy meter to root access (bsc#1170415).
  • CVE-2020-12352: Fixed an information leak when processing certain AMP packets aka 'BleedingTooth' (bsc#1177725).
  • CVE-2020-25645: Fixed an an issue in IPsec that caused traffic between two Geneve endpoints to be unencrypted (bnc#1177511).
  • CVE-2020-14381: Fixed a use-after-free in the fast user mutex (futex) wait operation, which could have lead to memory corruption and possibly privilege escalation (bsc#1176011).
  • CVE-2020-25212: Fixed A TOCTOU mismatch in the NFS client code which could have been used by local attackers to corrupt memory (bsc#1176381).
  • CVE-2020-14390: Fixed an out-of-bounds memory write leading to memory corruption or a denial of service when changing screen size (bnc#1176235).
  • CVE-2020-25643: Fixed a memory corruption and a read overflow which could have caused by improper input validation in the pppcpparse_cr function (bsc#1177206).
  • CVE-2020-26088: Fixed an improper CAPNETRAW check in NFC socket creation could have been used by local attackers to create raw sockets, bypassing security mechanisms (bsc#1176990).
  • CVE-2020-0432: Fixed an out of bounds write due to an integer overflow (bsc#1176721).
  • CVE-2020-0431: Fixed an out of bounds write due to a missing bounds check (bsc#1176722).
  • CVE-2020-0427: Fixed an out of bounds read due to a use after free (bsc#1176725).
  • CVE-2020-0404: Fixed a linked list corruption due to an unusual root cause (bsc#1176423).
  • CVE-2020-25284: Fixed an incomplete permission checking for access to rbd devices, which could have been leveraged by local attackers to map or unmap rbd block devices (bsc#1176482).

The following non-security bugs were fixed:

  • btrfs: fix race with relocation recovery and fs_root setup (bsc#1131277).
  • btrfs: flushspace always takes fsinfo->fs_root (bsc#1131277).
  • btrfs: btrfsinitnewdevice should use fsinfo->dev_root (bsc#1131277, bsc#1176922).
  • btrfs: btrfstestopt and friends should take a btrfsfsinfo (bsc#1131277, bsc#1176922).
  • btrfs: call functions that always use the same root with fs_info instead (bsc#1131277, bsc#1176922).
  • btrfs: call functions that overwrite their root parameter with fs_info (bsc#1131277, bsc#1176922).
  • btrfs: flushspace always takes fsinfo->fs_root (bsc#1131277, bsc#1176922).
  • btrfs: pull node/sector/stripe sizes out of root and into fs_info (bsc#1131277, bsc#1176922).
  • btrfs: Remove fsinfo argument of btrfswriteandwait_transaction (bsc#1131277, bsc#1176922).
  • btrfs: remove root parameter from transaction commit/end routines (bsc#1131277, bsc#1176922).
  • btrfs: remove root usage from can_overcommit (bsc#1131277, bsc#1176922).
  • btrfs: root->fsinfo cleanup, access fsinfo->delayed_root directly (bsc#1131277, bsc#1176922).
  • btrfs: root->fsinfo cleanup, add fsinfo convenience variables (bsc#1131277, bsc#1176922).
  • btrfs: root->fsinfo cleanup, btrfscalc{trans,trunc}metadata_size (bsc#1131277, bsc#1176922).
  • btrfs: root->fsinfo cleanup, updateblock_group{,flags} (bsc#1131277, bsc#1176922).
  • btrfs: root->fsinfo cleanup, use fsinfo->dev_root everywhere (bsc#1131277, bsc#1176922).
  • btrfs: split btrfswaitmarked_extents into normal and tree log functions (bsc#1131277, bsc#1176922).
  • btrfs: struct btrfsicstate->root should be an fsinfo (bsc#1131277, bsc#1176922).
  • btrfs: take an fs_info directly when the root is not used otherwise (bsc#1131277, bsc#1176922).
  • xen/blkback: use lateeoi irq binding (XSA-332 bsc#1177411).
  • xen: do not reschedule in preemption off sections (bsc#1175749).
  • xen/events: add a new 'late EOI' evtchn framework (XSA-332 bsc#1177411).
  • xen/events: add a proper barrier to 2-level uevent unmasking (XSA-332 bsc#1177411).
  • xen/events: avoid removing an event channel while handling it (XSA-331 bsc#1177410).
  • xen/events: block rogue events for some time (XSA-332 bsc#1177411).
  • xen/events: defer eoi in case of excessive number of events (XSA-332 bsc#1177411).
  • xen/events: do not use chip_data for legacy IRQs (XSA-332 bsc#1065600).
  • xen/events: fix race in evtchnfifounmask() (XSA-332 bsc#1177411).
  • xen/events: switch user event channels to lateeoi model (XSA-332 bsc#1177411).
  • xen/events: use a common cpu hotplug hook for event channels (XSA-332 bsc#1177411).
  • xen/netback: use lateeoi irq binding (XSA-332 bsc#1177411).
  • xen/pciback: use lateeoi irq binding (XSA-332 bsc#1177411).
  • xen/scsiback: use lateeoi irq binding (XSA-332 bsc#1177411).
  • XEN uses irqdesc::irqdatacommon::handler_data to store a per interrupt XEN data pointer which contains XEN specific information (XSA-332 bsc#1065600).
References

