[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2020:3748-1 -- SLES kernel

ID: oval:org.secpod.oval:def:89050243Date: (C)2023-10-10   (M)2024-04-17
Class: PATCHFamily: unix




The SUSE Linux Enterprise 15 SP2 kernel was updated to 3.12.31 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-15436: Fixed a use after free vulnerability in fs/block_dev.c which could have allowed local users to gain privileges or cause a denial of service . - CVE-2020-15437: Fixed a null pointer dereference which could have allowed local users to cause a denial of service. - CVE-2020-25668: Fixed a concurrency use-after-free in con_font_op . - CVE-2020-25669: Fixed a use-after-free read in sunkbd_reinit . - CVE-2020-25704: Fixed a leak in perf_event_parse_addr_filter . - CVE-2020-27777: Restrict RTAS requests from userspace - CVE-2020-28915: Fixed a buffer over-read in the fbcon code which could have been used by local attackers to read kernel memory . - CVE-2020-28974: Fixed a slab-out-of-bounds read in fbcon which could have been used by local attackers to read privileged information or potentially crash the kernel . - CVE-2020-29371: Fixed uninitialized memory leaks to userspace . - CVE-2020-25705: Fixed an issue which could have allowed to quickly scan open UDP ports. This flaw allowed an off-path remote user to effectively bypassing source port UDP randomization . - CVE-2020-28941: Fixed an issue where local attackers on systems with the speakup driver could cause a local denial of service attack . - CVE-2020-4788: Fixed an issue with IBM Power9 processors could have allowed a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances . - CVE-2020-29369: Fixed a race condition between certain expand functions and page-table free operations from an munmap call, aka CID-246c320a8cfe . The following non-security bugs were fixed: - 9P: Cast to loff_t before multiplying . - ACPI: button: Add DMI quirk for Medion Akoya E2228T . - ACPICA: Add NHLT table signature . - ACPI: dock: fix enum-conversion warning . - ACPI / extlog: Check for RDMSR failure . - ACPI: GED: fix -Wformat . - ACPI: NFIT: Fix comparison to "-ENXIO" . - ACPI: video: use ACPI backlight for HP 635 Notebook . - Add bug reference to two hv_netvsc patches . - ALSA: ctl: fix error path at adding user-defined element set . - ALSA: firewire: Clean up a locking issue in copy_resp_to_buf . - ALSA: fix kernel-doc markups . - ALSA: hda: fix jack detection with Realtek codecs when in D3 . - ALSA: hda: prevent undefined shift in snd_hdac_ext_bus_get_link . - ALSA: hda/realtek: Add some Clove SSID in the ALC293 . - ALSA: hda/realtek - Add supported for Lenovo ThinkPad Headset Button . - ALSA: hda/realtek - Add supported mute Led for HP . - ALSA: hda/realtek - Enable headphone for ASUS TM420 . - ALSA: hda/realtek - Fixed HP headset Mic can"t be detected . - ALSA: hda/realtek - HP Headset Mic can"t detect after boot . - ALSA: hda: Reinstate runtime_allow for all hda controllers . - ALSA: mixart: Fix mutex deadlock . - ALSA: usb-audio: Add delay quirk for all Logitech USB devices . - ALSA: usb-audio: Add implicit feedback quirk for MODX . - ALSA: usb-audio: Add implicit feedback quirk for Qu-16 . - ALSA: usb-audio: Add implicit feedback quirk for Zoom UAC-2 . - ALSA: usb-audio: add usb vendor id as DSD-capable for Khadas devices . - arm64: bpf: Fix branch offset in JIT . - arm64: dts: allwinner: a64: bananapi-m64: Enable RGMII RX/TX delay on PHY . - arm64: dts: allwinner: a64: OrangePi Win: Fix ethernet node . - arm64: dts: allwinner: a64: Pine64 Plus: Fix ethernet node . - arm64: dts: allwinner: beelink-gs1: Enable both RGMII RX/TX delay . - arm64: dts: allwinner: h5: OrangePi PC2: Fix ethernet node . - arm64: dts: allwinner: h5: OrangePi Prime: Fix ethernet node . - arm64: dts: allwinner: Pine H64: Enable both RGMII RX/TX delay . - arm64: dts: fsl: DPAA FMan DMA operations are coherent . - arm64: dts: imx8mm: fix voltage for 1.6GHz CPU operating