[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

250053

 
 

909

 
 

195940

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2020:1603-1 -- SLES kernel

ID: oval:org.secpod.oval:def:89043774Date: (C)2021-03-05   (M)2024-04-17
Class: PATCHFamily: unix




The SUSE Linux Enterprise 12 SP4 Azure kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-0543: Fixed a side channel attack against special registers which could have resulted in leaking of read values to cores other than the one which called it. This attack is known as Special Register Buffer Data Sampling or CrossTalk . - CVE-2020-13143: Fixed an out-of-bounds read in gadget_dev_desc_UDC_store in drivers/usb/gadget/configfs.c . - CVE-2020-12769: Fixed an issue which could have allowed attackers to cause a panic via concurrent calls to dw_spi_irq and dw_spi_transfer_one . - CVE-2020-12768: Fixed a memory leak in svm_cpu_uninit in arch/x86/kvm/svm.c . - CVE-2020-12657: An a use-after-free in block/bfq-iosched.c . - CVE-2020-12656: Fixed an improper handling of certain domain_release calls leadingch could have led to a memory leak . - CVE-2020-12655: Fixed an issue which could have allowed attackers to trigger a sync of excessive duration via an XFS v5 image with crafted metadata . - CVE-2020-12654: Fixed an issue in he wifi driver which could have allowed a remote AP to trigger a heap-based buffer overflow . - CVE-2020-12653: Fixed an issue in the wifi driver which could have allowed local users to gain privileges or cause a denial of service . - CVE-2020-12652: Fixed an issue which could have allowed local users to hold an incorrect lock during the ioctl operation and trigger a race condition . - CVE-2020-12464: Fixed a use-after-free due to a transfer without a reference . - CVE-2020-12114: Fixed a pivot_root race condition which could have allowed local users to cause a denial of service by corrupting a mountpoint reference counter . - CVE-2020-10757: Fixed an issue where remaping hugepage DAX to anon mmap could have caused user PTE access . - CVE-2020-10751: Fixed an improper implementation in SELinux LSM hook where it was assumed that an skb would only contain a single netlink message . - CVE-2020-10732: Fixed kernel data leak in userspace coredumps due to uninitialized data . - CVE-2020-10720: Fixed a use-after-free read in napi_gro_frags . - CVE-2020-10711: Fixed a null pointer dereference in SELinux subsystem which could have allowed a remote network user to crash the kernel resulting in a denial of service . - CVE-2020-10690: Fixed the race between the release of ptp_clock and cdev . - CVE-2019-9455: Fixed a pointer leak due to a WARN_ON statement in a video driver. This could lead to local information disclosure with System execution privileges needed . - CVE-2019-20812: Fixed an issue in prb_calc_retire_blk_tmo which could have resulted in a denial of service . - CVE-2019-20806: Fixed a null pointer dereference which may had lead to denial of service . - CVE-2019-19462: Fixed an issue which could have allowed local user to cause denial of service . - CVE-2018-1000199: Fixed a potential local code execution via ptrace . The following non-security bugs were fixed: - ACPI: CPPC: Fix reference count leak in acpi_cppc_processor_probe . - ACPI: sysfs: Fix reference count leak in acpi_sysfs_add_hotplug_profile . - acpi/x86: ignore unspecified bit positions in the ACPI global lock field . - Add commit for git-fix that"s not a fix This commit cleans up debug code but does not fix anything, and it relies on a new kernel function that isn"t yet in this version of SLE. - agp/intel: Reinforce the barrier after GTT updates . - ALSA: ctxfi: Remove unnecessary cast in kfree . - ALSA: hda: Do not release card at firmware loading error . - ALSA: hda/hdmi: fix race in monitor detection during probe . - ALSA: hda/hdmi: fix without unlocked before return . - ALSA: hda: Keep the controller initialization even if no codecs found . - ALSA: hda/realtek - Add more fixup entries for Clevo machines . - ALSA: hda/realtek - Add new codec supported for ALC245 . - ALSA: hda/realtek - Add new codec supported for ALC287 . - ALSA: hda/realtek - Fix S3 pop noise on Dell Wyse . - ALSA: hda/realtek - Fix unexpected init_amp override . - ALSA: hda/realtek - Limit int mic boost for Thinkpad T530 . - ALSA: hda/realtek - Two front mics on a Lenovo ThinkCenter . - ALSA: hwdep: fix a left shifting 1 by 31 UB bug . - ALSA: iec1712: Initialize STDSP24 properly when using the model=staudio option . - ALSA: opti9xx: shut up gcc-10 range warning . - ALSA: pcm: fix incorrect hw_base increase . - ALSA: pcm: oss: Place the plugin buffer overflow checks correctly . - ALSA: rawmidi: Fix racy buffer resize under concurrent accesses . - ALSA: usb-audio: Add control message quirk delay for Kingston HyperX headset . - ALSA: usb-audio: Correct a typo of NuPrime DAC-10 USB ID . - ALSA: usb-audio: Do not override ignore_ctl_error value from the map . - ALSA: usb-audio: Fix usb audio refcnt leak when getting spdif . - ALSA: usb-audio: mixer: volume quirk for ESS Technology Asus USB DAC . - ALSA: usx2y: Fix potential NULL dereference . - ASoC: codecs: hdac_hdmi: Fix incorrect use of list_for_each_entry . - ASoC: dapm: connect virtual mux with default value . - ASoC: dapm: fixup dapm kcontrol widget . - ASoC: dpcm: allow start or stop during pause for backend . - ASoC: fix regwmask . - ASoC: msm8916-wcd-digital: Reset RX interpolation path after use . - ASoC: topology: Check return value of pcm_new_ver . - ASoC: topology: use name_prefix for new kcontrol . - b43legacy: Fix case where channel status is corrupted . - batman-adv: fix batadv_nc_random_weight_tq . - batman-adv: Fix refcnt leak in batadv_show_throughput_override . - batman-adv: Fix refcnt leak in batadv_store_throughput_override . - batman-adv: Fix refcnt leak in batadv_v_ogm_process . - bcache: avoid unnecessary btree nodes flushing in btree_flush_write . - bcache: fix incorrect data type usage in btree_flush_write . - bcache: Revert bcache: shrink btree node cache after bch_btree_check . - block/drbd: delete invalid function drbd_md_mark_dirty_ . - block: drbd: remove a stray unlock in __drbd_send_protocol . - block: fix busy device checking in blk_drop_partitions again . - block: fix busy device checking in blk_drop_partitions . - block: fix memleak of bio integrity data . - block: remove the bd_openers checks in blk_drop_partitions . - bnxt_en: fix memory leaks in bnxt_dcbnl_ieee_getets . - bnxt_en: reinitialize IRQs when MTU is modified . - bonding/alb: make sure arp header is pulled before accessing it . - brcmfmac: abort and release host after error . - btrfs: fix deadlock with memory reclaim during scrub . - btrfs: fix log context list corruption after rename whiteout error . - btrfs: fix partial loss of prealloc extent past i_size after fsync . - btrfs: move the dio_sem higher up the callchain . - btrfs: reloc: clear DEAD_RELOC_TREE bit for orphan roots to prevent runaway balance . - btrfs: reloc: fix reloc root leak and NULL pointer dereference . - btrfs: setup a nofs context for memory allocation at btrfs_create_tree . - btrfs: setup a nofs context for memory allocation at __btrfs_set_acl . - btrfs: use nofs context when initializing security xattrs to avoid deadlock . - can: add missing attribute validation for termination . - cdc-acm: close race betrween suspend and acm_softint . - cdc-acm: introduce a cool down . - ceph: fix double unlock in handle_cap_export . - ceph: fix endianness bug when handling MDS session feature bits . - cgroup, netclassid: periodically release file_lock on classid updating . - CIFS: Allocate crypto structures on the fly for calculating signatures of incoming packets . - CIFS: Allocate encryption header through kmalloc . - CIFS: allow unlock flock and OFD lock across fork . - CIFS: check new file size when extending file by fallocate . - CIFS: cifspdu.h: Replace zero-length array with flexible-array member . - CIFS: clear PF_MEMALLOC before exiting demultiplex thread . - CIFS: do not share tcons with DFS . - CIFS: dump the session id and keys also for SMB2 sessions . - CIFS: ensure correct super block for DFS reconnect . - CIFS: Fix bug which the return value by asynchronous read is error . - CIFS: fix uninitialised lease_key in open_shroot . - CIFS: improve read performance for page size 64KB amp; cache=strict amp; vers=2.1+ . - CIFS: Increment num_remote_opens stats counter even in case of smb2_query_dir_first . - CIFS: minor update to comments around the cifs_tcp_ses_lock mutex . - CIFS: protect updating server- gt;dstaddr with a spinlock . - CIFS: smb2pdu.h: Replace zero-length array with flexible-array member . - CIFS: smbd: Calculate the correct maximum packet size for segmented SMBDirect send/receive . - CIFS: smbd: Check and extend sender credits in interrupt context . - CIFS: smbd: Check send queue size before posting a send . - CIFS: smbd: Do not schedule work to send immediate packet on every receive . - CIFS: smbd: Merge code to track pending packets . - CIFS: smbd: Properly process errors on ib_post_send . - CIFS: smbd: Update receive credits before sending and deal with credits roll back on failure before sending . - CIFS: Warn less noisily on default mount . - clk: Add clk_hw_unregister_composite helper function definition . - clk: imx6ull: use OSC clock during AXI rate change . - clk: imx: make mux parent strings const . - clk: mediatek: correct the clocks for MT2701 HDMI PHY module . - clk: sunxi-ng: a64: Fix gate bit of DSI DPHY . - clocksource/drivers/hyper-v: Set TSC clocksource as default w/ InvariantTSC . - clocksource: dw_apb_timer_of: Fix missing clockevent timers . - component: Silence bind error on -EPROBE_DEFER . - coresight: do not use the BIT macro in the UAPI header . - cpufreq: s3c64xx: Remove pointless NULL check in s3c64xx_cpufreq_driver_init . - crypto: ccp - AES CFB mode is a stream cipher . - crypto: ccp - Clean up and exit correctly on allocation failure . - crypto: ccp - Cleanup misc_dev on sev_exit . - crypto: ccp - Cleanup sp_dev_master in psp_dev_destroy . - debugfs: Add debugfs_create_xul for hexadecimal unsigned long . - dmaengine: dmatest: Fix iteration non-stop logic . - dm mpath: switch paths in dm_blk_ioctl code path . - dm writecache: fix data corruption when reloading the target . - dm writecache: fix incorrect flush sequence when doing SSD mode commit . - dm writecache: verify watermark during resume . - dm zoned: fix invalid memory access . - dm zoned: reduce overhead of backing device checks . - dm zoned: remove duplicate nr_rnd_zones increase in dmz_init_zone . - dm zoned: support zone sizes smaller than 128MiB . - dp83640: reverse arguments to list_add_tail . - Drivers: hv: Add a module description line to the hv_vmbus driver . - Drivers: HV: Send one page worth of kmsg dump over Hyper-V during panic . - Drivers: hv: vmbus: Fix the issue with freeing up hv_ctl_table_hdr . - Drivers: hv: vmbus: Get rid of MSR access from vmbus_drv.c . - Drivers: hv: vmus: Fix the check for return value from kmsg get dump buffer . - drivers/net/ibmvnic: Update VNIC protocol version reporting . - drm: amd/acp: fix broken menu structure * context changes - drm/crc: Actually allow to change the crc source * offset changes - drm/dp_mst: Fix clearing payload state on topology disable . - drm/dp_mst: Reformat drm_dp_check_act_status a bit . - drm/edid: Fix off-by-one in DispID DTD pixel clock - drm/i915/gvt: Init DPLL/DDI vreg for virtual display instead of - drm/i915: properly sanity check batch_start_offset * renamed display/intel_fbc.c - gt; intel_fb.c * renamed gt/intel_rc6.c - gt; intel_pm.c * context changes - drm/meson: Delete an error message in meson_dw_hdmi_bind . - drm: NULL pointer dereference [null-pointer-deref] problem - drm/qxl: qxl_release leak in qxl_draw_dirty_fb . - drm/qxl: qxl_release leak in qxl_hw_surface_alloc . - drm/qxl: qxl_release use after free . - drm: Remove PageReserved manipulation from drm_pci_alloc * offset changes - dump_stack: avoid the livelock of the dump_lock . - EDAC, sb_edac: Add support for systems with segmented PCI buses . - ext4: do not zeroout extents beyond i_disksize . - ext4: fix extent_status fragmentation for plain files . - ext4: use non-movable memory for superblock readahead . - fanotify: fix merging marks masks with FAN_ONDIR . - fbcon: fix null-ptr-deref in fbcon_switch * rename drivers/video/fbdev/core to drivers/video/console * context changes - fib: add missing attribute validation for tun_id . - firmware: qcom: scm: fix compilation error when disabled . - fs/cifs: fix gcc warning in sid_to_id . - fs/seq_file.c: simplify seq_file iteration code and interface . - gpio: tegra: mask GPIO IRQs during IRQ shutdown . - gre: fix uninit-value in __iptunnel_pull_header . - HID: hid-input: clear unmapped usages . - HID: hyperv: Add a module description line . - HID: i2c-hid: add Trekstor Primebook C11B to descriptor override . - HID: i2c-hid: override HID descriptors for certain devices . - HID: multitouch: add eGalaxTouch P80H84 support . - HID: wacom: Read HID_DG_CONTACTMAX directly for non-generic devices . - hrtimer: Annotate lockless