File _patchinfo of Package patchinfo.17123
<patchinfo incident="17123">
<issue id="1065600" tracker="bnc">Backports of upstream Xen-related kernel patches</issue>
<issue id="1083244" tracker="bnc">VUL-1: CVE-2017-18204: kernel-source: denial of service (deadlock) via DIO requests inside the ocfs2_setattr function in fs/ocfs2/file.c</issue>
<issue id="1131277" tracker="bnc">L3: System panic in btrfs_async_reclaim_metadata_space()->can_overcommit()</issue>
<issue id="1170415" tracker="bnc">VUL-0: CVE-2020-8694: kernel-source: Intel RAPL sidechannel aka PLATYPUS attack</issue>
<issue id="1175749" tracker="bnc">L3: Sles15sp2 xen VM crashed with oops Need core analyzed</issue>
<issue id="1176011" tracker="bnc">VUL-0: CVE-2020-14381: kernel-source, kernel: referencing inode of removed superblock in get_futex_key() causes UAF</issue>
<issue id="1176235" tracker="bnc">VUL-0: CVE-2020-14390: kernel-source: slab-out-of-bounds in fbcon_redraw_softback for latest linux</issue>
<issue id="1176253" tracker="bnc">VUL-0: CVE-2020-14390: kernel live patch: slab-out-of-bounds in fbcon_redraw_softback for latest linux</issue>
<issue id="1176278" tracker="bnc">VUL-0: kernel-source: out-of-bounds BUG in function "vgacon_scrolldelta"</issue>
<issue id="1176381" tracker="bnc">VUL-0: CVE-2020-25212: kernel-source: TOCTOU mismatch in the NFS client code</issue>
<issue id="1176382" tracker="bnc">VUL-0: CVE-2020-25212: kernel live patch: TOCTOU mismatch in the NFS client code</issue>
<issue id="1176423" tracker="bnc">VUL-1: CVE-2020-0404: kernel-source: media: uvcvideo: Avoid cyclic entity chains due to malformed USB descriptors</issue>
<issue id="1176482" tracker="bnc">VUL-1: CVE-2020-25284: kernel-source: The rbd block device driver in drivers/block/rbd.c in the Linux kernel through 5.8.9 used incomplete permission checking for access to rbd devices, which could be leveraged by local attackers to map or</issue>
<issue id="1176721" tracker="bnc">VUL-1: CVE-2020-0432: kernel-source: possible out of bounds write in skb_to_mamac of networking.c</issue>
<issue id="1176722" tracker="bnc">VUL-1: CVE-2020-0431: kernel-source: possible out of bounds write in kbd_keycode of keyboard.c</issue>
<issue id="1176725" tracker="bnc">VUL-1: CVE-2020-0427: kernel-source: possible out of bounds read in create_pinctrl of core.c</issue>
<issue id="1176896" tracker="bnc">VUL-1: CVE-2020-0431: kernel live patch: possible out of bounds write in kbd_keycode of keyboard.c</issue>
<issue id="1176990" tracker="bnc">VUL-0: CVE-2020-26088: kernel-source: missing CAP_NET_RAW check in NFC socket creation in net/nfc/rawsock.c allows local attackers to create raw sockets</issue>
<issue id="1177027" tracker="bnc">[HUAWEI - NOT FOR THE USA]When will the CVE of nfs CVE-2020-25212 be release in SLES12 SP2 ref:_00D1igLOd._5001iStttG:ref</issue>
<issue id="1177086" tracker="bnc">VUL-1: CVE-2020-14351: kernel-source: race in perf_mmap_close function</issue>
<issue id="1177165" tracker="bnc">VUL-1: CVE-2020-0432: kernel live patch: possible out of bounds write in skb_to_mamac of networking.c</issue>
<issue id="1177206" tracker="bnc">VUL-0: CVE-2020-25643: kernel-source: improper input validation in ppp_cp_parse_cr function leads to memory corruption and read overflow</issue>
<issue id="1177226" tracker="bnc">VUL-0: CVE-2020-25643: kernel live patch: improper input validation in ppp_cp_parse_cr function leads to memory corruption and read overflow</issue>
<issue id="1177410" tracker="bnc">VUL-0: CVE-2020-27675: kernel-source: Race condition in Linux event handler may crash dom0 (XSA-331 v2)</issue>
<issue id="1177411" tracker="bnc">VUL-0: CVE-2020-27673: kernel-source: Rogue guests can cause DoS of Dom0 via high frequency events (XSA-332 v2)</issue>
