SUSE-SU-2020:3544-1

Source
https://www.suse.com/support/update/announcement/2020/suse-su-20203544-1/
Import Source
https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:3544-1.json
JSON Data
https://api.osv.dev/v1/vulns/SUSE-SU-2020:3544-1
Related
Published
2020-11-26T15:53:57Z
Modified
2020-11-26T15:53:57Z
Summary
Security update for the Linux Kernel
Details

The SUSE Linux Enterprise 12 SP4 kernel was updated to receive various security and bug fixes.

The following security bugs were fixed:

  • CVE-2020-25705: A flaw in the way reply ICMP packets are limited in was found that allowed to quickly scan open UDP ports. This flaw allowed an off-path remote user to effectively bypassing source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software and services that rely on UDP source port randomization (like DNS) are indirectly affected as well. Kernel versions may be vulnerable to this issue (bsc#1175721, bsc#1178782).
  • CVE-2020-25704: Fixed a memory leak in perfeventparseaddrfilter() (bsc#1178393).
  • CVE-2020-25668: Fixed a use-after-free in confontop() (bnc#1178123).
  • CVE-2020-25656: Fixed a concurrency use-after-free in vtdokdgkb_ioctl (bnc#1177766).
  • CVE-2020-25285: Fixed a race condition between hugetlb sysctl handlers in mm/hugetlb.c (bnc#1176485).
  • CVE-2020-0430: Fixed an OOB read in skb_headlen of /include/linux/skbuff.h (bnc#1176723).
  • CVE-2020-14351: Fixed a race in the perfmmapclose() function (bsc#1177086).
  • CVE-2020-16120: Fixed a permissions issue in ovlpathopen() (bsc#1177470).
  • CVE-2020-8694: Restricted energy meter to root access (bsc#1170415).
  • CVE-2020-12351: Implemented a kABI workaround for bluetooth l2cap_ops filter addition (bsc#1177724).
  • CVE-2020-12352: Fixed an information leak when processing certain AMP packets aka 'BleedingTooth' (bsc#1177725).
  • CVE-2020-25212: Fixed a TOCTOU mismatch in the NFS client code (bnc#1176381).
  • CVE-2020-25645: Fixed an an issue in IPsec that caused traffic between two Geneve endpoints to be unencrypted (bnc#1177511).
  • CVE-2020-14381: Fixed a UAF in the fast user mutex (futex) wait operation (bsc#1176011).
  • CVE-2020-25643: Fixed an improper input validation in the pppcpparsecr function of the HDLCPPP module (bnc#1177206).
  • CVE-2020-25641: Fixed a zero-length biovec request issued by the block subsystem could have caused the kernel to enter an infinite loop, causing a denial of service (bsc#1177121).
  • CVE-2020-26088: Fixed an improper CAPNETRAW check in NFC socket creation could have been used by local attackers to create raw sockets, bypassing security mechanisms (bsc#1176990).
  • CVE-2020-14390: Fixed an out-of-bounds memory write leading to memory corruption or a denial of service when changing screen size (bnc#1176235).
  • CVE-2020-0432: Fixed an out of bounds write due to an integer overflow (bsc#1176721).
  • CVE-2020-0427: Fixed an out of bounds read due to a use after free (bsc#1176725).
  • CVE-2020-0431: Fixed an out of bounds write due to a missing bounds check (bsc#1176722).
  • CVE-2020-0404: Fixed a linked list corruption due to an unusual root cause (bsc#1176423).
  • CVE-2020-25284: Fixed an incomplete permission checking for access to rbd devices, which could have been leveraged by local attackers to map or unmap rbd block devices (bsc#1176482).
  • CVE-2020-27673: Fixed an issue where rogue guests could have caused denial of service of Dom0 via high frequency events (XSA-332 bsc#1177411)
  • CVE-2020-27675: Fixed a race condition in event handler which may crash dom0 (XSA-331 bsc#1177410).

