|Category:||SuSE Local Security Checks|
|Title:||SUSE: Security Advisory (SUSE-SU-2021:1572-1)|
|Summary:||The remote host is missing an update for the 'Linux Kernel' package(s) announced via the SUSE-SU-2021:1572-1 advisory.|
The remote host is missing an update for the 'Linux Kernel' package(s) announced via the SUSE-SU-2021:1572-1 advisory.
The SUSE Linux Enterprise 12 SP5 Azure kernel was updated to receive various security and bugfixes.
The following security bugs were fixed:
CVE-2020-36312: Fixed an issue within virt/kvm/kvm_main.c that had a
kvm_io_bus_unregister_dev memory leak upon a kmalloc failure
CVE-2021-29650: Fixed an issue within the netfilter subsystem that
allowed attackers to cause a denial of service (panic) because
net/netfilter/x_tables.c and include/linux/netfilter/x_tables.h lack a
full memory barrier upon the assignment of a new table value
CVE-2021-29155: Fixed an issue within kernel/bpf/verifier.c that
performed undesirable out-of-bounds speculation on pointer arithmetic,
leading to side-channel attacks that defeat Spectre mitigations and
obtain sensitive information from kernel memory. Specifically, for
sequences of pointer arithmetic operations, the pointer modification
performed by the first operation is not correctly accounted for when
restricting subsequent operations (bnc#1184942).
CVE-2020-36310: Fixed an issue within arch/x86/kvm/svm/svm.c that
allowed a set_memory_region_test infinite loop for certain nested page
CVE-2021-28950: Fixed an issue within fs/fuse/fuse_i.h where a 'stall on
CPU' could have occured because a retry loop continually finds the same
bad inode (bnc#1184194, bnc#1184211).
CVE-2020-36322: Fixed an issue within the FUSE filesystem implementation
where fuse_do_getattr() calls make_bad_inode() in inappropriate
situations, causing a system crash. NOTE: the original fix for this
vulnerability was incomplete, and its incompleteness is tracked as
CVE-2021-28950 (bnc#1184211, bnc#1184952).
CVE-2021-3444: Fixed incorrect mod32 BPF verifier truncation
The following non-security bugs were fixed:
arm64: PCI: mobiveil: remove driver Prepare to replace it with
blk-settings: align max_sectors on 'logical_block_size' boundary
block: fix use-after-free on cached last_lookup partition (bsc#1181062).
block: recalculate segment count for multi-segment discards correctly
btrfs: fix qgroup data rsv leak caused by falloc failure (bsc#1185549).
btrfs: track qgroup released data in own variable in
cdc-acm: fix BREAK rx code path adding necessary calls (git-fixes).
cxgb4: avoid collecting SGE_QBASE regs during traffic (bsc#1097585
bsc#1097586 bsc#1097587 bsc#1097588 bsc#1097583 bsc#1097584).
drivers/perf: thunderx2_pmu: Fix memory resource error handling
ext4: find old entry again if failed to rename whiteout (bsc#1184742).
ext4: fix potential error in ext4_do_update_inode (bsc#1184731).
fs: direct-io: fix missing sdio->boundary (bsc#1184736).
handle also the opposite type of race condition
i40e: Fix display statistics for veb_tc (bsc#1111981).
i40e: Fix kernel oo... [Please see the references for more information on the vulnerabilities]
'Linux Kernel' package(s) on SUSE Linux Enterprise Server 12-SP5
Please install the updated package(s).
Common Vulnerability Exposure (CVE) ID: CVE-2021-3444|
|Copyright||Copyright (C) 2021 Greenbone Networks GmbH|
|This is only one of 97459 vulnerability tests in our test suite. Find out more about running a complete security audit.|
To run a free test of this vulnerability against your system, register below.