[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248364

 
 

909

 
 

195388

 
 

282

Paid content will be excluded from the download.


Download | Alert*
OVAL

SUSE-SU-2019:2071-1 -- SLES kernel

ID: oval:org.secpod.oval:def:89050605Date: (C)2024-02-20   (M)2024-04-17
Class: PATCHFamily: unix




The SUSE Linux Enterprise 15 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-20855: An issue was discovered in the Linux kernel In create_qp_common in drivers/infiniband/hw/mlx5/qp.c, mlx5_ib_create_qp_resp was never initialized, resulting in a leak of stack memory to userspace. - CVE-2019-1125: Exclude ATOMs from speculation through SWAPGS . - CVE-2019-14283: In the Linux kernel, set_geometry in drivers/block/floppy.c did not validate the sect and head fields, as demonstrated by an integer overflow and out-of-bounds read. It could be triggered by an unprivileged local user when a floppy disk was inserted. NOTE: QEMU creates the floppy device by default. - CVE-2019-11810: An issue was discovered in the Linux kernel A NULL pointer dereference could occur when megasas_create_frame_pool failed in megasas_alloc_cmds in drivers/scsi/megaraid/megaraid_sas_base.c. This caused a Denial of Service, related to a use-after-free . - CVE-2019-13648: In the Linux kernel on the powerpc platform, when hardware transactional memory was disabled, a local user could cause a denial of service via a sigreturn system call that sent a crafted signal frame. - CVE-2019-13631: In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in the Linux kernel, a malicious USB device could send an HID report that triggered an out-of-bounds write during generation of debugging messages. The following non-security bugs were fixed: - Correct the CVE and bug reference for a floppy security fix A dedicated CVE was already assigned - acpi/nfit: Always dump _DSM output payload . - Add back sibling paca poiter to paca . - Add support for crct10dif-vpmsum . - af_unix: remove redundant lockdep class . alsa: compress: Be more restrictive about when a drain is allowed . - alsa: compress: Do not allow paritial drain operations on capture streams . - alsa: compress: Fix regression on compressed capture streams . - alsa: compress: Prevent bypasses of set_params . - alsa: hda - Add a conexant codec entry to let mute led work . - alsa: hda/realtek: apply ALC891 headset fixup to one Dell machine . - alsa: hda/realtek - Fixed Headphone Mic can"t record on Dell platform . - alsa: hda/realtek - Headphone Mic can"t record after S3 . - alsa: line6: Fix a typo . - alsa: line6: Fix wrong altsetting for LINE6_PODHD500_1 . - alsa: seq: Break too long mutex context in the write loop . - alsa: usb-audio: Add quirk for Focusrite Scarlett Solo . - alsa: usb-audio: Add quirk for MOTU MicroBook II . - alsa: usb-audio: Cleanup DSD whitelist . - alsa: usb-audio: Enable .product_name override for Emagic, Unitor 8 . - alsa: usb-audio: Sanity checks for each pipe and EP types . - asoc : cs4265 : readable register too low . - asoc: max98090: remove 24-bit format support if RJ is 0 . - asoc: soc-pcm: BE dai needs prepare when pause release after resume . - ath6kl: add some bounds checking . - batman-adv: fix for leaked TVLV handler . - bcache: acquire bch_register_lock later in cached_dev_detach_finish . - bcache: acquire bch_register_lock later in cached_dev_free . - bcache: add code comments for journal_read_bucket . - bcache: Add comments for blkdev_put in registration code path . - bcache: add comments for closure_fn to be called in closure_queue . - bcache: add comments for kobj release callback routine . - bcache: add comments for mutex_lock . - bcache: add error check for calling register_bdev . - bcache: add failure check to run_cache_set for journal replay . - bcache: add io error counting in write_bdev_super_endio . - bcache: add more error message in bch_cached_dev_attach . - bcache: add pendings_cleanup to stop pending bcache device . - bcache: add