<issue id="1177511" tracker="bnc">VUL-0: CVE-2020-25645: kernel-source: Geneve/IPsec traffic may be unencrypted between two Geneve endpoints</issue>
<issue id="1177513" tracker="bnc">VUL-0: CVE-2020-25645: kernel live patch: Geneve/IPsec traffic may be unencrypted between two Geneve endpoints</issue>
<issue id="1177725" tracker="bnc">VUL-0: CVE-2020-12352: kernel-source: net: bluetooth: information leak when processing certain AMP packets aka "BleedingTooth" aka "BadChoice"</issue>
<issue id="1177766" tracker="bnc">VUL-1: CVE-2020-25656: kernel-source: concurrency use-after-free in vt_do_kdgkb_ioctl</issue>
<issue id="1131277" tracker="bnc">L3: System panic in btrfs_async_reclaim_metadata_space()->can_overcommit()</issue>
<issue id="1175721" tracker="bnc">VUL-0: CVE-2020-25705: kernel-source: New vulnerabilities in ICMP rate limiting (paper: DNS Cache Poisoning Attack Reloaded: Revolutions with SideChannels)</issue>
<issue id="1176922" tracker="bnc">L3: System hang due to a massive amount of soft lockups in btrfs_drop_and_free_fs_root()</issue>
<issue id="1178782" tracker="bnc">VUL-0: CVE-2020-25705: SADDNS attack</issue>
<issue id="2020-25705" tracker="cve" />
<issue id="2020-25656" tracker="cve" />
<issue id="2017-18204" tracker="cve" />
<issue id="2020-14351" tracker="cve" />
<issue id="2020-8694" tracker="cve" />
<issue id="2020-12352" tracker="cve" />
<issue id="2020-25645" tracker="cve" />
<issue id="2020-14381" tracker="cve" />
<issue id="2020-25212" tracker="cve" />
<issue id="2020-14390" tracker="cve" />
<issue id="2020-25643" tracker="cve" />
<issue id="2020-26088" tracker="cve" />
<issue id="2020-0432" tracker="cve" />
<issue id="2020-0431" tracker="cve" />
<issue id="2020-0427" tracker="cve" />
<issue id="2020-0404" tracker="cve" />
<issue id="2020-25284" tracker="cve" />
<category>security</category>
<rating>important</rating>
<packager>osalvador</packager>
<reboot_needed/>
<description>
The SUSE Linux Enterprise 12 SP2 kernel was updated to receive various security and bug fixes.
The following security bugs were fixed:
- CVE-2020-25705: A flaw in the way reply ICMP packets are limited in was found that allowed to quickly scan open UDP ports. This flaw allowed an off-path remote user to effectively bypassing source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software and services that rely on UDP source port randomization (like DNS) are indirectly affected as well. Kernel versions may be vulnerable to this issue (bsc#1175721, bsc#1178782).
- CVE-2020-25656: Fixed a concurrency use-after-free in vt_do_kdgkb_ioctl (bnc#1177766).
- CVE-2017-18204: Fixed a denial of service in the ocfs2_setattr function of fs/ocfs2/file.c (bnc#1083244).
- CVE-2020-14351: Fixed a race in the perf_mmap_close() function (bsc#1177086).
- CVE-2020-8694: Restricted energy meter to root access (bsc#1170415).
- CVE-2020-12352: Fixed an information leak when processing certain AMP packets aka "BleedingTooth" (bsc#1177725).
- CVE-2020-25645: Fixed an an issue in IPsec that caused traffic between two Geneve endpoints to be unencrypted (bnc#1177511).
- CVE-2020-14381: Fixed a use-after-free in the fast user mutex (futex) wait operation, which could have lead to memory corruption and possibly privilege escalation (bsc#1176011).
- CVE-2020-25212: Fixed A TOCTOU mismatch in the NFS client code which could have been used by local attackers to corrupt memory (bsc#1176381).
- CVE-2020-14390: Fixed an out-of-bounds memory write leading to memory corruption or a denial of service when changing screen size (bnc#1176235).
- CVE-2020-25643: Fixed a memory corruption and a read overflow which could have caused by improper input validation in the ppp_cp_parse_cr function (bsc#1177206).