The following non-security bugs were fixed:

  • btrfs: remove root usage from can_overcommit (bsc#1131277).
  • hv: vmbus: Add timeout to vmbuswaitfor_unload (bsc#1177816).
  • hypervfb: disable superfluous VERSIONWIN10_V5 case (bsc#1175306).
  • hypervfb: Update screeninfo after removing old framebuffer (bsc#1175306).
  • livepatch: Add -fdump-ipa-clones to build (). Add support for -fdump-ipa-clones GCC option. Update config files accordingly.
  • livepatch: Test if -fdump-ipa-clones is really available As of now we add -fdump-ipa-clones unconditionally. It does not cause a trouble if the kernel is build with the supported toolchain. Otherwise it could fail easily. Do the correct thing and test for the availability.
  • NFS: On fatal writeback errors, we need to call nfsinoderemove_request() (bsc#1177340).
  • NFS: only invalidate dentrys that are clearly invalid (bsc#1178669 bsc#1170139).
  • NFS: Revalidate the file mapping on all fatal writeback errors (bsc#1177340).
  • NFSv4: do not mark all open state for recovery when handling recallable state revoked flag (bsc#1176935).
  • obsolete_kmp: provide newer version than the obsoleted one (boo#1170232).
  • ocfs2: give applications more IO opportunities during fstrim (bsc#1175228).
  • powerpc/pseries/cpuidle: add polling idle for shared processor guests (bsc#1178765 ltc#188968).
  • rpadlpario: Add MODULEDESCRIPTION entries to kernel modules (bsc#1176869 ltc#188243).
  • scsi: fnic: Do not call 'scsi_done()' for unhandled commands (bsc#1168468, bsc#1171675).
  • scsi: qla2xxx: Do not consume srb greedily (bsc#1173233).
  • scsi: qla2xxx: Handle incorrect entry_type entries (bsc#1173233).
  • video: hyperv: hyperv_fb: Obtain screen resolution from Hyper-V host (bsc#1175306).
  • video: hyperv: hyperv_fb: Support deferred IO for Hyper-V frame buffer driver (bsc#1175306).
  • video: hyperv: hyperv_fb: Use physical memory for fb on HyperV Gen 1 VMs (bsc#1175306).
  • x86/kexec: Use up-to-dated screen_info copy to fill boot params (bsc#1175306).
  • xen/blkback: use lateeoi irq binding (XSA-332 bsc#1177411).
  • xen/events: add a new 'late EOI' evtchn framework (XSA-332 bsc#1177411).
  • xen/events: add a proper barrier to 2-level uevent unmasking (XSA-332 bsc#1177411).
  • xen/events: avoid removing an event channel while handling it (XSA-331 bsc#1177410).
  • xen/events: block rogue events for some time (XSA-332 bsc#1177411).
  • xen/events: defer eoi in case of excessive number of events (XSA-332 bsc#1177411).
  • xen/events: do not use chip_data for legacy IRQs (XSA-332 bsc#1065600).
  • xen/events: fix race in evtchnfifounmask() (XSA-332 bsc#1177411).
  • xen/events: switch user event channels to lateeoi model (XSA-332 bsc#1177411).
  • xen/events: use a common cpu hotplug hook for event channels (XSA-332 bsc#1177411).
  • xen/netback: use lateeoi irq binding (XSA-332 bsc#1177411).
  • xen/pciback: use lateeoi irq binding (XSA-332 bsc#1177411).
  • xen/scsiback: use lateeoi irq binding (XSA-332 bsc#1177411).
  • xen uses irqdesc::irqdatacommon::handler_data to store a per interrupt XEN data pointer which contains XEN specific information (XSA-332 bsc#1065600).
References

Affected packages

SUSE:OpenStack Cloud 9 / kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20OpenStack%20Cloud%209

