This kernel update is based on upstream 5.10.20 and fixes atleast the following security issues: An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of . MGASA-2021-0117 - Updated kernel packages fix security issues and possible filesystem corruption Publication date: 07 Mar 2021 URL: https://advisories.mageia.org/MGASA-2021-0117.html Type: security Affected Mageia releases: 7, 8 CVE: CVE-2021-28038, CVE-2021-28039 This kernel update is based on upstream 5.10.20 and fixes atleast the following security issues: An issue was discovered in the Linux kernel through 5.11.3, as used with Xen PV. A certain part of the netback driver lacks necessary treatment of errors such as failed memory allocations (as a result of changes to the handling of grant mapping errors). A host OS denial of service may occur during misbehavior of a networking frontend driver. NOTE: this issue exists because of an incomplete fix for CVE-2021-26931. (CVE-2021-28038 / XSA-367) An issue was discovered in the Linux kernel 5.9.x through 5.11.3, as used with Xen. In some less-common configurations, an x86 PV guest OS user can crash a Dom0 or driver domain via a large amount of I/O activity. The issue relates to misuse of guest physical addresses when a configuration has CONFIG_XEN_UNPOPULATED_ALLOC but not CONFIG_XEN_BALLOON_MEMORY_HOTPLUG. (CVE-2021-28039 / XSA-369) It also adds a critical fix for filesystem level corruption: - on setups with swapfiles on filesystems sitting on top of brd, zram, btt or pmem, then when the system starts to swap out pages, at which point it corrupts filesystem blocks that don't belong to the swapfile. It also adds the following fixes: - Input: elan_i2c - add new trackpoint report type 0x5F - Input: elantech - fix protocol errors for some trackpoints - net: usb: qmi_wwan: support ZTE P685M modem - tty: fix up iterate_tty_read() EOVERFLOW handling - tty: fix up hung_up_tty_read() conversion - tty: clean uplegacy leftovers from n_tty line discipline - tty: teach n_tty line discipline about the new "cookie continuations" - tty: teach the n_tty ICANON case about the new "cookie continuations" too - x86_64-server config: * enable NUMA balancing * make CONNECTOR builtin to enable PROC_EVENTS (mga#28312) * support 512 cores/threads For other upstream fixes, see the referenced changelogs. References: - https://bugs.mageia.org/show_bug.cgi?id=28541 - https://bugs.mageia.org/show_bug.cgi?id=28312 - https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.20 - https://xenbits.xen.org/xsa/advisory-367.html - https://xenbits.xen.org/xsa/advisory-369.html - https://www.cve.org/CVERecord?id=CVE-2021-28038 - https://www.cve.org/CVERecord?id=CVE-2021-28039 SRPMS: - 8/core/kernel-5.10.20-2.mga8 - 8/core/kmod-virtualbox-6.1.18-18.mga8 - 8/core/kmod-xtables-addons-3.13-34.mga8 - 7/core/kernel-5.10.20-2.mga7 - 7/core/kmod-virtualbox-6.1.18-8.mga7 - 7/core/kmod-xtables-addons-3.13-14.mga7 . New kernel updates for Mageia tackle significant security vulnerabilities and potential data corruption threats.. Mageia Kernel Update, Denial of Service Fix, Filesystem Corruption Repair. . LinuxSecurity.com Team
An update that contains security fixes can now be installed. . openSUSE Security Update: Security update for MozillaFirefox ______________________________________________________________________________ Announcement ID: openSUSE-SU-2021:0335-1 Rating: low References: #1181848 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that contains security fixes can now be installed. Description: This update for MozillaFirefox fixes the following issues: Firefox Extended Support Release 78.7.1 ESR (bsc#1181848) - Fixed: Prevent access to NTFS special paths that could lead to filesystem corruption. - Buffer overflow in depth pitch calculations for compressed textures Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2021-335=1 Package List: - openSUSE Leap 15.2 (x86_64): MozillaFirefox-78.7.1-lp152.2.46.1 MozillaFirefox-branding-upstream-78.7.1-lp152.2.46.1 MozillaFirefox-buildsymbols-78.7.1-lp152.2.46.1 MozillaFirefox-debuginfo-78.7.1-lp152.2.46.1 MozillaFirefox-debugsource-78.7.1-lp152.2.46.1 MozillaFirefox-devel-78.7.1-lp152.2.46.1 MozillaFirefox-translations-common-78.7.1-lp152.2.46.1 MozillaFirefox-translations-other-78.7.1-lp152.2.46.1 References: https://bugzilla.suse.com/1181848 . Implement openSUSE Security Patch for MozillaFirefox to address memory overflow and storage related vulnerabilities.. MozillaFirefox Update, openSUSE Security, Buffer Overflow Fix. . Severity: Low. LinuxSecurity.com Team
