KernelCare update was released

6 views
Skip to first unread message

KernelCare

unread,
Jan 20, 2020, 8:57:03 AM1/20/20
to kernelca...@googlegroups.com
Dear Customers,

KernelCare prepared security updates for your system.
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.
You can manually update the server by running:

/usr/bin/kcarectl --update

Changelog:

precise:
CVE-2017-5715: Systems with microprocessors utilizing speculative execution and
indirect branch prediction may allow unauthorized disclosure of information to
an attacker with local user access via a side-channel analysis.
CVE-2018-12126: 'Microarchitectural Store Buffer Data Sampling (MSBDS): Store buffers
on some microprocessors utilizing speculative execution may allow an authenticated
user to potentially enable information disclosure via a side channel with local
access.'
CVE-2018-12127: 'Microarchitectural Load Port Data Sampling (MLPDS): Load ports
on some microprocessors utilizing speculative execution may allow an authenticated
user to potentially enable information disclosure via a side channel with local
access.'
CVE-2018-12130: 'Microarchitectural Fill Buffer Data Sampling (MFBDS): Fill buffers
on some microprocessors utilizing speculative execution may allow an authenticated
user to potentially enable information disclosure via a side channel with local
access.'
CVE-2018-12207: Improper invalidation for page table updates by a virtual guest
operating system for multiple Intel(R) Processors may allow an authenticated user
to potentially enable denial of service of the host system via local access.
CVE-2018-3620: Systems with microprocessors utilizing speculative execution and
address translations may allow unauthorized disclosure of information residing
in the L1 data cache to an attacker with local user access via a terminal page
fault and a side-channel analysis.
CVE-2018-3646: Systems with microprocessors utilizing speculative execution and
address translations may allow unauthorized disclosure of information residing
in the L1 data cache to an attacker with local user access with guest OS privilege
via a terminal page fault and a side-channel analysis.
CVE-2019-11091: 'Microarchitectural Data Sampling Uncacheable Memory (MDSUM): Uncacheable
memory on some microprocessors utilizing speculative execution may allow an authenticated
user to potentially enable information disclosure via a side channel with local
access.'
cvelist: [CVE-2017-5715, CVE-2018-12126, CVE-2018-12127, CVE-2018-12130, CVE-2019-11091,
CVE-2018-3620, CVE-2018-3646, CVE-2018-12207]
latest-version: 3.2.0-144.191

KernelCare

unread,
Jan 28, 2020, 10:32:06 AM1/28/20
to kernelca...@googlegroups.com
Dear Customers,

KernelCare prepared security updates for your system.
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.
You can manually update the server by running:

/usr/bin/kcarectl --update

Changelog:

ubuntu-xenial-aws:
CVE-2016-10905: An issue was discovered in fs/gfs2/rgrp.c in the Linux kernel before
4.8. A use-after-free is caused by the functions gfs2_clear_rgrpd and read_rindex_entry.
CVE-2017-18509: An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel
before 4.11. By setting a specific socket option, an attacker can control a pointer
in kernel land and cause an inet_csk_listen_stop general protection fault, or
potentially execute arbitrary code under certain circumstances. The issue can
be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN
capability) or after namespace unsharing. This occurs because sk_type and protocol
are not checked in the appropriate part of the ip6_mroute_* functions.
CVE-2018-20961: In the Linux kernel before 4.16.4, a double free vulnerability in
the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi
driver may allow attackers to cause a denial of service or possibly have unspecified
other impact.
CVE-2019-0136: Insufficient access control in the Intel(R) PROSet/Wireless WiFi
Software driver before version 21.10 may allow an unauthenticated user to potentially
enable denial of service via adjacent access.
CVE-2019-10207: A flaw was found in the Linux kernel's Bluetooth implementation
of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker
with local access and write permissions to the Bluetooth hardware could use this
flaw to issue a specially crafted ioctl function call and cause the system to
crash.
CVE-2019-11487: The Linux kernel before 5.1-rc5 allows page->_refcount reference
count overflow, with resultant use-after-free issues, if about 140 GiB of RAM
exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h,
include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It
can occur with FUSE requests.
CVE-2019-13631: In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in
the Linux kernel through 5.2.1, a malicious USB device can send an HID report
that triggers an out-of-bounds write during generation of debugging messages.
CVE-2019-15211: There is a use-after-free caused by a malicious USB device in the
drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c
does not properly allocate memory.
CVE-2019-15215: There is a use-after-free caused by a malicious USB device in the
drivers/media/usb/cpia2/cpia2_usb.c driver.
CVE-2019-15926: Out of bounds access exists in the functions ath6kl_wmi_pstream_timeout_event_rx
and ath6kl_wmi_cac_event_rx in the file drivers/net/wireless/ath/ath6kl/wmi.c.
cvelist: [CVE-2016-10905, CVE-2017-18509, CVE-2018-20961, CVE-2019-0136, CVE-2019-10207,
CVE-2019-11487, CVE-2019-13631, CVE-2019-15211, CVE-2019-15215, CVE-2019-15926]
latest-version: kernel-4.4.0-1100.111
ubuntu-trusty-lts-xenial:
CVE-2016-10905: An issue was discovered in fs/gfs2/rgrp.c in the Linux kernel before
4.8. A use-after-free is caused by the functions gfs2_clear_rgrpd and read_rindex_entry.
CVE-2017-18509: An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel
before 4.11. By setting a specific socket option, an attacker can control a pointer
in kernel land and cause an inet_csk_listen_stop general protection fault, or
potentially execute arbitrary code under certain circumstances. The issue can
be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN
capability) or after namespace unsharing. This occurs because sk_type and protocol
are not checked in the appropriate part of the ip6_mroute_* functions.
CVE-2018-20961: In the Linux kernel before 4.16.4, a double free vulnerability in
the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi
driver may allow attackers to cause a denial of service or possibly have unspecified
other impact.
CVE-2019-0136: Insufficient access control in the Intel(R) PROSet/Wireless WiFi
Software driver before version 21.10 may allow an unauthenticated user to potentially
enable denial of service via adjacent access.
CVE-2019-10207: A flaw was found in the Linux kernel's Bluetooth implementation
of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker
with local access and write permissions to the Bluetooth hardware could use this
flaw to issue a specially crafted ioctl function call and cause the system to
crash.
CVE-2019-11487: The Linux kernel before 5.1-rc5 allows page->_refcount reference
count overflow, with resultant use-after-free issues, if about 140 GiB of RAM
exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h,
include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It
can occur with FUSE requests.
CVE-2019-13631: In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in
the Linux kernel through 5.2.1, a malicious USB device can send an HID report
that triggers an out-of-bounds write during generation of debugging messages.
CVE-2019-15211: There is a use-after-free caused by a malicious USB device in the
drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c
does not properly allocate memory.
CVE-2019-15215: There is a use-after-free caused by a malicious USB device in the
drivers/media/usb/cpia2/cpia2_usb.c driver.
CVE-2019-15926: Out of bounds access exists in the functions ath6kl_wmi_pstream_timeout_event_rx
and ath6kl_wmi_cac_event_rx in the file drivers/net/wireless/ath/ath6kl/wmi.c.
cvelist: [CVE-2016-10905, CVE-2017-18509, CVE-2018-20961, CVE-2019-0136, CVE-2019-10207,
CVE-2019-11487, CVE-2019-13631, CVE-2019-15211, CVE-2019-15215, CVE-2019-15926]
latest-version: kernel-4.4.0-148.174~14.04.1
ubuntu-xenial:
CVE-2016-10905: An issue was discovered in fs/gfs2/rgrp.c in the Linux kernel before