point . - arm64: dts: imx8mq: Add missing interrupts to GPC . - arm64: dts: imx8mq: Fix TMU interrupt property . - arm64: dts: zynqmp: Remove additional compatible string for i2c IPs . - arm64: kprobe: add checks for ARMv8.3-PAuth combined instructions . - arm64: Run ARCH_WORKAROUND_1 enabling code on all CPUs . - arm64: Run ARCH_WORKAROUND_2 enabling code on all CPUs . - arm64: tegra: Add missing timeout clock to Tegra186 SDMMC nodes . - arm64: tegra: Add missing timeout clock to Tegra194 SDMMC nodes . - arm64: tegra: Add missing timeout clock to Tegra210 SDMMC . - arm64: vdso: Add "-Bsymbolic" to ldflags . - arm64: vdso: Add --eh-frame-hdr to ldflags . - ASoC: codecs: wcd9335: Set digital gain range correctly . - ASoC: cs42l51: manage mclk shutdown delay . - ASoC: Intel: kbl_rt5663_max98927: Fix kabylake_ssp_fixup function . - ASoC: qcom: lpass-platform: Fix memory leak . - ASoC: qcom: sdm845: set driver name correctly . - ath10k: fix VHT NSS calculation when STBC is enabled . - ath10k: start recovery process when payload length exceeds max htc length for sdio . - batman-adv: set .owner to THIS_MODULE . - bnxt_en: Avoid sending firmware messages when AER error is detected . - bnxt_en: Check abort error state in bnxt_open_nic . - bnxt_en: Fix NULL ptr dereference crash in bnxt_fw_reset_task . - bnxt_en: Fix regression in workqueue cleanup logic in bnxt_remove_one . - bnxt_en: Invoke cancel_delayed_work_sync for PFs also . - bnxt_en: return proper error codes in bnxt_show_temp . - bnxt_en: Send HWRM_FUNC_RESET fw command unconditionally . - bpf: Do not rely on GCC __attribute__ to disable GCSE . - bpf: Fix comment for helper bpf_current_task_under_cgroup . - bpf: Zero-fill re-used per-cpu map element . - btrfs: Account for merged patches upstream Move below patches to sorted section. - btrfs: cleanup cow block on error . - btrfs: fix bytes_may_use underflow in prealloc error condtition . - btrfs: fix metadata reservation for fallocate that leads to transaction aborts . - btrfs: fix relocation failure due to race with fallocate . - btrfs: remove item_size member of struct btrfs_clone_extent_info . - btrfs: rename btrfs_insert_clone_extent to a more generic name . - btrfs: rename btrfs_punch_hole_range to a more generic name . - btrfs: rename struct btrfs_clone_extent_info to a more generic name . - btrfs: reschedule if necessary when logging directory items . - btrfs: send, orphanize first all conflicting inodes when processing references . - btrfs: send, recompute reference path after orphanization of a directory . - can: af_can: prevent potential access of uninitialized member in canfd_rcv . - can: af_can: prevent potential access of uninitialized member in can_rcv . - can: can_create_echo_skb: fix echo skb generation: always use skb_clone . - can: dev: __can_get_echo_skb: fix real payload length return value for RTR frames . - can: dev: can_get_echo_skb: prevent call to kfree_skb in hard IRQ context . - can: dev: can_restart: post buffer from the right context . - can: flexcan: flexcan_remove: disable wakeup completely . - can: flexcan: flexcan_setup_stop_mode: add missing "req_bit" to stop mode property comment . - can: flexcan: remove FLEXCAN_QUIRK_DISABLE_MECR quirk for LS1021A . - can: gs_usb: fix endianess problem with candleLight firmware . - can: kvaser_usb: kvaser_usb_hydra: Fix KCAN bittiming limits . - can: m_can: fix nominal bitiming tseg2 min for version greater than = 3.1 . - can: m_can: m_can_handle_state_change: fix state change . - can: m_can: m_can_stop: set device to software init mode before closing . - can: mcba_usb: mcba_usb_start_xmit: first fill skb, then pass to can_put_echo_skb . - can: peak_canfd: pucan_handle_can_rx: fix echo management when loopback is on . - can: peak_usb: add range checking in decode operations . - can: peak_usb: fix potential integer overflow on shift of a int . - can: peak_usb: peak_usb_get_ts_time: fix timestamp wrapping . - can: rx-offload: do not call kfree_skb from IRQ context . - ceph: add check_session_state helper and make it global . - ceph: check session state after bumping session- greater than s_seq . - ceph: check the sesion state and return false in case it is closed . - ceph: downgrade warning from mdsmap decode to debug . - ceph: fix race in concurrent __ceph_remove_cap invocations . - cfg80211: initialize wdev data earlier . - cfg80211: regulatory: Fix inconsistent format argument . - cifs: Fix incomplete memory allocation on setxattr path . - cifs: remove bogus debug code . - cifs: Return the error from crypt_message when enc/dec key not found . - clk: define to_clk_regmap as inline function . - Convert trailing spaces and periods in path components . - cosa: Add missing kfree in error path of cosa_write . - dax: fix detection of dax support for non-persistent memory block devices . - dax: Fix stack overflow when mounting fsdax pmem device . - Delete patches.suse/fs-select.c-batch-user-writes-in-do_sys_poll.patch - devlink: Make sure devlink instance and port are in same net namespace . - docs: ABI: sysfs-c2port: remove a duplicated entry . - Documentation/admin-guide/module-signing.rst: add openssl command option example for CodeSign EKU . - Do not create null.i000.ipa-clones file Kbuild cc-option compiles /dev/null file to test for an option availability. Filter out -fdump-ipa-clones so that null.i000.ipa-clones file is not generated in the process. - drbd: code cleanup by using sendpage_ok to check page for kernel_sendpage . - drivers/net/ethernet: remove incorrectly formatted doc . - drivers: watchdog: rdc321x_wdt: Fix race condition bugs . - Drop sysctl files for dropped archs, add ppc64le and arm . Also correct the page size on ppc64. - EDAC/amd64: Cache secondary Chip Select registers . - EDAC/amd64: Find Chip Select memory size using Address Mask . - EDAC/amd64: Gather hardware information early . - EDAC/amd64: Initialize DIMM info for systems with more than two channels . - EDAC/amd64: Make struct amd64_family_type global . - EDAC/amd64: Save max number of controllers to family type . - EDAC/amd64: Support asymmetric dual-rank DIMMs . - efi: add missed destroy_workqueue when efisubsys_init fails . - efi: efibc: check for efivars write capability . - efi: EFI_EARLYCON should depend on EFI . - efi/efivars: Set generic ops before loading SSDT . - efi/esrt: Fix reference count leak in esre_create_sysfs_entry . - efi/libstub/x86: Work around LLVM ELF quirk build regression . - efi: provide empty efi_enter_virtual_mode implementation . - efivarfs: fix memory leak in efivarfs_create . - efivarfs: revert "fix memory leak in efivarfs_create" . - efi/x86: Align GUIDs to their size in the mixed mode runtime wrapper . - efi/x86: Do not panic or BUG on non-critical error conditions . - efi/x86: Fix the deletion of variables in mixed mode . - efi/x86: Free efi_pgd with free_pages . - efi/x86: Handle by-ref arguments covering multiple pages in mixed mode . - efi/x86: Ignore the memory attributes table on i386 . - efi/x86: Map the entire EFI vendor string before copying it . - exfat: fix name_hash computation on big endian systems . - exfat: fix overflow issue in exfat_cluster_to_sector . - exfat: fix possible memory leak in exfat_find . - exfat: fix use of uninitialized spinlock on error path . - exfat: fix wrong hint_stat initialization in exfat_find_dir_entry . - fbdev, newport_con: Move FONT_EXTRA_WORDS macros into linux/font.h . - Fix wrongly set CONFIG_SOUNDWIRE=y CONFIG_SOUNDWIRE was mistakenly set as built-in. Mark it as module. - ftrace: Fix recursion check for NMI test . - ftrace: Handle tracing when switching between context . - futex: Do not enable IRQs unconditionally in put_pi_state . - futex: Handle transient "ownerless" rtmutex state correctly . - gpio: pcie-idio-24: Enable PEX8311 interrupts . - gpio: pcie-idio-24: Fix IRQ Enable Register value . - gpio: pcie-idio-24: Fix