This stable update contains important fixes across the tree including an important fix for a bug that causes filesystem corruption in some cases.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-5904d0794d 2018-12-11 02:42:14.381803 --------------------------------------------------------------------------------Name : kernel Product : Fedora 29 Version : 4.19.7 Release : 300.fc29 URL : https://www.kernel.org/ Summary : The Linux kernel Description : The kernel meta package --------------------------------------------------------------------------------Update Information: This stable update contains important fixes across the tree including an important fix for a bug that causes filesystem corruption in some cases. --------------------------------------------------------------------------------ChangeLog: * Wed Dec 5 2018 Jeremy Cline - 4.19.7-300 - Linux v4.19.7 * Wed Dec 5 2018 Jeremy Cline - Fix corruption bug in direct dispatch for blk-mq * Tue Dec 4 2018 Justin M. Forbes - Fix CVE-2018-19824 (rhbz 1655816 1655817) * Mon Dec 3 2018 Jeremy Cline - Fix very quiet speakers on the Thinkpad T570 (rhbz 1554304) * Mon Dec 3 2018 Hans de Goede - Fix non functional hotkeys on Asus FX503VD (#1645070) * Sun Dec 2 2018 Jeremy Cline - 4.19.6-300 - Linux v4.19.6 * Thu Nov 29 2018 Jeremy Cline - Fix a problem with some rtl8168 chips (rhbz 1650984) - Fix slowdowns and crashes for AMD GPUs in pre-PCIe-v3 slots * Tue Nov 27 2018 Jeremy Cline - 4.19.5-300 - Linux v4.19.5 - Fix CVE-2018-16862 (rhbz 1649017 1653122) - Fix CVE-2018-19407 (rhbz 1652656 1652658) * Mon Nov 26 2018 Jeremy Cline - Fixes a null pointer dereference with Nvidia and vmwgfx drivers (rhbz 1650224) * Fri Nov 23 2018 Peter Robinson - 4.19.4-300 - Linux v4.19.4 * Thu Nov 22 2018 Peter Robinson - Fixes for Rockchips 3399 devices * Wed Nov 21 2018 Jeremy Cline - 4.19.3-300 - Linuxv4.19.3 * Tue Nov 20 2018 Hans de Goede - Turn on CONFIG_PINCTRL_GEMINILAKE on x86_64 (rhbz#1639155) - Add a patch fixing touchscreens on HP AMD based laptops (rhbz#1644013) - Add a patch fixing KIOX010A accelerometers (rhbz#1526312) * Sat Nov 17 2018 Peter Robinson 4.19.2-301 - Fix WiFi on Raspberry Pi 3 on aarch64 (rhbz 1649344) - Fixes for Raspberry Pi hwmon driver and firmware interface * Fri Nov 16 2018 Hans de Goede - Add patches from 4.20 fixing black screen on CHT devices with i915.fastboot=1 * Thu Nov 15 2018 Hans de Goede - Add patch fixing touchpads on some Apollo Lake devices not working (#1526312) * Wed Nov 14 2018 Jeremy Cline - 4.19.2-300 - Linux v4.19.2 - Fix CVE-2018-18710 (rhbz 1645140 1648485) * Mon Nov 12 2018 Laura Abbott - 4.18.18-300 - Linux v4.18.18 * Mon Nov 5 2018 Laura Abbott - 4.18.17-300 - Linux v4.18.17 * Tue Oct 23 2018 Laura Abbott - Add i915 eDP fixes --------------------------------------------------------------------------------References: [ 1 ] Bug #1655816 - CVE-2018-19824 kernel: Use-after-free in sound/usb/card.c:usb_audio_probe() https://bugzilla.redhat.com/show_bug.cgi?id=1655816 [ 2 ] Bug #1652650 - CVE-2018-19406 kernel: kvm: NULL pointer dereference in kvm_pv_send_ipi in arch/x86/kvm/lapic.c https://bugzilla.redhat.com/show_bug.cgi?id=1652650 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-5904d0794d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list