reclaimed_journal_buckets to struct cache_set . - bcache: add return value check to bch_cached_dev_run . - bcache: avoid a deadlock in bcache_reboot . - bcache: avoid clang -Wunintialized warning . - bcache: avoid flushing btree node in cache_set_flush if io disabled . - bcache: avoid potential memleak of list of journal_replay in the CACHE_SYNC branch of run_cache_set . - bcache: check CACHE_SET_IO_DISABLE bit in bch_journal . - bcache: check CACHE_SET_IO_DISABLE in allocator code . - bcache: check c-greater than gc_thread by IS_ERR_OR_NULL in cache_set_flush . - bcache: Clean up bch_get_congested . - bcache: destroy dc-greater than writeback_write_wq if failed to create dc-greater than writeback_thread . - bcache: do not assign in if condition in bcache_device_init . - bcache: do not set max writeback rate if gc is running . - bcache: fix a race between cache register and cacheset unregister . - bcache: fix crashes stopping bcache device before read miss done . - bcache: fix failure in journal relplay . - bcache: fix inaccurate result of unused buckets . - bcache: fix mistaken sysfs entry for io_error counter . - bcache: fix potential deadlock in cached_def_free . - bcache: fix race in btree_flush_write . - bcache: fix return value error in bch_journal_read . - bcache: fix stack corruption by PRECEDING_KEY . - bcache: fix wrong usage use-after-freed on keylist in out_nocoalesce branch of btree_gc_coalesce . - bcache: ignore read-ahead request failure on backing device . - bcache: improve bcache_reboot . - bcache: improve error message in bch_cached_dev_run . - bcache: make bset_search_tree be more understandable . - bcache: make is_discard_enabled static . - bcache: more detailed error message to bcache_device_link . - bcache: move definition of "int ret" out of macro read_bucket . - bcache: never set KEY_PTRS of journal key to 0 in journal_reclaim . - bcache: only clear BTREE_NODE_dirty bit when it is set . - bcache: only set BCACHE_DEV_WB_RUNNING when cached device attached . - bcache: performance improvement for btree_flush_write . - bcache: remove redundant LIST_HEAD from run_cache_set . - bcache: remove retry_flush_write from struct cache_set . - bcache: remove unncessary code in bch_btree_keys_init . - bcache: remove unnecessary prefetch in bset_search_tree . - bcache: remove "XXX:" comment line from run_cache_set . - bcache: return error immediately in bch_journal_replay . - bcache: Revert "bcache: fix high CPU occupancy during journal" . - bcache: Revert "bcache: free heap cache_set-greater than flush_btree in bch_journal_free" . - bcache: set largest seq to ja-greater than seq[bucket_index] in journal_read_bucket . - bcache: shrink btree node cache after bch_btree_check . - bcache: stop writeback kthread and kworker when bch_cached_dev_run failed . - bcache: use sysfs_match_string instead of __sysfs_match_string . - be2net: Fix number of Rx queues used for flow hashing . - be2net: Signal that the device cannot transmit during reconfiguration . - be2net: Synchronize be_update_queues with dev_watchdog . - block, bfq: NULL out the bic when it"s no longer valid . - bnx2x: Prevent load reordering in tx completion processing . - bnxt_en: Fix aggregation buffer leak under OOM condition . - bonding: fix arp_validate toggling in active-backup mode . - bonding: Force slave speed check after link state recovery for 802.3ad . - bpf, x64: fix stack layout of JITed bpf code . - bpf, x64: save 5 bytes in prologue when ebpf insns came from cbpf . - bridge: Fix error path for kobject_init_and_add . - btrfs: fix race between block group removal and block group allocation . - cgroup: Use css_tryget instead of css_tryget_online in task_get_css . - clk: qcom: Fix -Wunused-const-variable . - clk: rockchip: Do not yell about bad mmc phases when getting . - clk: tegra210: fix PLLU and PLLU_OUT1 . - cpufreq: acpi-cpufreq: Report if CPU does not support boost technologies . - cpufreq: brcmstb-avs-cpufreq: Fix initial