4.8. A use-after-free is caused by the functions gfs2_clear_rgrpd and read_rindex_entry.
CVE-2017-18509: An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel
before 4.11. By setting a specific socket option, an attacker can control a pointer
in kernel land and cause an inet_csk_listen_stop general protection fault, or
potentially execute arbitrary code under certain circumstances. The issue can
be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN
capability) or after namespace unsharing. This occurs because sk_type and protocol
are not checked in the appropriate part of the ip6_mroute_* functions.
CVE-2018-20961: In the Linux kernel before 4.16.4, a double free vulnerability in
the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi
driver may allow attackers to cause a denial of service or possibly have unspecified
other impact.
CVE-2019-0136: Insufficient access control in the Intel(R) PROSet/Wireless WiFi
Software driver before version 21.10 may allow an unauthenticated user to potentially
enable denial of service via adjacent access.
CVE-2019-10207: A flaw was found in the Linux kernel's Bluetooth implementation
of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker
with local access and write permissions to the Bluetooth hardware could use this
flaw to issue a specially crafted ioctl function call and cause the system to
crash.
CVE-2019-11487: The Linux kernel before 5.1-rc5 allows page->_refcount reference
count overflow, with resultant use-after-free issues, if about 140 GiB of RAM
exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h,
include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It
can occur with FUSE requests.
CVE-2019-13631: In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in
the Linux kernel through 5.2.1, a malicious USB device can send an HID report
that triggers an out-of-bounds write during generation of debugging messages.
CVE-2019-15211: There is a use-after-free caused by a malicious USB device in the
drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c
does not properly allocate memory.
CVE-2019-15215: There is a use-after-free caused by a malicious USB device in the
drivers/media/usb/cpia2/cpia2_usb.c driver.
CVE-2019-15926: Out of bounds access exists in the functions ath6kl_wmi_pstream_timeout_event_rx
and ath6kl_wmi_cac_event_rx in the file drivers/net/wireless/ath/ath6kl/wmi.c.
cvelist: [CVE-2016-10905, CVE-2017-18509, CVE-2018-20961, CVE-2019-0136, CVE-2019-10207,
CVE-2019-11487, CVE-2019-13631, CVE-2019-15211, CVE-2019-15215, CVE-2019-15926]
latest-version: kernel-4.4.0-171.200
ubuntu-trusty-lts-xenial-aws:
CVE-2016-10905: An issue was discovered in fs/gfs2/rgrp.c in the Linux kernel before
4.8. A use-after-free is caused by the functions gfs2_clear_rgrpd and read_rindex_entry.
CVE-2017-18509: An issue was discovered in net/ipv6/ip6mr.c in the Linux kernel
before 4.11. By setting a specific socket option, an attacker can control a pointer
in kernel land and cause an inet_csk_listen_stop general protection fault, or
potentially execute arbitrary code under certain circumstances. The issue can
be triggered as root (e.g., inside a default LXC container or with the CAP_NET_ADMIN
capability) or after namespace unsharing. This occurs because sk_type and protocol
are not checked in the appropriate part of the ip6_mroute_* functions.
CVE-2018-20961: In the Linux kernel before 4.16.4, a double free vulnerability in
the f_midi_set_alt function of drivers/usb/gadget/function/f_midi.c in the f_midi
driver may allow attackers to cause a denial of service or possibly have unspecified
other impact.
CVE-2019-0136: Insufficient access control in the Intel(R) PROSet/Wireless WiFi
Software driver before version 21.10 may allow an unauthenticated user to potentially
enable denial of service via adjacent access.
CVE-2019-10207: A flaw was found in the Linux kernel's Bluetooth implementation
of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker
with local access and write permissions to the Bluetooth hardware could use this
flaw to issue a specially crafted ioctl function call and cause the system to
crash.
CVE-2019-11487: The Linux kernel before 5.1-rc5 allows page->_refcount reference
count overflow, with resultant use-after-free issues, if about 140 GiB of RAM
exists. This is related to fs/fuse/dev.c, fs/pipe.c, fs/splice.c, include/linux/mm.h,
include/linux/pipe_fs_i.h, kernel/trace/trace.c, mm/gup.c, and mm/hugetlb.c. It
can occur with FUSE requests.
CVE-2019-13631: In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in
the Linux kernel through 5.2.1, a malicious USB device can send an HID report
that triggers an out-of-bounds write during generation of debugging messages.
CVE-2019-15211: There is a use-after-free caused by a malicious USB device in the
drivers/media/v4l2-core/v4l2-dev.c driver because drivers/media/radio/radio-raremono.c
does not properly allocate memory.
CVE-2019-15215: There is a use-after-free caused by a malicious USB device in the
drivers/media/usb/cpia2/cpia2_usb.c driver.
CVE-2019-15926: Out of bounds access exists in the functions ath6kl_wmi_pstream_timeout_event_rx
and ath6kl_wmi_cac_event_rx in the file drivers/net/wireless/ath/ath6kl/wmi.c.
cvelist: [CVE-2016-10905, CVE-2017-18509, CVE-2018-20961, CVE-2019-0136, CVE-2019-10207,
CVE-2019-11487, CVE-2019-13631, CVE-2019-15211, CVE-2019-15215, CVE-2019-15926]
latest-version: kernel-4.4.0-1037.40