Affected packages

SUSE:OpenStack Cloud 7 / kernel-default

Package

Name
kernel-default
Purl
purl:rpm/suse/kernel-default&distro=SUSE%20OpenStack%20Cloud%207

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.121-92.146.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.4.121-92.146.1",
            "kernel-devel": "4.4.121-92.146.1",
            "kernel-default-base": "4.4.121-92.146.1",
            "kernel-default-man": "4.4.121-92.146.1",
            "kgraft-patch-4_4_121-92_146-default": "1-3.5.1",
            "kernel-default": "4.4.121-92.146.1",
            "kernel-source": "4.4.121-92.146.1",
            "kernel-syms": "4.4.121-92.146.1",
            "kernel-default-devel": "4.4.121-92.146.1"
        }
    ]
}

SUSE:OpenStack Cloud 7 / kernel-source

Package

Name
kernel-source
Purl
purl:rpm/suse/kernel-source&distro=SUSE%20OpenStack%20Cloud%207

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.121-92.146.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.4.121-92.146.1",
            "kernel-devel": "4.4.121-92.146.1",
            "kernel-default-base": "4.4.121-92.146.1",
            "kernel-default-man": "4.4.121-92.146.1",
            "kgraft-patch-4_4_121-92_146-default": "1-3.5.1",
            "kernel-default": "4.4.121-92.146.1",
            "kernel-source": "4.4.121-92.146.1",
            "kernel-syms": "4.4.121-92.146.1",
            "kernel-default-devel": "4.4.121-92.146.1"
        }
    ]
}

SUSE:OpenStack Cloud 7 / kernel-syms

Package

Name
kernel-syms
Purl
purl:rpm/suse/kernel-syms&distro=SUSE%20OpenStack%20Cloud%207

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.121-92.146.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.4.121-92.146.1",
            "kernel-devel": "4.4.121-92.146.1",
            "kernel-default-base": "4.4.121-92.146.1",
            "kernel-default-man": "4.4.121-92.146.1",
            "kgraft-patch-4_4_121-92_146-default": "1-3.5.1",
            "kernel-default": "4.4.121-92.146.1",
            "kernel-source": "4.4.121-92.146.1",
            "kernel-syms": "4.4.121-92.146.1",
            "kernel-default-devel": "4.4.121-92.146.1"
        }
    ]
}

