Linux Security
Linux Security
Linux Security

Mageia 2021-0117: kernel security update

Date 07 Mar 2021
197
Posted By LinuxSecurity Advisories
This kernel update is based on upstream 5.10.20 and fixes atleast the following security issues: An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of
MGASA-2021-0117 - Updated kernel packages fix security issues and possible filesystem corruption

Publication date: 07 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0117.html
Type: security
Affected Mageia releases: 7, 8
CVE: CVE-2021-28038,
     CVE-2021-28039

This kernel update is based on upstream 5.10.20 and fixes atleast the
following security issues:

An issue was discovered in the Linux kernel through 5.11.3, as used with
Xen PV. A certain part of the netback driver lacks necessary treatment of
errors such as failed memory allocations (as a result of changes to the
handling of grant mapping errors). A host OS denial of service may occur
during misbehavior of a networking frontend driver. NOTE: this issue
exists because of an incomplete fix for CVE-2021-26931.
(CVE-2021-28038 / XSA-367)

An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used
with Xen. In some less-common configurations, an x86 PV guest OS user can
crash a Dom0 or driver domain via a large amount of I/O activity. The
issue relates to misuse of guest physical addresses when a configuration
has CONFIG_XEN_UNPOPULATED_ALLOC but not CONFIG_XEN_BALLOON_MEMORY_HOTPLUG.
(CVE-2021-28039 / XSA-369)

It also adds a critical fix for filesystem level corruption:
- on setups with swapfiles on filesystems sitting on top of brd, zram,
  btt or pmem, then when the system starts to swap out pages, at which
  point it corrupts filesystem blocks that don't belong to the swapfile.

It also adds the following fixes:
- Input: elan_i2c - add new trackpoint report type 0x5F
- Input: elantech - fix protocol errors for some trackpoints
- net: usb: qmi_wwan: support ZTE P685M modem
- tty: fix up iterate_tty_read() EOVERFLOW handling
- tty: fix up hung_up_tty_read() conversion
- tty: clean up legacy leftovers from n_tty line discipline
- tty: teach n_tty line discipline about the new "cookie continuations"
- tty: teach the n_tty ICANON case about the new "cookie continuations" too
- x86_64-server config:
  * enable NUMA balancing
  * make CONNECTOR builtin to enable PROC_EVENTS (mga#28312)
  * support 512 cores/threads

For other upstream fixes, see the referenced changelogs.

References:
- https://bugs.mageia.org/show_bug.cgi?id=28541
- https://bugs.mageia.org/show_bug.cgi?id=28312
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.20
- https://xenbits.xen.org/xsa/advisory-367.html
- https://xenbits.xen.org/xsa/advisory-369.html
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28038
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28039

SRPMS:
- 8/core/kernel-5.10.20-2.mga8
- 8/core/kmod-virtualbox-6.1.18-18.mga8
- 8/core/kmod-xtables-addons-3.13-34.mga8
- 7/core/kernel-5.10.20-2.mga7
- 7/core/kmod-virtualbox-6.1.18-8.mga7
- 7/core/kmod-xtables-addons-3.13-14.mga7

LinuxSecurity Poll

How frequently do you patch/update your system?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum 0 answer(s) and maximum 3 answer(s).
/main-polls/52-how-frequently-do-you-patch-update-your-system?task=poll.vote&format=json
52
radio
[{"id":"179","title":"As soon as patches\/updates are released - I track advisories for my distro(s) diligently","votes":"69","type":"x","order":"1","pct":75.82,"resources":[]},{"id":"180","title":"Every so often, when I think of it","votes":"14","type":"x","order":"2","pct":15.38,"resources":[]},{"id":"181","title":"Hardly ever","votes":"8","type":"x","order":"3","pct":8.79,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350

Please vote first in order to view vote results.

VOTE ON THE POLL PAGE


VIEW MORE POLLS

bottom 200

Please enable / Bitte aktiviere JavaScript!
Veuillez activer / Por favor activa el Javascript![ ? ]

We use cookies to provide and improve our services. By using our site, you consent to our Cookie Policy.