- CVE-2020-26088: Fixed an improper CAP_NET_RAW check in NFC socket creation could have been used by local attackers to create raw sockets, bypassing security mechanisms (bsc#1176990).
- CVE-2020-0432: Fixed an out of bounds write due to an integer overflow (bsc#1176721).
- CVE-2020-0431: Fixed an out of bounds write due to a missing bounds check (bsc#1176722).
- CVE-2020-0427: Fixed an out of bounds read due to a use after free (bsc#1176725).
- CVE-2020-0404: Fixed a linked list corruption due to an unusual root cause (bsc#1176423).
- CVE-2020-25284: Fixed an incomplete permission checking for access to rbd devices, which could have been leveraged by local attackers to map or unmap rbd block devices (bsc#1176482).
The following non-security bugs were fixed:
- btrfs: fix race with relocation recovery and fs_root setup (bsc#1131277).
- btrfs: flush_space always takes fs_info->fs_root (bsc#1131277).
- btrfs: btrfs_init_new_device should use fs_info->dev_root (bsc#1131277, bsc#1176922).
- btrfs: btrfs_test_opt and friends should take a btrfs_fs_info (bsc#1131277, bsc#1176922).
- btrfs: call functions that always use the same root with fs_info instead (bsc#1131277, bsc#1176922).
- btrfs: call functions that overwrite their root parameter with fs_info (bsc#1131277, bsc#1176922).
- btrfs: flush_space always takes fs_info->fs_root (bsc#1131277, bsc#1176922).
- btrfs: pull node/sector/stripe sizes out of root and into fs_info (bsc#1131277, bsc#1176922).
- btrfs: Remove fs_info argument of btrfs_write_and_wait_transaction (bsc#1131277, bsc#1176922).
- btrfs: remove root parameter from transaction commit/end routines (bsc#1131277, bsc#1176922).
- btrfs: remove root usage from can_overcommit (bsc#1131277, bsc#1176922).
- btrfs: root->fs_info cleanup, access fs_info->delayed_root directly (bsc#1131277, bsc#1176922).
- btrfs: root->fs_info cleanup, add fs_info convenience variables (bsc#1131277, bsc#1176922).
- btrfs: root->fs_info cleanup, btrfs_calc_{trans,trunc}_metadata_size (bsc#1131277, bsc#1176922).
- btrfs: root->fs_info cleanup, update_block_group{,flags} (bsc#1131277, bsc#1176922).
- btrfs: root->fs_info cleanup, use fs_info->dev_root everywhere (bsc#1131277, bsc#1176922).
- btrfs: split btrfs_wait_marked_extents into normal and tree log functions (bsc#1131277, bsc#1176922).
- btrfs: struct btrfsic_state->root should be an fs_info (bsc#1131277, bsc#1176922).
- btrfs: take an fs_info directly when the root is not used otherwise (bsc#1131277, bsc#1176922).
- xen/blkback: use lateeoi irq binding (XSA-332 bsc#1177411).
- xen: do not reschedule in preemption off sections (bsc#1175749).
- xen/events: add a new "late EOI" evtchn framework (XSA-332 bsc#1177411).
- xen/events: add a proper barrier to 2-level uevent unmasking (XSA-332 bsc#1177411).
- xen/events: avoid removing an event channel while handling it (XSA-331 bsc#1177410).
- xen/events: block rogue events for some time (XSA-332 bsc#1177411).
- xen/events: defer eoi in case of excessive number of events (XSA-332 bsc#1177411).
- xen/events: do not use chip_data for legacy IRQs (XSA-332 bsc#1065600).
- xen/events: fix race in evtchn_fifo_unmask() (XSA-332 bsc#1177411).
- xen/events: switch user event channels to lateeoi model (XSA-332 bsc#1177411).
- xen/events: use a common cpu hotplug hook for event channels (XSA-332 bsc#1177411).
- xen/netback: use lateeoi irq binding (XSA-332 bsc#1177411).
- xen/pciback: use lateeoi irq binding (XSA-332 bsc#1177411).
- xen/scsiback: use lateeoi irq binding (XSA-332 bsc#1177411).
- XEN uses irqdesc::irq_data_common::handler_data to store a per interrupt XEN data pointer which contains XEN specific information (XSA-332 bsc#1065600).
</description>
<summary>Security update for the Linux Kernel</summary>
</patchinfo>