irq mask when masking . - HID: logitech-dj: Fix an error in mse_bluetooth_descriptor . - HID: logitech-dj: Fix Dinovo Mini when paired with a MX5x00 receiver . - HID: logitech-dj: Handle quad/bluetooth keyboards with a builtin trackpad . - HID: logitech-hidpp: Add PID for MX Anywhere 2 . - hv_balloon: disable warning when floor reached . - hv: clocksource: Add notrace attribute to read_hv_sched_clock_* functions . - hv_netvsc: Add XDP support . - hv_netvsc: Fix XDP refcnt for synthetic and VF NICs . - hv_netvsc: make recording RSS hash depend on feature flag . - hv_netvsc: record hardware hash in skb . - hwmon: Fix RPM calculation . - hyperv_fb: Update screen_info after removing old framebuffer . - i2c: mediatek: move dma reset before i2c reset . - i2c: sh_mobile: implement atomic transfers . - igc: Fix not considering the TX delay for timestamps . - igc: Fix wrong timestamp latency numbers . - iio: accel: kxcjk1013: Add support for KIOX010A ACPI DSM for setting tablet-mode . - iio: accel: kxcjk1013: Replace is_smo8500_device with an acpi_type enum . - iio: adc: mediatek: fix unset field . - iio: light: fix kconfig dependency bug for VCNL4035 . - Input: adxl34x - clean up a data type in adxl34x_probe . - Input: resistive-adc-touch - fix kconfig dependency on IIO_BUFFER . - intel_idle: Customize IceLake server support . - ionic: check port ptr before use . - iwlwifi: mvm: write queue_sync_state only for sync . - kABI: revert use_mm name change . - kABI workaround for HD-audio . - kernel: better document the use_mm/unuse_mm API contract . - kernel-{binary,source}.spec.in: do not create loop symlinks - kernel-source.spec: Fix build with rpm 4.16 . RPM_BUILD_ROOT is cleared before %%install. Do the unpack into RPM_BUILD_ROOT in %%install - kernel/watchdog: fix watchdog_allowed_mask not used warning . - kgdb: Fix spurious true from in_dbg_master . - kthread_worker: prevent queuing delayed work from timer_fn when it is being canceled . - KVM: arm64: ARM_SMCCC_ARCH_WORKAROUND_1 does not return SMCCC_RET_NOT_REQUIRED . - lan743x: fix "BUG: invalid wait context" when setting rx mode . - lan743x: fix issue causing intermittent kernel log warnings . - lan743x: prevent entire kernel HANG on open, for some platforms . - leds: bcm6328, bcm6358: use devres LED registering function . - libbpf, hashmap: Fix undefined behavior in hash_bits . - libceph: use sendpage_ok in ceph_tcp_sendpage . - lib/crc32test: remove extra local_irq_disable/enable . - libnvdimm/nvdimm/flush: Allow architecture to override the flush barrier . - lib/strncpy_from_user.c: Mask out bytes after NUL terminator . - mac80211: always wind down STA state . - mac80211: fix use of skb payload instead of header . - mac80211: free sta in sta_info_insert_finish on errors . - mac80211: minstrel: fix tx status processing corner case . - mac80211: minstrel: remove deferred sampling code . - media: imx274: fix frame interval handling . - media: platform: Improve queue set up flow for bug fixing . - media: tw5864: check status of tw5864_frameinterval_get . - media: uvcvideo: Fix dereference of out-of-bound list iterator . - media: uvcvideo: Fix uvc_ctrl_fixup_xu_info not having any effect . - mei: protect mei_cl_mtu from null dereference . - memcg: fix NULL pointer dereference in __mem_cgroup_usage_unregister_event . - mfd: sprd: Add wakeup capability for PMIC IRQ . - mmc: renesas_sdhi_core: Add missing tmio_mmc_host_free at remove . - mmc: sdhci-of-esdhc: Handle pulse width detection erratum for more SoCs . - mmc: sdhci-pci: Prefer SDR25 timing for High Speed mode for BYT-based Intel controllers . - mm: fix exec activate_mm vs TLB shootdown and lazy tlb switching race . - mm: fix kthread_use_mm vs TLB invalidate . - mm/gup: allow FOLL_FORCE for get_user_pages_fast . - mm/gup: fix gup_fast with dynamic page table folding . - mm/ksm: fix NULL pointer dereference when KSM zero page is enabled . - mm, memcg: fix inconsistent oom event behavior . - mm/memcg: fix refcount error while moving and swapping . - mm/memcontrol.c: add missed css_put . - mm: mempolicy: require at least one nodeid for MPOL_PREFERRED . - mm/swapfile.c: fix potential memory leak in sys_swapon . - mm: swap: make page_evictable inline . - mm: swap: use smp_mb__after_atomic to order LRU bit set . - mm, THP, swap: fix allocating cluster for swapfile by mistake . - modsign: Add codeSigning EKU when generating X.509 key generation config . - net: add WARN_ONCE in kernel_sendpage for improper zero-copy send . - net: ena: Capitalize all log strings and improve code readability . - net: ena: Change license into format to SPDX in all files . - net: ena: Change log message to netif/dev function . - net: ena: Change RSS related macros and variables names . - net: ena: ethtool: Add new device statistics . - net: ena: ethtool: add stats printing to XDP queues . - net: ena: ethtool: convert stat_offset to 64 bit resolution . - net: ena: Fix all static chekers" warnings . - net: ena: fix packet"s addresses for rx_offset feature . - net: ena: handle bad request id in ena_netdev . - net: ena: Remove redundant print of placement policy . - net: ena: xdp: add queue counters for xdp actions . - net: fix pos incrementment in ipv6_route_seq_next . - net: introduce helper sendpage_ok in include/linux/net.h . kABI workaround for including mm.h in include/linux/net.h . - net/mlx5: Clear bw_share upon VF disable . - net/mlx5: E-Switch, Fail mlx5_esw_modify_vport_rate if qos disabled . - net: mscc: ocelot: fix race condition with TX timestamping . - net: usb: qmi_wwan: add Telit LE910Cx 0x1230 composition . - nfc: s3fwrn5: use signed integer for parsing GPIO numbers . - NFS: only invalidate dentrys that are clearly invalid . - NFSv4: Handle NFS4ERR_OLD_STATEID in CLOSE/OPEN_DOWNGRADE . - NFSv4: Wait for stateid updates after CLOSE/OPEN_DOWNGRADE . - NFSv4.x recover from pre-mature loss of openstateid . - nvme: do not update disk info for multipathed device . - nvme-tcp: check page by sendpage_ok before calling kernel_sendpage . - p54: avoid accessing the data mapped to streaming DMA . - PCI/ACPI: Whitelist hotplug ports for D3 if power managed by ACPI . - pinctrl: amd: fix incorrect way to disable debounce filter . - pinctrl: amd: use higher precision for 512 RtcClk . - pinctrl: aspeed: Fix GPI only function problem . - pinctrl: intel: Set default bias in case no particular value given . - platform/x86: thinkpad_acpi: Send tablet mode switch at wakeup time . - platform/x86: toshiba_acpi: Fix the wrong variable assignment . - PM: runtime: Drop runtime PM references to supplier on link removal . - powerpc/64s/radix: Fix mm_cpumask trimming race vs kthread_use_mm . - powerpc: Inline doorbell sending functions . - powerpc/perf: consolidate GPCI hcall structs into asm/hvcall.h . - powerpc/pmem: Add flush routines using new pmem store and sync instruction . - powerpc/pmem: Add new instructions for persistent storage and sync . - powerpc/pmem: Avoid the barrier in flush routines . - powerpc/pmem: Initialize pmem device on newer hardware . - powerpc/pmem: Restrict papr_scm to P8 and above . - powerpc/pmem: Update ppc64 to use the new barrier instruction . - powerpc/pseries: Add KVM guest doorbell restrictions . - powerpc/pseries: new lparcfg key/value pair: partition_affinity_score . - powerpc/pseries: Use doorbells even if XIVE is available . - powerpc: select ARCH_WANT_IRQS_OFF_ACTIVATE_MM . - powerpc/vnic: Extend "failover pending" window . - power: supply: bq27xxx: report "not charging" on all types . - power: supply: test_power: add missing newlines when printing parameters by sysfs . - qla2xxx: Add MODULE_VERSION back to driver . - RDMA/hns: Fix retry_cnt and rnr_cnt when querying QP . - RDMA/hns: Fix the wrong value of rnr_retry when querying qp . - RDMA/hns: Fix wrong field of SRQ number the device supports . - RDMA/hns: Solve the overflow of the calc_pg_sz . - RDMA/mlx5: Fix devlink deadlock on net namespace deletion . - RDMA/qedr: Fix return code if accept is called on a destroyed qp . - RDMA/ucma: Add missing locking around rdma_leave_multicast . - reboot: fix overflow parsing reboot cpu number . - Refresh patches.suse/vfs-add-super_operations-get_inode_dev. - regulator: avoid resolve_supply infinite recursion . - regulator: defer probe when trying to get voltage from unresolved supply . - regulator: fix memory leak with repeated set_machine_constraints . - regulator: pfuze100: limit pfuze-support-disable-sw to pfuze{100,200} . - regulator: ti-abb: Fix array out of bound read access on the first transition . - regulator: workaround self-referent regulators . - Restore the header of series.conf The header of series.conf was accidentally changed by abb50be8e6bc "". - Revert "cdc-acm: hardening against malicious devices" . - Revert "kernel/reboot.c: convert simple_strtoul to kstrtoint" . - Revert "xfs: complain if anyone tries to create a too-large buffer" . - rfkill: Fix use-after-free in rfkill_resume . - ring-buffer: Fix recursion protection transitions between interrupt context . - rpm/kernel-binary.spec.in: avoid using barewords Author: Dominique Leuenberger - less than dimstar at opensuse.org greater than - rpm/kernel-binary.spec.in: avoid using more barewords %split_extra still contained two. - rpm/kernel-binary.spec.in: use grep -E instead of egrep egrep is only a deprecated bash wrapper for "grep -E". So use the latter instead. - rpm/kernel-obs-build.spec.in: Add -q option to modprobe calls - rpm/kernel-{source,binary}.spec: do not include ghost symlinks . - rpm/mkspec: do not build kernel-obs-build on x86_32 We want to use 64bit kernel due to various bugs . There is: ExportFilter: ^kernel-obs-build.*\.x86_64.rpm$ . i586 in Factory"s prjconf now. No other actively maintained distro builds a x86_32 kernel, hence pushing to packaging directly. - s390/bpf: Fix multiple tail calls . - s390/cpum_cf,perf: change DFLT_CCERROR counter name . - s390/cpum_sf.c: fix file permission for cpum_sfb_size . - s390/dasd: fix null pointer dereference for ERP requests . - s390/pkey: fix paes selftest failure with paes and pkey static build . - s390/zcrypt: fix kmalloc 256k failure . - s390/zcrypt: Fix ZCRYPT_PERDEV_REQCNT ioctl . - sched/fair: Ensure tasks spreading in LLC during LB . - sched/fair: Fix unthrottle_cfs_rq for leaf_cfs_rq list . - sched: Fix loadavg accounting race on arm64 kabi . - sched: Fix rq- greater than nr_iowait ordering . - scripts/lib/SUSE/MyBS.pm: properly close prjconf Macros: section - scsi: libiscsi: Fix NOP race condition . - scsi: libiscsi: use sendpage_ok in iscsi_tcp_segment_map . - serial: 8250_mtk: Fix uart_get_baud_rate warning . - serial: txx9: add missing platform_driver_unregister on error in serial_txx9_init . - spi: lpspi: Fix use-after-free on unbind . - staging: comedi: cb_pcidas: Allow 2-channel commands for AO subdevice . - staging: octeon: Drop on uncorrectable alignment or FCS error . - staging: octeon: repair "fixed-link" support . - staging: rtl8723bs: Add 024c:0627 to the list of SDIO device-ids . - SUNRPC: fix copying of multiple pages in gss_read_proxy_verf . - SUNRPC: Fix general protection fault in trace_rpc_xdr_overflow . - svcrdma: fix bounce buffers for unaligned offsets and multiple pages . - tcp: use sendpage_ok to detect misused .sendpage . - thunderbolt: Add the missed ida_simple_remove in ring_request_msix . - thunderbolt: Fix memory leak if ida_simple_get fails in enumerate_services . - timer: Fix wheel index calculation on last level . - timer: Prevent base- greater than clk from moving backward . - tpm: efi: Do not create binary_bios_measurements file for an empty log . - tpm_tis: Disable interrupts on ThinkPad T490s . - tracing: Fix out of bounds write in get_trace_buf . - tty: serial: fsl_lpuart: add LS1028A support . - tty: serial: fsl_lpuart: LS1021A had a FIFO size of 16 words, like LS1028A . - tty: serial: imx: fix potential deadlock . - tty: serial: imx: keep console clocks always on . - uio: Fix use-after-free in uio_unregister_device . - uio: free uio id after uio file node is freed . - USB: Add NO_LPM quirk for Kingston flash drive . - USB: adutux: fix debugging . - USB: cdc-acm: Add DISABLE_ECHO for Renesas USB Download mode . - USB: cdc-acm: fix cooldown mechanism . - USB: core: Change %pK for __user pointers to %px . - USB: core: driver: fix stray tabs in error messages . - USB: core: Fix regression in Hercules audio card . - USB: gadget: Fix memleak in gadgetfs_fill_super . - USB: gadget: f_midi: Fix memleak in f_midi_alloc . - USB: gadget: goku_udc: fix potential crashes in probe . - USB: host: fsl-mph-dr-of: check return of dma_set_mask . - USB: mtu3: fix panic in mtu3_gadget_stop . - USB: serial: cyberjack: fix write-URB completion race . - USB: serial: option: add LE910Cx compositions 0x1203, 0x1230, 0x1231 . - USB: serial: option: add Quectel EC200T module support . - USB: serial: option: add Telit FN980 composition 0x1055 . - USB: typec: tcpm: During PR_SWAP, source caps should be sent only after tSwapSourceStart . - USB: typec: tcpm: reset hard_reset_count for any disconnect . - USB: xhci: omit duplicate actions when suspending a runtime suspended host . - video: hyperv_fb: Fix the cache type when mapping the VRAM . - video: hyperv_fb: include vmalloc.h . - video: hyperv: hyperv_fb: Obtain screen resolution from Hyper-V host . - video: hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver . - video: hyperv: hyperv_fb: Use physical memory for fb on HyperV Gen 1 VMs . - virtio: virtio_console: fix DMA memory allocation for rproc serial . - vt: Disable KD_FONT_OP_COPY . - x86/hyperv: Clarify comment on x2apic mode . - x86/i8259: Use printk_deferred to prevent deadlock . - x86/kexec: Use up-to-dated screen_info copy to fill boot params . - x86/microcode/intel: Check patch signature before saving microcode for early loading . - x86/speculation: Allow IBPB to be conditionally enabled on CPUs with always-on STIBP . - xfs: complain if anyone tries to create a too-large buffer log item . - xfs: do not update mtime on COW faults . - xfs: fix a missing unlock on error in xfs_fs_map_blocks . - xfs: fix brainos in the refcount scrubber"s rmap fragment processor . - xfs: fix flags argument to rmap lookup when converting shared file rmaps . - xfs: fix rmap key and record comparison functions . - xfs: fix scrub flagging rtinherit even if there is no rt device . - xfs: flush new eof page on truncate to avoid post-eof corruption . - xfs: introduce XFS_MAX_FILEOFF . - xfs: prohibit fs freezing when using empty transactions . - xfs: remove unused variable "done" . - xfs: revert "xfs: fix rmap key and record comparison functions" . - xfs: set the unwritten bit in rmap lookup flags in xchk_bmap_get_rmapextents . - xfs: set xefi_discard when creating a deferred agfl free log intent item . - xfs: truncate should remove all blocks, not just to the end of the page cache . - xhci: Fix sizeof mismatch . - xhci: hisilicon: fix refercence leak in xhci_histb_probe . kernel-default-base fixes the following issues: - Add wireguard kernel module - Create the list of crypto kernel modules dynamically, supersedes hardcoded list of crc32 implementations Special Instructions and Notes: Please reboot the system after installing this update.

Platform:
SUSE Linux Enterprise Server 15 SP2
SUSE Linux Enterprise Desktop 15 SP2
Product:
kernel
Reference:
SUSE-SU-2020:3748-1
CVE-2020-15436
CVE-2020-15437
CVE-2020-25668
CVE-2020-25669
CVE-2020-25704
CVE-2020-27777
CVE-2020-28915
CVE-2020-28941
CVE-2020-28974
CVE-2020-29369
CVE-2020-29371
CVE-2020-4788
CVE-2020-25705
CVE    13
CVE-2020-29369
CVE-2020-29371
CVE-2020-15436
CVE-2020-25668
...
CPE    3
cpe:/o:linux:linux_kernel
cpe:/o:suse:suse_linux_enterprise_server:15:sp2
cpe:/o:suse:suse_linux_enterprise_desktop:15:sp2

© SecPod Technologies