Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

Fedora 33: 2021-4a91649cf3 Medium: tcmu-runner Access Control Fix

fedora
Calendar Grey February 2, 2021
Dist Fedora Esm H88
In reference to CVE-2020-28375, this patch enhances tcmu-runner's verification process for device accessibility concerning WRITE requests.
Fixes CVE-2020-28374 See tcmu-runner commit 2b16e96e6b63d0419d857f53e4cc67f0adb383fd tcmu-runner can't determine whether the device(s) referred to in XCOPY Copy Source/Copy Destina...

Summary

A daemon that handles the complexity of the LIO kernel target's userspace

passthrough interface (TCMU). It presents a C plugin API for extension modules

that handle SCSI requests in ways not possible or suitable to be handled

by LIO's in-kernel backstores.

Fixes CVE-2020-28374 See tcmu-runner commit

2b16e96e6b63d0419d857f53e4cc67f0adb383fd tcmu-runner can't determine whether

the device(s) referred to in XCOPY Copy Source/Copy Destination (CSCD)

descriptors should be accessible to the initiator via transport settings, ACLs,

etc. Consequently, fail XCOPY requests with CSCD descriptors which refer to any

device other than where the XCOPY request is processed.

* Mon Jan 25 2021 Maurizio Lombardi - 1.5.2-7

- Fixes CVE-2020-28374

su -c 'dnf upgrade --advisory FEDORA-2021-4a91649cf3' at the command

line. For more information, refer to the dnf documentation available at

https://dnf.readthedocs.io/en/latest/command_ref.html

All packages are signed with the Fedora Project GPG key. More details on the

GPG keys used by the Fedora Project can be found at

https://fedoraproject.org/security/

package-announce mailing list -- package-announce@lists.fedoraproject.org

To unsubscribe send an email to package-announce-leave@lists.fedoraproject.org

Fedora Code of Conduct: https://docs.fedoraproject.org/en-US/project/code-of-conduct/

List Guidelines: https://fedoraproject.org/wiki/Mailing_list_guidelines

List Archives: https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/

Change Log

References

Update Instructions

Severity
medium
Lowest
Low
Medium
High
Critical

Product: Fedora 33
Version: 1.5.2
Release: 7.fc33
Summary: A daemon that supports LIO userspace backends

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here