An update that solves 5 vulnerabilities and has one errata is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP1) ______________________________________________________________________________ Announcement ID: SUSE-SU-2021:0853-1 Rating: important References: #1178684 #1179616 #1179664 #1180859 #1181553 #1182468 Cross-References: CVE-2020-27786 CVE-2020-28374 CVE-2020-29368 CVE-2021-0342 CVE-2021-3347 CVSS scores: CVE-2020-27786 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2020-27786 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2020-28374 (NVD) : 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVE-2020-28374 (SUSE): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N CVE-2020-29368 (NVD) : 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2020-29368 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-0342 (NVD) : 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H CVE-2021-0342 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-3347 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2021-3347 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise Module for Live Patching 15-SP1 ______________________________________________________________________________ An update that solves 5 vulnerabilities and has one errata is now available. Description: This update for the Linux Kernel 4.12.14-197_72 fixes several issues. The following security issues were fixed: - CVE-2020-29368: Fixed an issue in copy-on-write implementation which could have granted unintended write access because of a race condition in a THP mapcount check (bsc#1179664). -Fixed an issue where NFS client filesystems got unmounted on fail-over (bsc#1182468). - CVE-2021-3347: Fixed a use-after-free in the PI futexes during fault handling, allowing local users to execute code in the kernel (bsc#1181553). - CVE-2020-27786: Fixed a potential user after free which could have led to memory corruption or privilege escalation (bsc#1179616). - CVE-2020-28374: Fixed insufficient identifier checking in the LIO SCSI target code which could have been used by remote attackers to read or write files via directory traversal in an XCOPY request (bsc#1178684). - CVE-2021-0342: Fixed a potential memory corruption due to a use after free which could have led to local escalation of privilege with System execution privileges required (bsc#1180859). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Live Patching 15-SP1: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP1-2021-853=1 SUSE-SLE-Module-Live-Patching-15-SP1-2021-854=1 SUSE-SLE-Module-Live-Patching-15-SP1-2021-855=1 SUSE-SLE-Module-Live-Patching-15-SP1-2021-861=1 SUSE-SLE-Module-Live-Patching-15-SP1-2021-862=1 SUSE-SLE-Module-Live-Patching-15-SP1-2021-863=1 Package List: - SUSE Linux Enterprise Module for Live Patching 15-SP1 (ppc64le x86_64): kernel-livepatch-4_12_14-197_34-default-10-2.2 kernel-livepatch-4_12_14-197_37-default-10-2.2 kernel-livepatch-4_12_14-197_40-default-9-2.2 kernel-livepatch-4_12_14-197_64-default-4-2.2 kernel-livepatch-4_12_14-197_67-default-4-2.2 kernel-livepatch-4_12_14-197_72-default-3-2.2 References: https://www.suse.com/security/cve/CVE-2020-27786.html https://www.suse.com/security/cve/CVE-2020-28374.html https://www.suse.com/security/cve/CVE-2020-29368.html https://www.suse.com/security/cve/CVE-2021-0342.html https://www.suse.com/security/cve/CVE-2021-3347.html https://bugzilla.suse.com/1178684 https://bugzilla.suse.com/1179616 https://bugzilla.suse.com/1179664 https://bugzilla.suse.com/1180859 https://bugzilla.suse.com/1181553 https://bugzilla.suse.com/1182468 . DEBIAN Security Bulletin resolves urgent issues in the Linux Kernel, providing guidelines for applying Update 21.. Linux Kernel Security,SUSE Update Instructions,Live Patching Guide. . Severity: Important. LinuxSecurity.com Team
Not using pivot_root(2) leaves the host /proc around in the mount namespace so that it is possible to mount another /proc without any other submount, even if /proc in the container is not fully visible. This flaw allows an attacker to read and modify some parts of the Linux kernel memory (rhbz#1663068). . MGASA-2019-0068 - Updated opencontainers-runc packages fix security vulnerability Publication date: 13 Feb 2019 URL: https://advisories.mageia.org/MGASA-2019-0068.html Type: security Affected Mageia releases: 6 CVE: CVE-2019-5736 Not using pivot_root(2) leaves the host /proc around in the mount namespace so that it is possible to mount another /proc without any other submount, even if /proc in the container is not fully visible. This flaw allows an attacker to read and modify some parts of the Linux kernel memory (rhbz#1663068). runc through 1.0-rc6 allows attackers to overwrite the host runc binary (and consequently obtain host root access) by leveraging the ability to execute a command as root within one of these types of containers: a new container with an attacker-controlled image, or an existing container, to which the attacker previously had write access, that can be attached with docker exec. This occurs because of file-descriptor mishandling, related to /proc/self/exe (CVE-2019-5736). References: - https://bugs.mageia.org/show_bug.cgi?id=24253 - https://lists.fedoraproject.org/archives/list/
Get the latest Linux and open source security news straight to your inbox.