An update that fixes two vulnerabilities is now available. . SUSE Security Update: Security update for the Linux Kernel (Live Patch 26 for SLE 15 SP2) ______________________________________________________________________________ Announcement ID: SUSE-SU-2022:2779-1 Rating: important References: #1200605 #1201080 Cross-References: CVE-2022-1679 CVE-2022-20141 CVSS scores: CVE-2022-1679 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-1679 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-20141 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVE-2022-20141 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H Affected Products: SUSE Linux Enterprise High Performance Computing 15-SP2 SUSE Linux Enterprise Module for Live Patching 15-SP2 SUSE Linux Enterprise Server 15-SP2 SUSE Linux Enterprise Server for SAP Applications 15-SP2 ______________________________________________________________________________ An update that fixes two vulnerabilities is now available. Description: This update for the Linux Kernel 5.3.18-150200_24_112 fixes several issues. The following security issues were fixed: - CVE-2022-1679: Fixed a use-after-free in the Atheros wireless driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages (bsc#1199487). - CVE-2022-20141: Fixed a possible use after free due to improper locking in ip_check_mc_rcu() (bsc#1200604). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Live Patching 15-SP2: zypper in -t patch SUSE-SLE-Module-Live-Patching-15-SP2-2022-2779=1 Package List: - SUSE Linux Enterprise Module for Live Patching 15-SP2 (ppc64le s390x x86_64): kernel-livepatch-5_3_18-150200_24_112-default-6-150200.2.2 kernel-livepatch-5_3_18-150200_24_112-default-debuginfo-6-150200.2.2 kernel-livepatch-SLE15-SP2_Update_26-debugsource-6-150200.2.2 References: https://www.suse.com/security/cve/CVE-2022-1679.html https://www.suse.com/security/cve/CVE-2022-20141.html https://bugzilla.suse.com/1200605 https://bugzilla.suse.com/1201080 . Canonical has released a security patch dealing with two vulnerabilities in the Linux Kernel Live Patch 24 for Ubuntu 20.04 LTS. Ensure your systems are current!. SUSE Linux Security, Kernel Patch Update, Live Patching Solutions. . Severity: Important. LinuxSecurity.com Team
An update for kpatch-patch is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score,. -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 ==================================================================== Red Hat Security Advisory Synopsis: Important: kpatch-patch security update Advisory ID: RHSA-2021:0940-01 Product: Red Hat Enterprise Linux Advisory URL: https://access.redhat.com/errata/RHSA-2021:0940 Issue date: 2021-03-18 CVE Names: CVE-2020-29661 ==================================================================== 1. Summary: An update for kpatch-patch is now available for Red Hat Enterprise Linux 7.6 Extended Update Support. Red Hat Product Security has rated this update as having a security impact of Important. A Common Vulnerability Scoring System (CVSS) base score, which gives a detailed severity rating, is available for each vulnerability from the CVE link(s) in the References section. 