Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

Mageia: 2021-0151 Critical Kernel Update For Memory Exposure Threats

mageia
Calendar Grey March 22, 2021
Dist Mageia Esm H88
System patch enhances security flaws across various Mageia versions. Mitigating risks of vulnerabilities and unauthorized access.
This kernel update is based on upstream 5.10.25 and fixes atleast the following security issues: Unprivileged BPF programs running on affected systems can bypass the protection an...

Summary

This kernel update is based on upstream 5.10.25 and fixes atleast the following security issues:
Unprivileged BPF programs running on affected systems can bypass the protection and execute speculatively out-of-bounds loads from any location within the kernel memory. This can be abused to extract contents of kernel memory via side-channel (CVE-2020-27170).
Unprivileged BPF programs running on affected 64-bit systems can exploit this to execute speculatively out-of-bounds loads from 4GB window within the kernel memory. This can be abused to extract contents of kernel memory via side-channel (CVE-2020-27171).
An issue was discovered in the Linux kernel through 5.11.3. A kernel pointer leak can be used to determine the address of the iscsi_transport structure. When an iSCSI transport is registered with the iSCSI subsystem, the transport's handle is available to unprivileged users via the sysfs file system, at /sys/class/iscsi_transport/$TRANSPORT_NAME/handle. When read, the show_transpo...

Read the Full Advisory

References

- https://bugs.mageia.org/show_bug.cgi?id=28610

- https://bugs.mageia.org/show_bug.cgi?id=28596

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.21

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.22

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.23

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.24

- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.25

- https://www.cve.org/CVERecord?id=CVE-2020-27170

- https://www.cve.org/CVERecord?id=CVE-2020-27171

- https://www.cve.org/CVERecord?id=CVE-2021-27363

- https://www.cve.org/CVERecord?id=CVE-2021-27364

- https://www.cve.org/CVERecord?id=CVE-2021-27365

- https://www.cve.org/CVERecord?id=CVE-2021-28375

Resolution

SRPMS

- 7/core/kernel-5.10.25-1.mga7

- 7/core/kmod-virtualbox-6.1.18-11.mga7

- 7/core/kmod-xtables-addons-3.13-17.mga7

- 7/core/wireguard-tools-1.0.20210315-1.mga7

- 8/core/kernel-5.10.25-1.mga8

- 8/core/kmod-virtualbox-6.1.18-21.mga8

- 8/core/kmod-xtables-addons-3.13-37.mga8

- 8/core/wireguard-tools-1.0.20210315-1.mga8

Severity
critical
Lowest
Low
Medium
High
Critical

Publication date: 22 Mar 2021
URL: https://advisories.mageia.org/MGASA-2021-0151.html
Type: security
CVE: CVE-2020-27170, CVE-2020-27171, CVE-2021-27363, CVE-2021-27364, CVE-2021-27365, CVE-2021-28375

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here