command check . - cpufreq: brcmstb-avs-cpufreq: Fix types for voltage/frequency . - cpufreq: check if policy is inactive early in __cpufreq_get . - cpufreq: kirkwood: fix possible object reference leak . - cpufreq/pasemi: fix possible object reference leak . - cpufreq: pmac32: fix possible object reference leak . - cpufreq: ppc_cbe: fix possible object reference leak . - cpufreq: Use struct kobj_attribute instead of struct global_attr . - crypto: arm64/sha1-ce - correct digest for empty data in finup . - crypto: arm64/sha2-ce - correct digest for empty data in finup . - crypto: ccp - Fix 3DES complaint from ccp-crypto module . - crypto: ccp - fix AES CFB error exposed by new test vectors . - crypto: ccp - Fix SEV_VERSION_GREATER_OR_EQUAL . - crypto: ccp/gcm - use const time tag comparison . - crypto: ccp - memset structure fields to zero before reuse . - crypto: ccp - Validate the the error value used to index error messages . - crypto: chacha20poly1305 - fix atomic sleep when using async algorithm . - crypto: crypto4xx - fix a potential double free in ppc4xx_trng_probe . - crypto: ghash - fix unaligned memory access in ghash_setkey . - crypto: talitos - Align SEC1 accesses to 32 bits boundaries . - crypto: talitos - check data blocksize in ablkcipher . - crypto: talitos - fix CTR alg blocksize . - crypto: talitos - fix max key size for sha384 and sha512 . - crypto: talitos - HMAC SNOOP NO AFEU mode requires SW icv checking . - crypto: talitos - properly handle split ICV . - crypto: talitos - reduce max key size for SEC1 . - crypto: talitos - rename alternative AEAD algos . - dasd_fba: Display "00000000" for zero page when dumping sense . - dmaengine: hsu: Revert "set HSU_CH_MTSR to memory width" . - dpaa_eth: fix SG frame cleanup . - drm/meson: Add support for XBGR8888 ABGR8888 formats . - drm/msm/a3xx: remove TPL1 regs from snapshot . - drm/nouveau/i2c: Enable i2c pads busses during preinit . - drm/rockchip: Properly adjust to a true clock in adjusted_mode . - e1000e: start network tx queue only when link is up . - ethtool: check the return value of get_regs_len . - ethtool: fix potential userspace buffer overflow . - Fix kABI for asus-wmi quirk_entry field addition . - Fix memory leak in sctp_process_init . - fork, memcg: fix cached_stacks case . - fork, memcg: fix crash in free_thread_stack on memcg charge fail . - hid: wacom: correct touch resolution x/y typo . - hid: wacom: generic: Correct pad syncing . - hid: wacom: generic: only switch the mode on devices with LEDs . - hid: wacom: generic: read HID_DG_CONTACTMAX from any feature report . - input: elantech - enable middle button support on 2 ThinkPads . - input: imx_keypad - make sure keyboard can always wake up system . - input: psmouse - fix build error of multiple definition . - input: synaptics - enable SMBUS on T480 thinkpad trackpad . - input: tm2-touchkey - acknowledge that setting brightness is a blocking call . - intel_th: msu: Fix single mode with disabled IOMMU . - ipv4: Fix raw socket lookup for local traffic . - ipv4/igmp: fix another memory leak in igmpv3_del_delrec . - ipv4/igmp: fix build error if !CONFIG_IP_MULTICAST . - ipv4: Use return value of inet_iif for __raw_v4_lookup in the while loop . - ipv6: Consider sk_bound_dev_if when binding a raw socket to an address . - ipv6: fix EFAULT on sendto with icmpv6 and hdrincl . - ipv6: flowlabel: fl6_sock_lookup must use atomic_inc_not_zero . - ipv6: use READ_ONCE for inet-greater than hdrincl as in ipv4 . - kbuild: use -flive-patching when CONFIG_LIVEPATCH is enabled . - kernel: jump label transformation performance . - kvm: arm/arm64: vgic-its: Take the srcu lock when parsing the memslots . - kvm: arm/arm64: vgic-its: Take the srcu lock when writing to guest memory . - kvm: mmu: Fix overflow on kvm mmu page limit calculation . - kvm/mmu: kABI fix for *_mmu_pages changes in struct kvm_arch . - kvm: polling: add architecture backend to disable polling . - kvm: s390: change