2. Relevant releases/architectures: Red Hat Enterprise Linux Server EUS (v. 7.6) - ppc64le, x86_64 3. Description: This is a kernel live patch module which is automatically loaded by the RPM post-install script to modify the code of a running kernel. Security Fix(es): * kernel: locking issue in drivers/tty/tty_jobctrl.c can lead to an use-after-free (CVE-2020-29661) For more details about the security issue(s), including the impact, a CVSS score, acknowledgments, and other related information, refer to the CVE page(s) listed in the References section. 4. Solution: For details on how to apply this update, which includes the changes described in this advisory, refer to: https://access.redhat.com/articles/11258 5. Bugs fixed (https://bugzilla.redhat.com/): 1906525 - CVE-2020-29661 kernel: locking issue in drivers/tty/tty_jobctrl.c can lead to an use-after-free 6. Package List: RedHat Enterprise Linux Server EUS (v.7.6): Source: kpatch-patch-3_10_0-957_46_1-1-4.el7.src.rpm kpatch-patch-3_10_0-957_48_1-1-4.el7.src.rpm kpatch-patch-3_10_0-957_54_1-1-1.el7.src.rpm kpatch-patch-3_10_0-957_56_1-1-1.el7.src.rpm kpatch-patch-3_10_0-957_58_2-1-1.el7.src.rpm kpatch-patch-3_10_0-957_61_1-1-1.el7.src.rpm kpatch-patch-3_10_0-957_61_2-1-1.el7.src.rpm kpatch-patch-3_10_0-957_62_1-1-1.el7.src.rpm kpatch-patch-3_10_0-957_65_1-1-1.el7.src.rpm kpatch-patch-3_10_0-957_66_1-1-1.el7.src.rpm ppc64le: kpatch-patch-3_10_0-957_46_1-1-4.el7.ppc64le.rpm kpatch-patch-3_10_0-957_48_1-1-4.el7.ppc64le.rpm kpatch-patch-3_10_0-957_54_1-1-1.el7.ppc64le.rpm kpatch-patch-3_10_0-957_54_1-debuginfo-1-1.el7.ppc64le.rpm kpatch-patch-3_10_0-957_56_1-1-1.el7.ppc64le.rpm kpatch-patch-3_10_0-957_56_1-debuginfo-1-1.el7.ppc64le.rpm kpatch-patch-3_10_0-957_58_2-1-1.el7.ppc64le.rpm kpatch-patch-3_10_0-957_58_2-debuginfo-1-1.el7.ppc64le.rpm kpatch-patch-3_10_0-957_61_1-1-1.el7.ppc64le.rpm kpatch-patch-3_10_0-957_61_1-debuginfo-1-1.el7.ppc64le.rpm kpatch-patch-3_10_0-957_61_2-1-1.el7.ppc64le.rpm kpatch-patch-3_10_0-957_61_2-debuginfo-1-1.el7.ppc64le.rpm kpatch-patch-3_10_0-957_62_1-1-1.el7.ppc64le.rpm kpatch-patch-3_10_0-957_62_1-debuginfo-1-1.el7.ppc64le.rpm kpatch-patch-3_10_0-957_65_1-1-1.el7.ppc64le.rpm kpatch-patch-3_10_0-957_65_1-debuginfo-1-1.el7.ppc64le.rpm kpatch-patch-3_10_0-957_66_1-1-1.el7.ppc64le.rpm kpatch-patch-3_10_0-957_66_1-debuginfo-1-1.el7.ppc64le.rpm x86_64: kpatch-patch-3_10_0-957_46_1-1-4.el7.x86_64.rpm kpatch-patch-3_10_0-957_48_1-1-4.el7.x86_64.rpm kpatch-patch-3_10_0-957_54_1-1-1.el7.x86_64.rpm kpatch-patch-3_10_0-957_54_1-debuginfo-1-1.el7.x86_64.rpm kpatch-patch-3_10_0-957_56_1-1-1.el7.x86_64.rpm kpatch-patch-3_10_0-957_56_1-debuginfo-1-1.el7.x86_64.rpm kpatch-patch-3_10_0-957_58_2-1-1.el7.x86_64.rpm kpatch-patch-3_10_0-957_58_2-debuginfo-1-1.el7.x86_64.rpm kpatch-patch-3_10_0-957_61_1-1-1.el7.x86_64.rpm kpatch-patch-3_10_0-957_61_1-debuginfo-1-1.el7.x86_64.rpm kpatch-patch-3_10_0-957_61_2-1-1.el7.x86_64.rpm kpatch-patch-3_10_0-957_61_2-debuginfo-1-1.el7.x86_64.rpm kpatch-patch-3_10_0-957_62_1-1-1.el7.x86_64.rpm kpatch-patch-3_10_0-957_62_1-debuginfo-1-1.el7.x86_64.rpm kpatch-patch-3_10_0-957_65_1-1-1.el7.x86_64.rpm kpatch-patch-3_10_0-957_65_1-debuginfo-1-1.el7.x86_64.rpm kpatch-patch-3_10_0-957_66_1-1-1.el7.x86_64.rpm kpatch-patch-3_10_0-957_66_1-debuginfo-1-1.el7.x86_64.rpm These packages are GPG signed by Red Hat for security. Our key and details on