access to timer- gt;state . - hsr: add restart routine into hsr_get_node_list . - hsr: check protocol version in hsr_newlink . - hsr: fix general protection fault in hsr_addr_is_self . - hsr: set .netnsok flag . - hsr: use rcu_read_lock in hsr_get_node_{list/status} . - i2c: acpi: Force bus speed to 400KHz if a Silead touchscreen is present . - i2c: acpi: put device when verifying client fails . - i2c: brcmstb: remove unused struct member . - i2c: core: Allow empty id_table in ACPI case as well . - i2c: core: decrease reference count of device node in i2c_unregister_device . - i2c: dev: Fix the race between the release of i2c_dev and cdev . - i2c: fix missing pm_runtime_put_sync in i2c_device_probe . - i2c-hid: properly terminate i2c_hid_dmi_desc_override_table array . - i2c: i801: Do not add ICH_RES_IO_SMI for the iTCO_wdt device . - i2c: iproc: Stop advertising support of SMBUS quick cmd . - i2c: isch: Remove unnecessary acpi.h include . - i2c: mux: demux-pinctrl: Fix an error handling path in "i2c_demux_pinctrl_probe" . - i2c: st: fix missing struct parameter description . - IB/ipoib: Add child to parent list only if device initialized . - IB/ipoib: Consolidate checking of the proposed child interface . - IB/ipoib: Do not remove child devices from within the ndo_uninit . - IB/ipoib: Get rid of IPOIB_FLAG_GOING_DOWN . - IB/ipoib: Get rid of the sysfs_mutex . - IB/ipoib: Maintain the child_intfs list from ndo_init/uninit . - IB/ipoib: Move all uninit code into ndo_uninit . - IB/ipoib: Move init code to ndo_init . - IB/ipoib: Replace printk with pr_warn . - IB/ipoib: Use cancel_delayed_work_sync for neigh-clean task . - IB/ipoib: Warn when one port fails to initialize . - ibmvnic: Skip fatal error reset after passive init . - iio:ad7797: Use correct attribute_group . - iio: adc: stm32-adc: fix device used to request dma . - iio: adc: stm32-adc: fix sleep in atomic context . - iio: adc: stm32-adc: Use dma_request_chan instead dma_request_slave_channel . - iio: dac: vf610: Fix an error handling path in "vf610_dac_probe" . - iio: sca3000: Remove an erroneous "get_device" . - iio: xilinx-xadc: Fix ADC-B powerdown . - iio: xilinx-xadc: Fix clearing interrupt when enabling trigger . - iio: xilinx-xadc: Fix sequencer configuration for aux channels in simultaneous mode . - ima: Fix return value of ima_write_policy . - Input: evdev - call input_flush_device on release, not flush . - Input: hyperv-keyboard - add module description . - Input: i8042 - add Acer Aspire 5738z to nomux list . - Input: i8042 - add ThinkPad S230u to i8042 reset list . - Input: raydium_i2c_ts - use true and false for boolean values . - Input: synaptics-rmi4 - fix error return code in rmi_driver_probe . - Input: synaptics-rmi4 - really fix attn_data use-after-free . - Input: usbtouchscreen - add support for BonXeon TP . - Input: xpad - add custom init packet for Xbox One S controllers . - iommu/amd: Call domain_flush_complete in update_domain . - iommu/amd: Do not flush Device Table in iommu_map_page . - iommu/amd: Do not loop forever when trying to increase address space . - iommu/amd: Fix legacy interrupt remapping for x2APIC-enabled system . - iommu/amd: Fix over-read of ACPI UID from IVRS table . - iommu/amd: Fix race in increase_address_space/fetch_pte . - iommu/amd: Update Device Table in increase_address_space . - iommu: Fix reference count leak in iommu_group_alloc . - ipv4: fix a RCU-list lock in fib_triestat_seq_show . - ipv6/addrconf: call ipv6_mc_up for non-Ethernet interface . - ipv6: do not auto-add link-local address to lag ports . - ipvlan: add cond_resched_rcu while processing muticast backlog . - ipvlan: do not deref eth hdr before checking it"s set . - ipvlan: do not use cond_resched_rcu in ipvlan_process_multicast . - iwlwifi: pcie: actually release queue memory in TVQM . - kabi fix for early XHCI debug . - kabi for for md: improve handling of bio with REQ_PREFLUSH in md_flush_request . - kabi, protect struct ib_device . - kabi/severities: Do not track KVM internal symbols. - kabi/severities: Ingnore get_dev_data The function is internal to the AMD IOMMU driver and must not be called by any third party. - kabi workaround for snd_rawmidi buffer_ref field addition . - KEYS: reaching the keys quotas correctly . - KVM: arm64: Change hyp_panics dependency on tpidr_el2 . - KVM: arm64: Stop save/restoring host tpidr_el1 on VHE . - KVM: Check validity of resolved slot when searching memslots . - KVM: s390: vsie: Fix delivery of addressing exceptions . - KVM: SVM: Fix potential memory leak in svm_cpu_init . - KVM x86: Extend AMD specific guest behavior to Hygon virtual CPUs . - l2tp: Allow management of tunnels and session in user namespace . - libata: Remove extra scsi_host_put in ata_scsi_add_hosts . - libata: Return correct status in sata_pmp_eh_recover_pm when ATA_DFLAG_DETACH is set . - lib: raid6: fix awk build warnings . - lib/raid6/test: fix build on distros whose /bin/sh is not bash . - lib/stackdepot.c: fix global out-of-bounds in stack_slabs . - locks: print unsigned ino in /proc/locks . - mac80211: add ieee80211_is_any_nullfunc . - mac80211_hwsim: Use kstrndup in place of kasprintf . - mac80211: mesh: fix discovery timer re-arming issue / crash . - macsec: avoid to set wrong mtu . - macsec: restrict to ethernet devices . - macvlan: add cond_resched during multicast processing . - macvlan: fix null dereference in macvlan_device_event . - md: improve handling of bio with REQ_PREFLUSH in md_flush_request . - md/raid0: Fix an error message in raid0_make_request . - md/raid10: prevent access of uninitialized resync_pages offset . - media: dvb: return -EREMOTEIO on i2c transfer failure . - media: platform: fcp: Set appropriate DMA parameters . - media: ti-vpe: cal: fix disable_irqs to only the intended target . - mei: release me_cl object reference . - mlxsw: Fix some IS_ERR vs NULL bugs . - mlxsw: spectrum_flower: Do not stop at FLOW_ACTION_VLAN_MANGLE . - mmc: atmel-mci: Fix debugfs on 64-bit platforms . - mmc: dw_mmc: Fix debugfs on 64-bit platforms . - mmc: meson-gx: make sure the descriptor is stopped on errors . - mmc: meson-gx: simplify interrupt handler . - mmc: renesas_sdhi: limit block count to 16 bit for old revisions . - mmc: sdhci-esdhc-imx: fix the mask for tuning start point . - mmc: sdhci-msm: Clear tuning done flag while hs400 tuning . - mmc: sdhci-of-at91: fix memleak on clk_get failure . - mmc: sdhci-pci: Fix eMMC driver strength for BYT-based controllers . - mmc: sdhci-xenon: fix annoying 1.8V regulator warning . - mmc: sdio: Fix potential NULL pointer error in mmc_sdio_init_card . - mmc: tmio: fix access width of Block Count Register . - mm: thp: handle page cache THP correctly in PageTransCompoundMap . - mtd: cfi: fix deadloop in cfi_cmdset_0002.c do_write_buffer . - mtd: spi-nor: cadence-quadspi: add a delay in write sequence . - mtd: spi-nor: enable 4B opcodes for mx66l51235l . - mtd: spi-nor: fsl-quadspi: Do not let -EINVAL on the bus . - mwifiex: avoid -Wstringop-overflow warning . - mwifiex: Fix memory corruption in dump_station . - net: bcmgenet: correct per TX/RX ring statistics . - net: dsa: b53: Fix ARL register definitions . - net: dsa: b53: Rework ARL bin logic . - net: dsa: bcm_sf2: Do not register slave MDIO bus with OF . - net: dsa: bcm_sf2: Ensure correct sub-node is parsed . - net: dsa: Fix duplicate frames flooded by learning . - net: dsa: mv88e6xxx: fix lockup on warm boot . - net: fec: validate the new settings in fec_enet_set_coalesce . - net: fix race condition in __inet_lookup_established . - net: fq: add missing attribute validation for orphan mask . - net, ip_tunnel: fix interface lookup with no key . - net: ipv4: devinet: Fix crash when add/del multicast IP with autojoin . - net: ipv6: do not consider routes via gateways for anycast address check . - netlink: Use netlink header as base to calculate bad attribute offset . - net: memcg: fix lockdep splat in inet_csk_accept . - net: memcg: late association of sock to memcg . - net/mlx4_en: avoid indirect call in TX completion . - net/mlx5: Add new fields to Port Type and Speed register . - net/mlx5: Add RoCE RX ICRC encapsulated counter . - net/mlx5e: Fix ethtool self test: link speed . - net/mlx5e: Move port speed code from en_ethtool.c to en/port.c . - net/mlx5: Expose link speed directly . - net/mlx5: Expose port speed when possible . - net: mvneta: Fix the case where the last poll did not process all rx . - net: netrom: Fix potential nr_neigh refcnt leak in nr_add_node . - net/packet: tpacket_rcv: do not increment ring index on drop . - net: qmi_wwan: add support for ASKEY WWHC050 . - net: revert default NAPI poll timeout to 2 jiffies . - net_sched: cls_route: remove the right filter from hashtable . - net/x25: Fix x25_neigh refcnt leak when