default halt poll time to 50us . - kvm: s390: enable CONFIG_HAVE_KVM_NO_POLL We need to enable CONFIG_HAVE_KVM_NO_POLL for bsc#1119222 - kvm: s390: fix typo in parameter description . - kvm: s390: kABI Workaround for "kvm_vcpu_stat" Add halt_no_poll_steal to kvm_vcpu_stat. Hide it from the kABI checker. - kvm: s390: kABI Workaround for "lowcore" . - kvm: s390: provide kvm_arch_no_poll function . - kvm: svm/avic: Do not send AVIC doorbell to self . - kvm: SVM: Fix detection of AMD Errata 1096 . - lapb: fixed leak of control-blocks . - lib: fix stall in __bitmap_parselist . - libnvdimm/namespace: Fix label tracking error . - lib/bitmap.c: make bitmap_parselist thread-safe and much faster . - lib/scatterlist: Fix mapping iterator when sg-greater than offset is greater than PAGE_SIZE . - livepatch: Remove duplicate warning about missing reliable stacktrace support . - livepatch: Use static buffer for debugging messages under rq lock . - llc: fix skb leak in llc_build_and_send_ui_pkt . - media: cpia2_usb: first wake up, then free in disconnect . - media: marvell-ccic: fix DMA s/g desc number calculation . - media: s5p-mfc: Make additional clocks optional . - media: v4l2: Test type instead of cfg-greater than type in v4l2_ctrl_new_custom . - media: vivid: fix incorrect assignment operation when setting video mode . - mei: bus: need to unlink client before freeing . - mei: me: add denverton innovation engine device IDs . - mei: me: add gemini lake devices id . - memory: tegra: Fix integer overflow on tick value calculation . - memstick: Fix error cleanup path of memstick_init . - mfd: intel-lpss: Release IDA resources . - mmc: sdhci-pci: Try "cd" for card-detect lookup before using NULL . - mm: migrate: Fix reference check race between __find_get_block and migration . - mm/nvdimm: add is_ioremap_addr and use that to check ioremap address . - mm, page_alloc: fix has_unmovable_pages for HugePages . - mm: replace all open encodings for NUMA_NO_NODE . - neigh: fix use-after-free read in pneigh_get_next . - net/af_iucv: remove GFP_DMA restriction for HiperTransport . - net: avoid weird emergency message . - net: fec: fix the clk mismatch in failed_reset path . - netfilter: conntrack: fix calculation of next bucket number in early_drop . - net-gro: fix use-after-free read in napi_gro_frags . - net/mlx4_core: Change the error print to info print . - net/mlx4_en: ethtool, Remove unsupported SFP EEPROM high pages query . - net/mlx5: Allocate root ns memory using kzalloc to match kfree . - net/mlx5: Avoid double free in fs init error unwinding path . - net: mvneta: Fix err code path of probe . - net: mvpp2: fix bad MVPP2_TXQ_SCHED_TOKEN_CNTR_REG queue value . - net: openvswitch: do not free vport if register_netdevice is failed . - net/packet: fix memory leak in packet_set_ring . - net: rds: fix memory leak in rds_ib_flush_mr_pool . - net: seeq: fix crash caused by not set dev.parent . - net: stmmac: fix reset gpio free missing . - net: usb: qmi_wwan: add Telit 0x1260 and 0x1261 compositions . - nvme: fix memory leak caused by incorrect subsystem free . - ocfs2: add first lock wait time in locking_state . - ocfs2: add last unlock times in locking_state . - ocfs2: add locking filter debugfs file . - packet: Fix error path in packet_init . - packet: in recvmsg msg_name return at least sizeof sockaddr_ll . - pci: Always allow probing with driver_override . - pci: hv: Add hv_pci_remove_slots when we unload the driver . - pci: hv: Add pci_destroy_slot in pci_devices_present_work, if necessary . - pci: hv: Fix a memory leak in hv_eject_device_work . - pci: hv: Fix a use-after-free bug in hv_eject_device_work . - pci: hv: Fix return value check in hv_pci_assign_slots . - pci: hv: Remove unused reason for refcount handler . - pci: hv: support reporting serial number as slot information . - pci: Return error if cannot probe VF . - pkey: Indicate old mkvp only if old and current mkvp are different . - pktgen: do not sleep with