SUSE:OpenStack Cloud 7 / kgraft-patch-SLE12-SP2_Update_38

Package

Name
kgraft-patch-SLE12-SP2_Update_38
Purl
purl:rpm/suse/kgraft-patch-SLE12-SP2_Update_38&distro=SUSE%20OpenStack%20Cloud%207

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1-3.5.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.4.121-92.146.1",
            "kernel-devel": "4.4.121-92.146.1",
            "kernel-default-base": "4.4.121-92.146.1",
            "kernel-default-man": "4.4.121-92.146.1",
            "kgraft-patch-4_4_121-92_146-default": "1-3.5.1",
            "kernel-default": "4.4.121-92.146.1",
            "kernel-source": "4.4.121-92.146.1",
            "kernel-syms": "4.4.121-92.146.1",
            "kernel-default-devel": "4.4.121-92.146.1"
        }
    ]
}

SUSE:Linux Enterprise High Availability Extension 12 SP2 / kernel-default

Package

Name
kernel-default
Purl
purl:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.121-92.146.1

Ecosystem specific

{
    "binaries": [
        {
            "dlm-kmp-default": "4.4.121-92.146.1",
            "gfs2-kmp-default": "4.4.121-92.146.1",
            "cluster-network-kmp-default": "4.4.121-92.146.1",
            "ocfs2-kmp-default": "4.4.121-92.146.1",
            "cluster-md-kmp-default": "4.4.121-92.146.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP2 / kernel-default

Package

Name
kernel-default
Purl
purl:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.121-92.146.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.4.121-92.146.1",
            "kernel-devel": "4.4.121-92.146.1",
            "kernel-default-base": "4.4.121-92.146.1",
            "kgraft-patch-4_4_121-92_146-default": "1-3.5.1",
            "kernel-default": "4.4.121-92.146.1",
            "kernel-source": "4.4.121-92.146.1",
            "kernel-syms": "4.4.121-92.146.1",
            "kernel-default-devel": "4.4.121-92.146.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP2 / kernel-source

Package

Name
kernel-source
Purl
purl:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.121-92.146.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.4.121-92.146.1",
            "kernel-devel": "4.4.121-92.146.1",
            "kernel-default-base": "4.4.121-92.146.1",
            "kgraft-patch-4_4_121-92_146-default": "1-3.5.1",
            "kernel-default": "4.4.121-92.146.1",
            "kernel-source": "4.4.121-92.146.1",
            "kernel-syms": "4.4.121-92.146.1",
            "kernel-default-devel": "4.4.121-92.146.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP2 / kernel-syms

Package

Name
kernel-syms
Purl
purl:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.121-92.146.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.4.121-92.146.1",
            "kernel-devel": "4.4.121-92.146.1",
            "kernel-default-base": "4.4.121-92.146.1",
            "kgraft-patch-4_4_121-92_146-default": "1-3.5.1",
            "kernel-default": "4.4.121-92.146.1",
            "kernel-source": "4.4.121-92.146.1",
            "kernel-syms": "4.4.121-92.146.1",
            "kernel-default-devel": "4.4.121-92.146.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP2 / kgraft-patch-SLE12-SP2_Update_38

Package

Name
kgraft-patch-SLE12-SP2_Update_38
Purl
purl:rpm/suse/kgraft-patch-SLE12-SP2_Update_38&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP2

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1-3.5.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.4.121-92.146.1",
            "kernel-devel": "4.4.121-92.146.1",
            "kernel-default-base": "4.4.121-92.146.1",
            "kgraft-patch-4_4_121-92_146-default": "1-3.5.1",
            "kernel-default": "4.4.121-92.146.1",
            "kernel-source": "4.4.121-92.146.1",
            "kernel-syms": "4.4.121-92.146.1",
            "kernel-default-devel": "4.4.121-92.146.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP2-LTSS / kernel-default