KernelCare

unread,
Jan 29, 2020, 4:25:07 AM1/29/20
to kernelca...@googlegroups.com

KernelCare

unread,
Feb 7, 2020, 6:13:08 AM2/7/20
to kernelca...@googlegroups.com
Dear Customers,

KernelCare prepared security updates for your system.
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.
You can manually update the server by running:

/usr/bin/kcarectl --update

Changelog:

ubuntu-xenial-aws:
CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel,
all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw
could occur when the station attempts a connection negotiation during the handling
of the remote devices country settings. This could allow the remote device to
cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-14896: A heap-based buffer overflow vulnerability was found in the Linux
kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker
could cause a denial of service (system crash) or, possibly execute arbitrary
code, when the lbs_ibss_join_existing function is called after a STA connects
to an AP.
CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version
kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial
of service (system crash) or, possibly execute arbitrary code, when a STA works
in IBSS mode (allows connecting stations together without the use of an AP) and
connects to another STA.
CVE-2019-14901: A heap overflow flaw was found in the Linux kernel, all versions
3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability
allows a remote attacker to cause a system crash, resulting in a denial of service,
or execute arbitrary code. The highest threat with this vulnerability is with
the availability of the system. If code execution occurs, the code will run with
the permissions of root. This will affect both confidentiality and integrity of
files on the system.
CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/input/ff-memless.c
driver, aka CID-fa3a5a1880c9.
CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that
can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c
driver, aka CID-f7a1337f0d29.
cvelist: [CVE-2019-14895, CVE-2019-14896, CVE-2019-14897, CVE-2019-14901, CVE-2019-19052,
CVE-2019-19524, CVE-2019-19534]
latest-version: kernel-4.4.0-1100.111
ubuntu-trusty-lts-xenial:
CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel,
all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw
could occur when the station attempts a connection negotiation during the handling
of the remote devices country settings. This could allow the remote device to
cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-14896: A heap-based buffer overflow vulnerability was found in the Linux
kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker
could cause a denial of service (system crash) or, possibly execute arbitrary
code, when the lbs_ibss_join_existing function is called after a STA connects
to an AP.
CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version
kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial
of service (system crash) or, possibly execute arbitrary code, when a STA works
in IBSS mode (allows connecting stations together without the use of an AP) and
connects to another STA.
CVE-2019-14901: A heap overflow flaw was found in the Linux kernel, all versions
3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability
allows a remote attacker to cause a system crash, resulting in a denial of service,
or execute arbitrary code. The highest threat with this vulnerability is with
the availability of the system. If code execution occurs, the code will run with
the permissions of root. This will affect both confidentiality and integrity of
files on the system.
CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/input/ff-memless.c
driver, aka CID-fa3a5a1880c9.
CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that
can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c
driver, aka CID-f7a1337f0d29.
cvelist: [CVE-2019-14895, CVE-2019-14896, CVE-2019-14897, CVE-2019-14901, CVE-2019-19052,
CVE-2019-19524, CVE-2019-19534]
latest-version: kernel-4.4.0-148.174~14.04.1
ubuntu-xenial-fips:
CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel,
all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw
could occur when the station attempts a connection negotiation during the handling
of the remote devices country settings. This could allow the remote device to
cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-14896: A heap-based buffer overflow vulnerability was found in the Linux
kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker
could cause a denial of service (system crash) or, possibly execute arbitrary
code, when the lbs_ibss_join_existing function is called after a STA connects
to an AP.
CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version
kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial
of service (system crash) or, possibly execute arbitrary code, when a STA works
in IBSS mode (allows connecting stations together without the use of an AP) and
connects to another STA.
CVE-2019-14901: A heap overflow flaw was found in the Linux kernel, all versions
3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability
allows a remote attacker to cause a system crash, resulting in a denial of service,
or execute arbitrary code. The highest threat with this vulnerability is with
the availability of the system. If code execution occurs, the code will run with
the permissions of root. This will affect both confidentiality and integrity of
files on the system.
CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/input/ff-memless.c
driver, aka CID-fa3a5a1880c9.
CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that
can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c
driver, aka CID-f7a1337f0d29.
cvelist: [CVE-2019-14895, CVE-2019-14896, CVE-2019-14897, CVE-2019-14901, CVE-2019-19052,
CVE-2019-19524, CVE-2019-19534]
latest-version: kernel-4.4.0-1027.32
ubuntu-xenial:
CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel,
all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw
could occur when the station attempts a connection negotiation during the handling
of the remote devices country settings. This could allow the remote device to
cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-14896: A heap-based buffer overflow vulnerability was found in the Linux
kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker
could cause a denial of service (system crash) or, possibly execute arbitrary
code, when the lbs_ibss_join_existing function is called after a STA connects
to an AP.
CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version
kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial
of service (system crash) or, possibly execute arbitrary code, when a STA works
in IBSS mode (allows connecting stations together without the use of an AP) and
connects to another STA.
CVE-2019-14901: A heap overflow flaw was found in the Linux kernel, all versions
3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability
allows a remote attacker to cause a system crash, resulting in a denial of service,
or execute arbitrary code. The highest threat with this vulnerability is with
the availability of the system. If code execution occurs, the code will run with
the permissions of root. This will affect both confidentiality and integrity of
files on the system.
CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/input/ff-memless.c
driver, aka CID-fa3a5a1880c9.
CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that
can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c
driver, aka CID-f7a1337f0d29.
cvelist: [CVE-2019-14895, CVE-2019-14896, CVE-2019-14897, CVE-2019-14901, CVE-2019-19052,
CVE-2019-19524, CVE-2019-19534]
latest-version: kernel-4.4.0-173.203
ubuntu-trusty-lts-xenial-aws:
CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel,
all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw
could occur when the station attempts a connection negotiation during the handling
of the remote devices country settings. This could allow the remote device to
cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-14896: A heap-based buffer overflow vulnerability was found in the Linux
kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker
could cause a denial of service (system crash) or, possibly execute arbitrary
code, when the lbs_ibss_join_existing function is called after a STA connects
to an AP.
CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version
kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial
of service (system crash) or, possibly execute arbitrary code, when a STA works
in IBSS mode (allows connecting stations together without the use of an AP) and
connects to another STA.
CVE-2019-14901: A heap overflow flaw was found in the Linux kernel, all versions
3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability
allows a remote attacker to cause a system crash, resulting in a denial of service,
or execute arbitrary code. The highest threat with this vulnerability is with
the availability of the system. If code execution occurs, the code will run with
the permissions of root. This will affect both confidentiality and integrity of
files on the system.
CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/input/ff-memless.c
driver, aka CID-fa3a5a1880c9.
CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that
can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c
driver, aka CID-f7a1337f0d29.
cvelist: [CVE-2019-14895, CVE-2019-14896, CVE-2019-14897, CVE-2019-14901, CVE-2019-19052,
CVE-2019-19524, CVE-2019-19534]
latest-version: kernel-4.4.0-1037.40