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-95.65.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-95.65.1",
            "kernel-devel": "4.12.14-95.65.1",
            "kernel-default-base": "4.12.14-95.65.1",
            "kernel-default": "4.12.14-95.65.1",
            "kernel-source": "4.12.14-95.65.1",
            "kernel-syms": "4.12.14-95.65.1",
            "kernel-default-devel": "4.12.14-95.65.1"
        }
    ]
}

SUSE:OpenStack Cloud 9 / kernel-source

Package

Name
kernel-source
Purl
pkg:rpm/suse/kernel-source&distro=SUSE%20OpenStack%20Cloud%209

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-95.65.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-95.65.1",
            "kernel-devel": "4.12.14-95.65.1",
            "kernel-default-base": "4.12.14-95.65.1",
            "kernel-default": "4.12.14-95.65.1",
            "kernel-source": "4.12.14-95.65.1",
            "kernel-syms": "4.12.14-95.65.1",
            "kernel-default-devel": "4.12.14-95.65.1"
        }
    ]
}

SUSE:OpenStack Cloud 9 / kernel-syms

Package

Name
kernel-syms
Purl
pkg:rpm/suse/kernel-syms&distro=SUSE%20OpenStack%20Cloud%209

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-95.65.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-95.65.1",
            "kernel-devel": "4.12.14-95.65.1",
            "kernel-default-base": "4.12.14-95.65.1",
            "kernel-default": "4.12.14-95.65.1",
            "kernel-source": "4.12.14-95.65.1",
            "kernel-syms": "4.12.14-95.65.1",
            "kernel-default-devel": "4.12.14-95.65.1"
        }
    ]
}

SUSE:OpenStack Cloud Crowbar 9 / kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-95.65.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-95.65.1",
            "kernel-devel": "4.12.14-95.65.1",
            "kernel-default-base": "4.12.14-95.65.1",
            "kernel-default": "4.12.14-95.65.1",
            "kernel-source": "4.12.14-95.65.1",
            "kernel-syms": "4.12.14-95.65.1",
            "kernel-default-devel": "4.12.14-95.65.1"
        }
    ]
}

SUSE:OpenStack Cloud Crowbar 9 / kernel-source

Package

Name
kernel-source
Purl
pkg:rpm/suse/kernel-source&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-95.65.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-95.65.1",
            "kernel-devel": "4.12.14-95.65.1",
            "kernel-default-base": "4.12.14-95.65.1",
            "kernel-default": "4.12.14-95.65.1",
            "kernel-source": "4.12.14-95.65.1",
            "kernel-syms": "4.12.14-95.65.1",
            "kernel-default-devel": "4.12.14-95.65.1"
        }
    ]
}

SUSE:OpenStack Cloud Crowbar 9 / kernel-syms

Package

Name
kernel-syms
Purl
pkg:rpm/suse/kernel-syms&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-95.65.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-95.65.1",
            "kernel-devel": "4.12.14-95.65.1",
            "kernel-default-base": "4.12.14-95.65.1",
            "kernel-default": "4.12.14-95.65.1",
            "kernel-source": "4.12.14-95.65.1",
            "kernel-syms": "4.12.14-95.65.1",
            "kernel-default-devel": "4.12.14-95.65.1"
        }
    ]
}

SUSE:Linux Enterprise High Availability Extension 12 SP4 / kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-95.65.1

Ecosystem specific

{
    "binaries": [
        {
            "dlm-kmp-default": "4.12.14-95.65.1",
            "gfs2-kmp-default": "4.12.14-95.65.1",
            "ocfs2-kmp-default": "4.12.14-95.65.1",
            "cluster-md-kmp-default": "4.12.14-95.65.1"
        }
    ]
}

SUSE:Linux Enterprise Live Patching 12 SP4 / kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-95.65.1

Ecosystem specific

{
    "binaries": [
        {
            "kgraft-patch-4_12_14-95_65-default": "1-6.5.1",
            "kernel-default-kgraft": "4.12.14-95.65.1",
            "kernel-default-kgraft-devel": "4.12.14-95.65.1"
        }
    ]
}