the thread lock held . - platform/x86: asus-nb-wmi: Support ALS on the Zenbook UX430UQ . - platform/x86: asus-wmi: Only Tell EC the OS will handle display hotkeys from asus_nb_wmi . - platform/x86: intel_turbo_max_3: Remove restriction for HWP platforms . - platform/x86: pmc_atom: Add CB4063 Beckhoff Automation board to critclk_systems DMI table . - powerpc/64s: Remove POWER9 DD1 support . - powerpc/crypto: Use cheaper random numbers for crc-vpmsum self-test . - powerpc/mm: Change function prototype . - powerpc/mm: Consolidate numa_enable check and min_common_depth check . - powerpc/mm/drconf: Use NUMA_NO_NODE on failures instead of node 0 . - powerpc/mm: Fix node look up with numa=off boot . - powerpc/mm/hugetlb: Update huge_ptep_set_access_flags to call __ptep_set_access_flags directly . - powerpc/mm/radix: Change pte relax sequence to handle nest MMU hang . - powerpc/mm/radix: Move function from radix.h to pgtable-radix.c . - powerpc/watchpoint: Restore NV GPRs while returning from exception . - ppp: deflate: Fix possible crash in deflate_init . - rds: ib: fix "passing zero to ERR_PTR" warning . - Revert "bcache: set CACHE_SET_IO_DISABLE in bch_cached_dev_error" . - Revert "e1000e: fix cyclic resets at link up with active tx" . - Revert "livepatch: Remove reliable stacktrace check in klp_try_switch_task" . - Revert "serial: 8250: Do not service RX FIFO if interrupts are disabled" . - rtnetlink: always put IFLA_LINK for links with a link-netnsid . - s390/qeth: be drop monitor friendly . - s390/vtime: steal time exponential moving average . - scripts/git_sort/git_sort.py: Add mmots tree. - scsi: ibmvfc: fix WARN_ON during event pool release . - sctp: Free cookie before we memdup a new one . - sctp: silence warns on sctp_stream_init allocations . - serial: uartps: Do not add a trailing semicolon to macro . - serial: uartps: Fix long line over 80 chars . - serial: uartps: Fix multiple line dereference . - serial: uartps: Remove useless return from cdns_uart_poll_put_char . - staging: comedi: amplc_pci230: fix null pointer deref on interrupt . - staging: comedi: dt282x: fix a null pointer deref on interrupt . - staging: rtl8712: reduce stack usage, again . - sunhv: Fix device naming inconsistency between sunhv_console and sunhv_reg . - tcp: reduce tcp_fastretrans_alert verbosity . - team: Always enable vlan tx offload . - tty: rocket: fix incorrect forward declaration of "rp_init" . - tty: serial_core: Set port active bit in uart_port_activate . - tty: serial: cpm_uart - fix init when SMC is relocated . - tuntap: synchronize through tfiles array instead of tun-greater than numqueues . - usb: gadget: ether: Fix race between gether_disconnect and rx_submit . - usb: gadget: fusb300_udc: Fix memory leak of fusb300-greater than ep[i] . - usb: gadget: udc: lpc32xx: allocate descriptor with GFP_ATOMIC . - usb: pci-quirks: Correct AMD PLL quirk detection . - usb: serial: ftdi_sio: add ID for isodebug v1 . - usb: serial: option: add support for GosunCn ME3630 RNDIS mode . - vmci: Fix integer overflow in VMCI handle arrays . - vsock/virtio: free packets during the socket release . - vsock/virtio: set SOCK_DONE on peer shutdown . - wil6210: fix potential out-of-bounds read . - x86, mm: fix fast GUP with hyper-based TLB flushing . - xen: let alloc_xenballooned_pages fail if not enough memory free . - xfs: do not overflow xattr listent buffer . Special Instructions and Notes: Please reboot the system after installing this update.

Platform:
SUSE Linux Enterprise Server 15
SUSE Linux Enterprise Desktop 15
Product:
kernel
Reference:
SUSE-SU-2019:2071-1
CVE-2018-20855
CVE-2019-1125
CVE-2019-11810
CVE-2019-13631
CVE-2019-13648
CVE-2019-14283
CVE-2019-14284
CVE    7
CVE-2018-20855
CVE-2019-14284
CVE-2019-14283
CVE-2019-1125
...
CPE    2124
cpe:/o:linux:linux_kernel:2.4.27:pre5
cpe:/o:linux:linux_kernel:2.4.27:pre4
cpe:/o:linux:linux_kernel:2.4.27:pre1
cpe:/o:linux:linux_kernel:2.4.27:pre3
...

© SecPod Technologies