KernelCare

unread,
Feb 7, 2020, 6:31:07 AM2/7/20
to kernelca...@googlegroups.com
Dear Customers,

KernelCare prepared security updates for your system.
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.
You can manually update the server by running:

/usr/bin/kcarectl --update

Changelog:

ubuntu-xenial-lts-bionic-aws:
CVE-2019-11135: TSX Asynchronous Abort condition on some CPUs utilizing speculative
execution may allow an authenticated user to potentially enable information disclosure
via a side channel with local access.
CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel,
all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw
could occur when the station attempts a connection negotiation during the handling
of the remote devices country settings. This could allow the remote device to
cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-14896: A heap-based buffer overflow vulnerability was found in the Linux
kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker
could cause a denial of service (system crash) or, possibly execute arbitrary
code, when the lbs_ibss_join_existing function is called after a STA connects
to an AP.
CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version
kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial
of service (system crash) or, possibly execute arbitrary code, when a STA works
in IBSS mode (allows connecting stations together without the use of an AP) and
connects to another STA.
CVE-2019-14901: A heap overflow flaw was found in the Linux kernel, all versions
3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability
allows a remote attacker to cause a system crash, resulting in a denial of service,
or execute arbitrary code. The highest threat with this vulnerability is with
the availability of the system. If code execution occurs, the code will run with
the permissions of root. This will affect both confidentiality and integrity of
files on the system.
CVE-2019-16231: drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16233: drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-19045: A memory leak in the mlx5_fpga_conn_create_cq() function in drivers/net/ethernet/mellanox/mlx5/core/fpga/conn.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering mlx5_vector2eqn() failures, aka CID-c8c2a057fdc7.
CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
CVE-2019-19083: Memory leaks in *clock_source_create() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel before 5.3.8 allow attackers to cause a denial of service
(memory consumption). This affects the dce112_clock_source_create() function in
drivers/gpu/drm/amd/display/dc/dce112/dce112_resource.c, the dce100_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce100/dce100_resource.c, the dcn10_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dcn10/dcn10_resource.c, the dcn20_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dcn20/dcn20_resource.c, the dce120_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce120/dce120_resource.c, the dce110_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce110/dce110_resource.c, and the dce80_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce80/dce80_resource.c, aka CID-055e547478a1.
CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/input/ff-memless.c
driver, aka CID-fa3a5a1880c9.
CVE-2019-19529: In the Linux kernel before 5.3.11, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c
driver, aka CID-4d6636498c41.
CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that
can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c
driver, aka CID-f7a1337f0d29.
cvelist: [CVE-2019-14895, CVE-2019-14896, CVE-2019-14897, CVE-2019-14901, CVE-2019-16231,
CVE-2019-16233, CVE-2019-19045, CVE-2019-19052, CVE-2019-19083, CVE-2019-19524,
CVE-2019-19529, CVE-2019-19534, CVE-2019-11135]
latest-version: kernel-4.15.0-1056.58~16.04.1
ubuntu-bionic:
CVE-2019-11135: TSX Asynchronous Abort condition on some CPUs utilizing speculative
execution may allow an authenticated user to potentially enable information disclosure
via a side channel with local access.
CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel,
all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw
could occur when the station attempts a connection negotiation during the handling
of the remote devices country settings. This could allow the remote device to
cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-14896: A heap-based buffer overflow vulnerability was found in the Linux
kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker
could cause a denial of service (system crash) or, possibly execute arbitrary
code, when the lbs_ibss_join_existing function is called after a STA connects
to an AP.
CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version
kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial
of service (system crash) or, possibly execute arbitrary code, when a STA works
in IBSS mode (allows connecting stations together without the use of an AP) and
connects to another STA.
CVE-2019-14901: A heap overflow flaw was found in the Linux kernel, all versions
3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability
allows a remote attacker to cause a system crash, resulting in a denial of service,
or execute arbitrary code. The highest threat with this vulnerability is with
the availability of the system. If code execution occurs, the code will run with
the permissions of root. This will affect both confidentiality and integrity of
files on the system.
CVE-2019-16231: drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16233: drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-19045: A memory leak in the mlx5_fpga_conn_create_cq() function in drivers/net/ethernet/mellanox/mlx5/core/fpga/conn.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering mlx5_vector2eqn() failures, aka CID-c8c2a057fdc7.
CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
CVE-2019-19083: Memory leaks in *clock_source_create() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel before 5.3.8 allow attackers to cause a denial of service
(memory consumption). This affects the dce112_clock_source_create() function in