This stable update contains important fixes across the tree including an important fix for a bug that causes filesystem corruption in some cases.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-5904d0794d 2018-12-11 02:42:14.381803 --------------------------------------------------------------------------------Name : kernel-headers Product : Fedora 29 Version : 4.19.7 Release : 300.fc29 URL : https://www.kernel.org/ Summary : Header files for the Linux kernel for use by glibc Description : Kernel-headers includes the C header files that specify the interface between the Linux kernel and userspace libraries and programs. The header files define structures and constants that are needed for building most standard programs and are also needed for rebuilding the glibc package. --------------------------------------------------------------------------------Update Information: This stable update contains important fixes across the tree including an important fix for a bug that causes filesystem corruption in some cases. --------------------------------------------------------------------------------ChangeLog: * Wed Dec 5 2018 Jeremy Cline - 4.19.7-300 - Linux v4.19.7 * Sun Dec 2 2018 Jeremy Cline - 4.19.6-300 - Linux v4.19.6 * Tue Nov 27 2018 Jeremy Cline - 4.19.5-300 - Linux v4.19.5 * Wed Nov 21 2018 Jeremy Cline - 4.19.5-300 - Linux v4.19.3 * Wed Nov 14 2018 Jeremy Cline - 4.19.2-300 - Linux v4.19.2 * Mon Nov 12 2018 Laura Abbott - 4.18.18-300 - Linux v4.18.18 * Mon Nov 5 2018 Laura Abbott - 4.18.17-300 - Linux v4.18.17 --------------------------------------------------------------------------------References: [ 1 ] Bug #1655816 - CVE-2018-19824 kernel: Use-after-free in sound/usb/card.c:usb_audio_probe() https://bugzilla.redhat.com/show_bug.cgi?id=1655816 [ 2 ] Bug #1652650 - CVE-2018-19406 kernel: kvm: NULL pointer dereference inkvm_pv_send_ipi in arch/x86/kvm/lapic.c https://bugzilla.redhat.com/show_bug.cgi?id=1652650 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-5904d0794d' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the Fedora Project can be found at --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
This stable update contains important fixes across the tree including an important fix for a bug that causes filesystem corruption in some cases.. --------------------------------------------------------------------------------Fedora Update Notification FEDORA-2018-a0914af224 2018-12-11 01:56:16.221050 --------------------------------------------------------------------------------Name : kernel-headers Product : Fedora 28 Version : 4.19.7 Release : 200.fc28 URL : https://www.kernel.org/ Summary : Header files for the Linux kernel for use by glibc Description : Kernel-headers includes the C header files that specify the interface between the Linux kernel and userspace libraries and programs. The header files define structures and constants that are needed for building most standard programs and are also needed for rebuilding the glibc package. --------------------------------------------------------------------------------Update Information: This stable update contains important fixes across the tree including an important fix for a bug that causes filesystem corruption in some cases. --------------------------------------------------------------------------------References: [ 1 ] Bug #1655816 - CVE-2018-19824 kernel: Use-after-free in sound/usb/card.c:usb_audio_probe() https://bugzilla.redhat.com/show_bug.cgi?id=1655816 [ 2 ] Bug #1652650 - CVE-2018-19406 kernel: kvm: NULL pointer dereference in kvm_pv_send_ipi in arch/x86/kvm/lapic.c https://bugzilla.redhat.com/show_bug.cgi?id=1652650 --------------------------------------------------------------------------------This update can be installed with the "dnf" update program. Use su -c 'dnf upgrade --advisory FEDORA-2018-a0914af224' at the command line. For more information, refer to the dnf documentation available at https://dnf.readthedocs.io/en/latest/command_ref.html All packages are signed with the Fedora Project GPG key. More details on the GPG keys used by the FedoraProject can be found at https://fedoraproject.org/security/ --------------------------------------------------------------------------------_______________________________________________ package-announce mailing list --
Get the latest Linux and open source security news straight to your inbox.