receiving frame . - nfc: add missing attribute validation for SE API . - nfc: add missing attribute validation for vendor subcommand . - nfc: st21nfca: add missed kfree_skb in an error path . - nfsd4: fix up replay_matches_cache . - nfsd: Ensure CLONE persists data and metadata changes to the target file . - nfsd: fix delay timer on 32-bit architectures . - nfsd: fix jiffies/time_t mixup in LRU list . - NFS: Directory page cache pages need to be locked when read . - nfsd: memory corruption in nfsd4_lock . - NFS: Do not call generic_error_remove_page while holding locks . - NFS: Fix memory leaks and corruption in readdir . - NFS: Fix O_DIRECT accounting of number of bytes read/written . - nfs: Fix potential posix_acl refcnt leak in nfs3_set_acl . - NFS: fix racey wait in nfs_set_open_stateid_locked . - NFS/flexfiles: Use the correct TCP timeout for flexfiles I/O . - NFS/pnfs: Fix pnfs_generic_prepare_to_resend_writes . - NFS: Revalidate the file size on a fatal write error . - NFSv4.0: nfs4_do_fsinfo should not do implicit lease renewals . - NFSv4: Do not allow a cached open with a revoked delegation . - NFSv4: Fix leak of clp- gt;cl_acceptor string . - NFSv4/pnfs: Return valid stateids in nfs_layout_find_inode_by_stateid . - NFSv4: try lease recovery on NFS4ERR_EXPIRED . - NFSv4.x: Drop the slot if nfs4_delegreturn_prepare waits for layoutreturn . - nl802154: add missing attribute validation for dev_type . - nl802154: add missing attribute validation . - nvme-fc: print proper nvme-fc devloss_tmo value . - objtool: Fix stack offset tracking for indirect CFAs . - objtool: Fix switch table detection in .text.unlikely . - objtool: Make BP scratch register warning more robust . - padata: Remove broken queue flushing . - Partially revert kfifo: fix kfifo_alloc and kfifo_init . - pinctrl: baytrail: Enable pin configuration setting for GPIO chip . - pinctrl: cherryview: Add missing spinlock usage in chv_gpio_irq_handler . - platform/x86: asus-nb-wmi: Do not load on Asus T100TA and T200TA . - pNFS: Ensure we do clear the return-on-close layout stateid on fatal errors . - powerpc: Add attributes for setjmp/longjmp . - powerpc/pci/of: Parse unassigned resources . - powerpc/setup_64: Set cache-line-size based on cache-block-size . - powerpc/sstep: Fix DS operand in ld encoding to appropriate value . - r8152: check disconnect status after long sleep . - raid6/ppc: Fix build for clang . - rcu: locking and unlocking need to always be at least barriers . - RDMA/ipoib: Fix use of sizeof . - RDMA/netdev: Fix netlink support in IPoIB . - RDMA/netdev: Hoist alloc_netdev_mqs out of the driver . - RDMA/netdev: Use priv_destructor for netdev cleanup . - Remove 2 git-fixes that cause build issues. - Revert ALSA: hda/realtek: Fix pop noise on ALC225 . - Revert drm/panel: simple: Add support for Sharp LQ150X1LG11 panels - Revert ipc,sem: remove uneeded sem_undo_list lock usage in exit_sem . - rtlwifi: Fix a double free in _rtl_usb_tx_urb_setup . - s390/ftrace: fix potential crashes when switching tracers . - s390/ism: fix error return code in ism_probe . - s390/pci: Fix possible deadlock in recover_store . - s390/pci: Recover handle in clp_set_pci_fn . - scripts/decodecode: fix trapping instruction formatting . - scripts/dtc: Remove redundant YYLOC global declaration . - scsi: bnx2i: fix potential use after free . - scsi: core: Handle drivers which set sg_tablesize to zero This commit also required: gt; scsi: core: avoid preallocating big SGL for data - scsi: core: save/restore command resid for error handling . - scsi: core: scsi_trace: Use get_unaligned_be* . - scsi: core: try to get module before removing device . - scsi: csiostor: Adjust indentation in csio_device_reset . - scsi: csiostor: Do not enable IRQs too early . - scsi: esas2r: unlock on error in esas2r_nvram_read_direct . - scsi: fnic: fix invalid stack access . - scsi: fnic: fix msix interrupt allocation . - scsi: ibmvscsi: Fix WARN_ON during event pool release . - scsi: iscsi: Avoid potential deadlock in iscsi_if_rx func . - scsi: iscsi: Fix a potential deadlock in the timeout handler . - scsi: iscsi: qla4xxx: fix double free in probe . - scsi: lpfc: fix: Coverity: lpfc_cmpl_els_rsp: Null pointer dereferences . - scsi: lpfc: Fix crash in target side cable pulls hitting WAIT_FOR_UNREG . - scsi: megaraid_sas: Do not initiate OCR if controller is not in ready state . - scsi: qla2xxx: add ring buffer for tracing debug logs . - scsi: qla2xxx: check UNLOADING before posting async work . - scsi: qla2xxx: Delete all sessions before unregister local nvme port . - scsi: qla2xxx: Do not log message when reading port speed via sysfs . - scsi: qla2xxx: Fix hang when issuing nvme disconnect-all in NPIV . - scsi: qla2xxx: Fix regression warnings . - scsi: qla2xxx: Remove non functional code . - scsi: qla2xxx: set UNLOADING before waiting for session deletion . - scsi: qla4xxx: Adjust indentation in qla4xxx_mem_free . - scsi: qla4xxx: fix double free bug . - scsi: sd: Clear sdkp- gt;protection_type if disk is reformatted without PI . - scsi: sg: add sg_remove_request in sg_common_write . - scsi: tracing: Fix handling of TRANSFER LENGTH == 0 for READ and WRITE . - scsi: ufs: change msleep to usleep_range . - scsi: ufs: Clean up ufshcd_scale_clks and clock scaling error out path . - scsi: ufs: Fix ufshcd_hold caused scheduling while atomic . - scsi: ufs: Fix ufshcd_probe_hba reture value in case ufshcd_scsi_add_wlus fails . - scsi: ufs: Recheck bkops level if bkops is disabled . - sctp: fix possibly using a bad saddr with a given dst . - sctp: fix refcount bug in sctp_wfree . - seq_file: fix problem when seeking mid-record . - serial: uartps: Move the spinlock after the read of the tx empty . - sfc: detach from cb_page in efx_copy_channel . - signal/pid_namespace: Fix reboot_pid_ns to use send_sig not force_sig . - slcan: not call free_netdev before rtnl_unlock in slcan_open . - slip: make slhc_compress more robust against malicious packets . - smb3: Additional compression structures . - smb3: Add new compression flags . - smb3: change noisy error message to FYI . - smb3: enable swap on SMB3 mounts . - smb3: Minor cleanup of protocol definitions . - smb3: remove overly noisy debug line in signing errors . - smb3: smbdirect support can be configured by default . - smb3: use SMB2_SIGNATURE_SIZE define . - spi: bcm2835: Fix 3-wire mode if DMA is enabled . - spi: bcm63xx-hsspi: Really keep pll clk enabled . - spi: bcm-qspi: when tx/rx buffer is NULL set to 0 . - spi: dw: Add SPI Rx-done wait method to DMA-based transfer . - spi: dw: Add SPI Tx-done wait method to DMA-based transfer . - spi: dw: Zero DMA Tx and Rx configurations on stack . - spi: fsl: do not map irq during probe . - spi: fsl: use platform_get_irq instead of of_irq_to_resource . - spi: pxa2xx: Add CS control clock quirk . - spi: qup: call spi_qup_pm_resume_runtime before suspending . - spi: spi-fsl-dspi: Replace interruptible wait queue with a simple completion . - spi: spi-s3c64xx: Fix system resume support . - spi/zynqmp: remove entry that causes a cs glitch . - staging: comedi: dt2815: fix writing hi byte of analog output . - staging: comedi: Fix comedi_device refcnt leak in comedi_open . - staging: iio: ad2s1210: Fix SPI reading . - staging: vt6656: Do not set RCR_MULTICAST or RCR_BROADCAST by default . - staging: vt6656: Fix drivers TBTT timing counter . - staging: vt6656: Fix pairwise key entry save . - sunrpc: expiry_time should be seconds not timeval . - SUNRPC: Fix a potential buffer overflow in "svc_print_xprts" . - supported.conf: Add br_netfilter to base . - svcrdma: Fix leak of transport addresses . - taskstats: fix data-race . - tcp: cache line align MAX_TCP_HEADER . - tcp: repair: fix TCP_QUEUE_SEQ implementation . - team: add missing attribute validation for array index . - team: add missing attribute validation for port ifindex . - team: fix hang in team_mode_get . - tools lib traceevent: Remove unneeded qsort and uses memmove instead . - tpm: ibmvtpm: retry on H_CLOSED in tpm_ibmvtpm_send . - tpm/tpm_tis: Free IRQ if probing fails . - tpm/tpm_tis: Free IRQ if probing fails . - tracing: Add a vmalloc_sync_mappings for safe measure . - tracing: Disable trace_printk on post poned tests . - tracing: Fix the race between registering "snapshot" event trigger and triggering "snapshot" operation . - tty: rocket, avoid OOB access . - UAS: fix deadlock in error handling and PM flushing work . - UAS: no use logging any details in case of ENODEV . - USB: Add USB_QUIRK_DELAY_CTRL_MSG and USB_QUIRK_DELAY_INIT for Corsair K70 RGB RAPIDFIRE . - USB: cdc-acm: restore capability check order . - USB: core: Fix misleading driver bug report . - USB: dwc3: do not set gadget- gt;is_otg flag . - USB: dwc3: gadget: Do link recovery for SS and SSP . - USB: early: Handle AMD"s spec-compliant identifiers, too . - USB: f_fs: Clear OS Extended descriptor counts to zero in ffs_data_reset . - USB: gadget: audio: Fix a missing error return value in audio_bind . - USB: gadget: composite: Inform controller driver of self-powered . - USB: gadget: legacy: fix error return code in cdc_bind . - USB: gadget: legacy: fix error return code in gncm_bind . - USB: gadget: legacy: fix redundant initialization warnings . - USB: gadget: net2272: Fix a memory leak in an error handling path in "net2272_plat_probe" . - USB: gadget: udc: atmel: Fix vbus disconnect handling . - USB: gadget: udc: atmel: Make some symbols static . - USB: gadget: udc: bdc: Remove unnecessary NULL checks in bdc_req_complete . - USB: host: xhci-plat: keep runtime active when removing host . - USB: hub: Fix handling of connect changes during sleep . - usbnet: silence an unnecessary warning . - USB: serial: garmin_gps: add sanity checking for data length . - USB: serial: option: add BroadMobi BM806U . - USB: serial: option: add support for ASKEY WWHC050 . - USB: serial: option: add Wistron Neweb D19Q1 . - USB: serial: qcserial: Add DW5816e support . - USB: sisusbvga: Change port variable from signed to unsigned . - usb-storage: Add unusual_devs entry for JMicron JMS566 . - USB: uas: add quirk for LaCie 2Big Quadra . - USB: xhci: Fix NULL pointer dereference when enqueuing trbs from urb sg list . - video: fbdev: sis: Remove unnecessary parentheses and commented code - video: fbdev: w100fb: Fix a potential double free . - vrf: Check skb for XFRM_TRANSFORMED flag . - vt: ioctl, switch VT_IS_IN_USE and VT_BUSY to inlines . - vt: selection, introduce vc_is_sel . - vt: vt_ioctl: fix race in VT_RESIZEX . - vt: vt_ioctl: fix use-after-free in vt_in_use . - vt: vt_ioctl: fix VT_DISALLOCATE freeing in-use virtual console . - vxlan: check return value of gro_cells_init . - watchdog: reset last_hw_keepalive time at start . - wcn36xx: Fix error handling path in "wcn36xx_probe" . - wil6210: remove reset file from debugfs . - wimax/i2400m: Fix potential urb refcnt leak . - workqueue: do not use wq_select_unbound_cpu for bound works . - x86/entry/64: Fix unwind hints in kernel exit path . - x86/entry/64: Fix unwind hints in register clearing code . - x86/entry/64: Fix unwind hints in rewind_stack_do_exit . - x86/entry/64: Fix unwind hints in __switch_to_asm . - x86/Hyper-V: Allow guests to enable InvariantTSC . - x86/Hyper-V: Free hv_panic_page when fail to register kmsg dump . - x86/Hyper-V: Report crash data in die when panic_on_oops is set . - x86/Hyper-V: Report crash register data or kmsg before running crash kernel . - x86/Hyper-V: Report crash register data when sysctl_record_panic_msg is not set . - x86/Hyper-V: report value of misc_features . - x86/Hyper-V: Trigger crash enlightenment only once during system crash . - x86/Hyper-V: Unload vmbus channel in hv panic callback . - x86/kprobes: Avoid kretprobe recursion bug . - x86/resctrl: Fix invalid attempt at removing the default resource group . - x86/resctrl: Preserve CDP enable over CPU hotplug . - x86/unwind/orc: Do not skip the first frame for inactive tasks . - x86/unwind/orc: Fix error handling in __unwind_start . - x86/unwind/orc: Fix error path for bad ORC entry type . - x86/unwind/orc: Fix unwind_get_return_address_ptr for inactive tasks . - x86/unwind/orc: Prevent unwinding before ORC initialization . - x86/unwind: Prevent false warnings for non-current tasks . - xen/pci: reserve MCFG areas earlier . - xfrm: Always set XFRM_TRANSFORMED in xfrm{4,6}_output_finish . - xfs: Correctly invert xfs_buftarg LRU isolation logic . - xfs: do not ever return a stale pointer from __xfs_dir3_free_read . - xprtrdma: Fix completion wait during device removal . Special Instructions and Notes: Please reboot the system after installing this update.

Platform:
SUSE Linux Enterprise Server 12 SP4
Product:
kernel
Reference:
SUSE-SU-2020:1603-1
CVE-2018-1000199
CVE-2019-19462
CVE-2019-20806
CVE-2019-20812
CVE-2019-9455
CVE-2020-0543
CVE-2020-10690
CVE-2020-10711
CVE-2020-10720
CVE-2020-10732
CVE-2020-10751
CVE-2020-10757
CVE-2020-12114
CVE-2020-12464
CVE-2020-12652
CVE-2020-12653
CVE-2020-12654
CVE-2020-12655
CVE-2020-12656
CVE-2020-12657
CVE-2020-12768
CVE-2020-12769
CVE-2020-13143
CVE    23
CVE-2020-10690
CVE-2020-12769
CVE-2020-12654
CVE-2020-12653
...

© SecPod Technologies