SUSE:Linux Enterprise Live Patching 12 SP4 / kgraft-patch-SLE12-SP4_Update_17

Package

Name
kgraft-patch-SLE12-SP4_Update_17
Purl
pkg:rpm/suse/kgraft-patch-SLE12-SP4_Update_17&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
1-6.5.1

Ecosystem specific

{
    "binaries": [
        {
            "kgraft-patch-4_12_14-95_65-default": "1-6.5.1",
            "kernel-default-kgraft": "4.12.14-95.65.1",
            "kernel-default-kgraft-devel": "4.12.14-95.65.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP4 / kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-95.65.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-95.65.1",
            "kernel-devel": "4.12.14-95.65.1",
            "kernel-default-base": "4.12.14-95.65.1",
            "kernel-default": "4.12.14-95.65.1",
            "kernel-source": "4.12.14-95.65.1",
            "kernel-syms": "4.12.14-95.65.1",
            "kernel-default-devel": "4.12.14-95.65.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP4 / kernel-source

Package

Name
kernel-source
Purl
pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-95.65.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-95.65.1",
            "kernel-devel": "4.12.14-95.65.1",
            "kernel-default-base": "4.12.14-95.65.1",
            "kernel-default": "4.12.14-95.65.1",
            "kernel-source": "4.12.14-95.65.1",
            "kernel-syms": "4.12.14-95.65.1",
            "kernel-default-devel": "4.12.14-95.65.1"
        }
    ]
}

SUSE:Linux Enterprise Server for SAP Applications 12 SP4 / kernel-syms

Package

Name
kernel-syms
Purl
pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-95.65.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-95.65.1",
            "kernel-devel": "4.12.14-95.65.1",
            "kernel-default-base": "4.12.14-95.65.1",
            "kernel-default": "4.12.14-95.65.1",
            "kernel-source": "4.12.14-95.65.1",
            "kernel-syms": "4.12.14-95.65.1",
            "kernel-default-devel": "4.12.14-95.65.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP4-LTSS / kernel-default

Package

Name
kernel-default
Purl
pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-95.65.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-95.65.1",
            "kernel-devel": "4.12.14-95.65.1",
            "kernel-default-base": "4.12.14-95.65.1",
            "kernel-default-man": "4.12.14-95.65.1",
            "kernel-default": "4.12.14-95.65.1",
            "kernel-source": "4.12.14-95.65.1",
            "kernel-syms": "4.12.14-95.65.1",
            "kernel-default-devel": "4.12.14-95.65.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP4-LTSS / kernel-source

Package

Name
kernel-source
Purl
pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-95.65.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-95.65.1",
            "kernel-devel": "4.12.14-95.65.1",
            "kernel-default-base": "4.12.14-95.65.1",
            "kernel-default-man": "4.12.14-95.65.1",
            "kernel-default": "4.12.14-95.65.1",
            "kernel-source": "4.12.14-95.65.1",
            "kernel-syms": "4.12.14-95.65.1",
            "kernel-default-devel": "4.12.14-95.65.1"
        }
    ]
}

SUSE:Linux Enterprise Server 12 SP4-LTSS / kernel-syms

Package

Name
kernel-syms
Purl
pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSS

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.12.14-95.65.1

Ecosystem specific

{
    "binaries": [
        {
            "kernel-macros": "4.12.14-95.65.1",
            "kernel-devel": "4.12.14-95.65.1",
            "kernel-default-base": "4.12.14-95.65.1",
            "kernel-default-man": "4.12.14-95.65.1",
            "kernel-default": "4.12.14-95.65.1",
            "kernel-source": "4.12.14-95.65.1",
            "kernel-syms": "4.12.14-95.65.1",
            "kernel-default-devel": "4.12.14-95.65.1"
        }
    ]
}