Package

Name
kernel-default
Purl
purl:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.121-92.146.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.4.121-92.146.1",
            "kernel-devel": "4.4.121-92.146.1",
            "kernel-default-base": "4.4.121-92.146.1",
            "kernel-default-man": "4.4.121-92.146.1",
            "kgraft-patch-4_4_121-92_146-default": "1-3.5.1",
            "kernel-default": "4.4.121-92.146.1",
            "kernel-source": "4.4.121-92.146.1",
            "kernel-syms": "4.4.121-92.146.1",
            "kernel-default-devel": "4.4.121-92.146.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP2-LTSS / kernel-source

Package

Name
kernel-source
Purl
purl:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.121-92.146.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.4.121-92.146.1",
            "kernel-devel": "4.4.121-92.146.1",
            "kernel-default-base": "4.4.121-92.146.1",
            "kernel-default-man": "4.4.121-92.146.1",
            "kgraft-patch-4_4_121-92_146-default": "1-3.5.1",
            "kernel-default": "4.4.121-92.146.1",
            "kernel-source": "4.4.121-92.146.1",
            "kernel-syms": "4.4.121-92.146.1",
            "kernel-default-devel": "4.4.121-92.146.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP2-LTSS / kernel-syms

Package

Name
kernel-syms
Purl
purl:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.121-92.146.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.4.121-92.146.1",
            "kernel-devel": "4.4.121-92.146.1",
            "kernel-default-base": "4.4.121-92.146.1",
            "kernel-default-man": "4.4.121-92.146.1",
            "kgraft-patch-4_4_121-92_146-default": "1-3.5.1",
            "kernel-default": "4.4.121-92.146.1",
            "kernel-source": "4.4.121-92.146.1",
            "kernel-syms": "4.4.121-92.146.1",
            "kernel-default-devel": "4.4.121-92.146.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP2-LTSS / kgraft-patch-SLE12-SP2_Update_38

Package

Name
kgraft-patch-SLE12-SP2_Update_38
Purl
purl:rpm/suse/kgraft-patch-SLE12-SP2_Update_38&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1-3.5.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.4.121-92.146.1",
            "kernel-devel": "4.4.121-92.146.1",
            "kernel-default-base": "4.4.121-92.146.1",
            "kernel-default-man": "4.4.121-92.146.1",
            "kgraft-patch-4_4_121-92_146-default": "1-3.5.1",
            "kernel-default": "4.4.121-92.146.1",
            "kernel-source": "4.4.121-92.146.1",
            "kernel-syms": "4.4.121-92.146.1",
            "kernel-default-devel": "4.4.121-92.146.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP2-BCL / kernel-default

Package

Name
kernel-default
Purl
purl:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.121-92.146.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.4.121-92.146.1",
            "kernel-devel": "4.4.121-92.146.1",
            "kernel-default-base": "4.4.121-92.146.1",
            "kernel-default": "4.4.121-92.146.1",
            "kernel-source": "4.4.121-92.146.1",
            "kernel-syms": "4.4.121-92.146.1",
            "kernel-default-devel": "4.4.121-92.146.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP2-BCL / kernel-source

Package

Name
kernel-source
Purl
purl:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.121-92.146.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.4.121-92.146.1",
            "kernel-devel": "4.4.121-92.146.1",
            "kernel-default-base": "4.4.121-92.146.1",
            "kernel-default": "4.4.121-92.146.1",
            "kernel-source": "4.4.121-92.146.1",
            "kernel-syms": "4.4.121-92.146.1",
            "kernel-default-devel": "4.4.121-92.146.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP2-BCL / kernel-syms

Package

Name
kernel-syms
Purl
purl:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP2-BCL

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.4.121-92.146.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.4.121-92.146.1",
            "kernel-devel": "4.4.121-92.146.1",
            "kernel-default-base": "4.4.121-92.146.1",
            "kernel-default": "4.4.121-92.146.1",
            "kernel-source": "4.4.121-92.146.1",
            "kernel-syms": "4.4.121-92.146.1",
            "kernel-default-devel": "4.4.121-92.146.1"
        }
    ]
}