how to verify the signature are available from https://access.redhat.com/security/team/key/ 7. References: https://access.redhat.com/security/cve/CVE-2020-29661 https://access.redhat.com/security/updates/classification/#important 8. Contact: The Red Hat security contact is . More contact details at https://access.redhat.com/security/team/contact/ Copyright 2021 Red Hat, Inc. -----BEGIN PGP SIGNATURE----- Version: GnuPG v1 iQIVAwUBYFOEUtzjgjWX9erEAQj6XQ//YHyiTcfTsGkQ50//NebSvXYHHix84DOn MbWT8IsjMUrUWcCLcoX+fvw4sIB88xBaaWQgaLnKMfwZsc3kSYOgFZmbxyeKV0kO anZegDXFfddsGFf8WwZNkvZY0M/JQVHs+cCqjVLIzbbIl1go7mxGxPVCdtdSBCEY qQkB6OXbzyx32j8kvTR+ddACUdpGdvNOsQ3yREdWEbWiIT3zfVv5X4BfHyBle6nt TUP1wDU56eX5sSK8Pn3hIqir2tGD8UDGwDXw/9esTTHLh6F0h0wKBs5oZg20DK+N 2ilpNGWR8DSJYaknFYPmHGCbkeQbMIEhodJUGVkc5LgdREMuteBlO+XkntsoRBZj 7X/CPjIy/P2eHLkAdSnUI3qcVEt8vjH7ol8elw7vuQz/hF5yWxcYhLN6xBMdHHhO lMywYJ8JLRYe9NJtfMApSNyAT089x4W0YnghaqDwgOkJSXxxQlcJB5f8/67bIFjs K213aC+kTU0AogjqJ82l/27FTO3HUC3QiusLViH1k+TlcuAM+gVey2F4IoSTu2tm AjZu5FYnWKtNCZhNU4yVG0HHzCDcrRO2CsbM5s/prZucqfFWRGW3+NTttQdeyrZU BjOCSRzW6ykmfr0b42j99RUVJBxMvjyJzgPbr4iNLJJw69RAmuZom+alT8Q+hhtV PXwmQU3W3Ms=Ho9A -----END PGP SIGNATURE----- -- RHSA-announce mailing list
Low: selinux-policy enhancement update. Date: Thu, 22 Dec 2011 11:24:52 -0600 Reply-To: Pat Riehecky Sender: Security Errata for Scientific Linux From: Pat Riehecky Organization: Fermilab Subject: Security ERRATA Low: selinux-policy on SL6.x i386/x86_64 MIME-Version: 1.0 Synopsis: Low: selinux-policy enhancement update Issue date: 2011-12-19 This update fixes the following bug: * When running a KDE session on a virtual machine with SELinux in enforcing mode, the session was not locked as expected when the SPICE console was closed. This update adds necessary SELinux rules which ensure that the user's session is properly locked under these circumstances. SL6.x SRPMS: selinux-policy-3.7.19-126.el6_2.4.src.rpm i386: selinux-policy-3.7.19-126.el6_2.4.noarch.rpm selinux-policy-doc-3.7.19-126.el6_2.4.noarch.rpm selinux-policy-minimum-3.7.19-126.el6_2.4.noarch.rpm selinux-policy-mls-3.7.19-126.el6_2.4.noarch.rpm selinux-policy-targeted-3.7.19-126.el6_2.4.noarch.rpm x86_64: selinux-policy-3.7.19-126.el6_2.4.noarch.rpm selinux-policy-doc-3.7.19-126.el6_2.4.noarch.rpm selinux-policy-minimum-3.7.19-126.el6_2.4.noarch.rpm selinux-policy-mls-3.7.19-126.el6_2.4.noarch.rpm selinux-policy-targeted-3.7.19-126.el6_2.4.noarch.rpm Changelog: * Thu Dec 08 2011 Miroslav Grepl 3.7.19-126.el6_2.4 - Allow rhev_agentd_consolehelper to dbus chat with session bus * Wed Nov 23 2011 Miroslav Grepl 3.7.19-126.el6_2.3 - Update config.tgz to make cronjob working also for user_t * Wed Nov 16 2011 Miroslav Grepl 3.7.19-126.el6_2.2 - Add cron_role for sysadm_t * Wed Nov 16 2011 Miroslav Grepl 3.7.19-126.el6_2.1 - Make cronjob working on MLS * Wed Nov 09 2011 Miroslav Grepl 3.7.19-126 - Fix dev_rw_generic_usb_dev . The latest update of selinux-policy in Scientific Linux resolves session locking issues faced with SELinux enforcement, enhancing user experience while maintaining security. selinux-policy, update, security fix, enhancement, Scientific Linux. . Severity: Important.LinuxSecurity.com Team
Get the latest Linux and open source security news straight to your inbox.