Vulnerability   
Search   
    Search 211766 CVE descriptions
and 97459 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.1.4.2021.1572.1
Category:SuSE Local Security Checks
Title:SUSE: Security Advisory (SUSE-SU-2021:1572-1)
Summary:The remote host is missing an update for the 'Linux Kernel' package(s) announced via the SUSE-SU-2021:1572-1 advisory.
Description:Summary:
The remote host is missing an update for the 'Linux Kernel' package(s) announced via the SUSE-SU-2021:1572-1 advisory.

Vulnerability Insight:
The SUSE Linux Enterprise 12 SP5 Azure kernel was updated to receive various security and bugfixes.


The following security bugs were fixed:

CVE-2020-36312: Fixed an issue within virt/kvm/kvm_main.c that had a
kvm_io_bus_unregister_dev memory leak upon a kmalloc failure
(bnc#1184509).

CVE-2021-29650: Fixed an issue within the netfilter subsystem that
allowed attackers to cause a denial of service (panic) because
net/netfilter/x_tables.c and include/linux/netfilter/x_tables.h lack a
full memory barrier upon the assignment of a new table value
(bnc#1184208).

CVE-2021-29155: Fixed an issue within kernel/bpf/verifier.c that
performed undesirable out-of-bounds speculation on pointer arithmetic,
leading to side-channel attacks that defeat Spectre mitigations and
obtain sensitive information from kernel memory. Specifically, for
sequences of pointer arithmetic operations, the pointer modification
performed by the first operation is not correctly accounted for when
restricting subsequent operations (bnc#1184942).

CVE-2020-36310: Fixed an issue within arch/x86/kvm/svm/svm.c that
allowed a set_memory_region_test infinite loop for certain nested page
faults (bnc#1184512).

CVE-2021-28950: Fixed an issue within fs/fuse/fuse_i.h where a 'stall on
CPU' could have occured because a retry loop continually finds the same
bad inode (bnc#1184194, bnc#1184211).

CVE-2020-36322: Fixed an issue within the FUSE filesystem implementation
where fuse_do_getattr() calls make_bad_inode() in inappropriate
situations, causing a system crash. NOTE: the original fix for this
vulnerability was incomplete, and its incompleteness is tracked as
CVE-2021-28950 (bnc#1184211, bnc#1184952).

CVE-2021-3444: Fixed incorrect mod32 BPF verifier truncation
(bsc#1184170).

The following non-security bugs were fixed:

arm64: PCI: mobiveil: remove driver Prepare to replace it with
upstreamed driver

blk-settings: align max_sectors on 'logical_block_size' boundary
(bsc#1185195).

block: fix use-after-free on cached last_lookup partition (bsc#1181062).

block: recalculate segment count for multi-segment discards correctly
(bsc#1184724).

btrfs: fix qgroup data rsv leak caused by falloc failure (bsc#1185549).

btrfs: track qgroup released data in own variable in
insert_prealloc_file_extent (bsc#1185549).

cdc-acm: fix BREAK rx code path adding necessary calls (git-fixes).

cxgb4: avoid collecting SGE_QBASE regs during traffic (bsc#1097585
bsc#1097586 bsc#1097587 bsc#1097588 bsc#1097583 bsc#1097584).

drivers/perf: thunderx2_pmu: Fix memory resource error handling
(git-fixes).

ext4: find old entry again if failed to rename whiteout (bsc#1184742).

ext4: fix potential error in ext4_do_update_inode (bsc#1184731).

fs: direct-io: fix missing sdio->boundary (bsc#1184736).

handle also the opposite type of race condition

i40e: Fix display statistics for veb_tc (bsc#1111981).

i40e: Fix kernel oo... [Please see the references for more information on the vulnerabilities]

Affected Software/OS:
'Linux Kernel' package(s) on SUSE Linux Enterprise Server 12-SP5

Solution:
Please install the updated package(s).

CVSS Score:
4.9

CVSS Vector:
AV:L/AC:L/Au:N/C:N/I:N/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2021-3444
http://packetstormsecurity.com/files/162117/Kernel-Live-Patch-Security-Notice-LSN-0075-1.html
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=9b00f1b78809
https://www.openwall.com/lists/oss-security/2021/03/23/2
http://www.openwall.com/lists/oss-security/2021/03/23/2
CopyrightCopyright (C) 2021 Greenbone Networks GmbH

This is only one of 97459 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2021 E-Soft Inc. All rights reserved.