drivers/gpu/drm/amd/display/dc/dce112/dce112_resource.c, the dce100_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce100/dce100_resource.c, the dcn10_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dcn10/dcn10_resource.c, the dcn20_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dcn20/dcn20_resource.c, the dce120_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce120/dce120_resource.c, the dce110_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce110/dce110_resource.c, and the dce80_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce80/dce80_resource.c, aka CID-055e547478a1.
CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/input/ff-memless.c
driver, aka CID-fa3a5a1880c9.
CVE-2019-19529: In the Linux kernel before 5.3.11, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c
driver, aka CID-4d6636498c41.
CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that
can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c
driver, aka CID-f7a1337f0d29.
cvelist: [CVE-2019-14895, CVE-2019-14896, CVE-2019-14897, CVE-2019-14901, CVE-2019-16231,
CVE-2019-16233, CVE-2019-19045, CVE-2019-19052, CVE-2019-19083, CVE-2019-19524,
CVE-2019-19529, CVE-2019-19534, CVE-2019-11135]
latest-version: kernel-4.15.0-76.86
ubuntu-bionic-gcp:
CVE-2019-0154: Insufficient access control in subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 and E-2100 Processor Families
may allow an authenticated user to potentially enable denial of service via local
access.
CVE-2019-0155: Insufficient access control in a subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6, E-2100 and E-2200 Processor
Families; Intel(R) Graphics Driver for Windows before 26.20.100.6813 (DCH) or
26.20.100.6812 and before 21.20.x.5077 (aka15.45.5077), i915 Linux Driver for
Intel(R) Processor Graphics before versions 5.4-rc7, 5.3.11, 4.19.84, 4.14.154,
4.9.201, 4.4.201 may allow an authenticated user to potentially enable escalation
of privilege via local access.
CVE-2019-11135: TSX Asynchronous Abort condition on some CPUs utilizing speculative
execution may allow an authenticated user to potentially enable information disclosure
via a side channel with local access.
CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel,
all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw
could occur when the station attempts a connection negotiation during the handling
of the remote devices country settings. This could allow the remote device to
cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-14896: A heap-based buffer overflow vulnerability was found in the Linux
kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker
could cause a denial of service (system crash) or, possibly execute arbitrary
code, when the lbs_ibss_join_existing function is called after a STA connects
to an AP.
CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version
kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial
of service (system crash) or, possibly execute arbitrary code, when a STA works
in IBSS mode (allows connecting stations together without the use of an AP) and
connects to another STA.
CVE-2019-14901: A heap overflow flaw was found in the Linux kernel, all versions
3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability
allows a remote attacker to cause a system crash, resulting in a denial of service,
or execute arbitrary code. The highest threat with this vulnerability is with
the availability of the system. If code execution occurs, the code will run with
the permissions of root. This will affect both confidentiality and integrity of
files on the system.
CVE-2019-16231: drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16233: drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-19045: A memory leak in the mlx5_fpga_conn_create_cq() function in drivers/net/ethernet/mellanox/mlx5/core/fpga/conn.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering mlx5_vector2eqn() failures, aka CID-c8c2a057fdc7.
CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
CVE-2019-19083: Memory leaks in *clock_source_create() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel before 5.3.8 allow attackers to cause a denial of service
(memory consumption). This affects the dce112_clock_source_create() function in
drivers/gpu/drm/amd/display/dc/dce112/dce112_resource.c, the dce100_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce100/dce100_resource.c, the dcn10_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dcn10/dcn10_resource.c, the dcn20_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dcn20/dcn20_resource.c, the dce120_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce120/dce120_resource.c, the dce110_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce110/dce110_resource.c, and the dce80_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce80/dce80_resource.c, aka CID-055e547478a1.
CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/input/ff-memless.c
driver, aka CID-fa3a5a1880c9.
CVE-2019-19529: In the Linux kernel before 5.3.11, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c
driver, aka CID-4d6636498c41.
CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that
can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c
driver, aka CID-f7a1337f0d29.
cvelist: [CVE-2019-14895, CVE-2019-14896, CVE-2019-14897, CVE-2019-14901, CVE-2019-16231,
CVE-2019-16233, CVE-2019-19045, CVE-2019-19052, CVE-2019-19083, CVE-2019-19524,
CVE-2019-19529, CVE-2019-19534, CVE-2019-11135, CVE-2019-0155, CVE-2019-0154]
latest-version: kernel-5.0.0-1026.27~18.04.1
ubuntu-bionic-aws:
CVE-2019-11135: TSX Asynchronous Abort condition on some CPUs utilizing speculative
execution may allow an authenticated user to potentially enable information disclosure
via a side channel with local access.
CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel,
all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw
could occur when the station attempts a connection negotiation during the handling
of the remote devices country settings. This could allow the remote device to
cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-14896: A heap-based buffer overflow vulnerability was found in the Linux
kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker
could cause a denial of service (system crash) or, possibly execute arbitrary
code, when the lbs_ibss_join_existing function is called after a STA connects
to an AP.
CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version
kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial
of service (system crash) or, possibly execute arbitrary code, when a STA works
in IBSS mode (allows connecting stations together without the use of an AP) and
connects to another STA.
CVE-2019-14901: A heap overflow flaw was found in the Linux kernel, all versions
3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability
allows a remote attacker to cause a system crash, resulting in a denial of service,
or execute arbitrary code. The highest threat with this vulnerability is with
the availability of the system. If code execution occurs, the code will run with
the permissions of root. This will affect both confidentiality and integrity of
files on the system.
CVE-2019-16231: drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16233: drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-19045: A memory leak in the mlx5_fpga_conn_create_cq() function in drivers/net/ethernet/mellanox/mlx5/core/fpga/conn.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering mlx5_vector2eqn() failures, aka CID-c8c2a057fdc7.
CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
CVE-2019-19083: Memory leaks in *clock_source_create() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel before 5.3.8 allow attackers to cause a denial of service
(memory consumption). This affects the dce112_clock_source_create() function in
drivers/gpu/drm/amd/display/dc/dce112/dce112_resource.c, the dce100_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce100/dce100_resource.c, the dcn10_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dcn10/dcn10_resource.c, the dcn20_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dcn20/dcn20_resource.c, the dce120_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce120/dce120_resource.c, the dce110_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce110/dce110_resource.c, and the dce80_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce80/dce80_resource.c, aka CID-055e547478a1.
CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/input/ff-memless.c
driver, aka CID-fa3a5a1880c9.
CVE-2019-19529: In the Linux kernel before 5.3.11, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c
driver, aka CID-4d6636498c41.
CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that
can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c
driver, aka CID-f7a1337f0d29.
cvelist: [CVE-2019-14895, CVE-2019-14896, CVE-2019-14897, CVE-2019-14901, CVE-2019-16231,
CVE-2019-16233, CVE-2019-19045, CVE-2019-19052, CVE-2019-19083, CVE-2019-19524,
CVE-2019-19529, CVE-2019-19534, CVE-2019-11135]
latest-version: kernel-4.15.0-1058.60
ubuntu-bionic-hwe:
CVE-2019-0154: Insufficient access control in subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 and E-2100 Processor Families
may allow an authenticated user to potentially enable denial of service via local
access.
CVE-2019-0155: Insufficient access control in a subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6, E-2100 and E-2200 Processor
Families; Intel(R) Graphics Driver for Windows before 26.20.100.6813 (DCH) or
26.20.100.6812 and before 21.20.x.5077 (aka15.45.5077), i915 Linux Driver for
Intel(R) Processor Graphics before versions 5.4-rc7, 5.3.11, 4.19.84, 4.14.154,
4.9.201, 4.4.201 may allow an authenticated user to potentially enable escalation
of privilege via local access.
cvelist: [CVE-2019-0155, CVE-2019-0154]
latest-version: kernel-5.3.0-28.30~18.04.1
ubuntu-xenial-lts-bionic:
CVE-2019-11135: TSX Asynchronous Abort condition on some CPUs utilizing speculative
execution may allow an authenticated user to potentially enable information disclosure
via a side channel with local access.
CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel,
all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw
could occur when the station attempts a connection negotiation during the handling
of the remote devices country settings. This could allow the remote device to
cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-14896: A heap-based buffer overflow vulnerability was found in the Linux
kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker
could cause a denial of service (system crash) or, possibly execute arbitrary
code, when the lbs_ibss_join_existing function is called after a STA connects
to an AP.
CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version
kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial
of service (system crash) or, possibly execute arbitrary code, when a STA works
in IBSS mode (allows connecting stations together without the use of an AP) and
connects to another STA.
CVE-2019-14901: A heap overflow flaw was found in the Linux kernel, all versions
3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability
allows a remote attacker to cause a system crash, resulting in a denial of service,
or execute arbitrary code. The highest threat with this vulnerability is with
the availability of the system. If code execution occurs, the code will run with
the permissions of root. This will affect both confidentiality and integrity of
files on the system.
CVE-2019-16231: drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16233: drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-19045: A memory leak in the mlx5_fpga_conn_create_cq() function in drivers/net/ethernet/mellanox/mlx5/core/fpga/conn.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering mlx5_vector2eqn() failures, aka CID-c8c2a057fdc7.
CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
CVE-2019-19083: Memory leaks in *clock_source_create() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel before 5.3.8 allow attackers to cause a denial of service
(memory consumption). This affects the dce112_clock_source_create() function in
drivers/gpu/drm/amd/display/dc/dce112/dce112_resource.c, the dce100_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce100/dce100_resource.c, the dcn10_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dcn10/dcn10_resource.c, the dcn20_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dcn20/dcn20_resource.c, the dce120_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce120/dce120_resource.c, the dce110_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce110/dce110_resource.c, and the dce80_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce80/dce80_resource.c, aka CID-055e547478a1.
CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/input/ff-memless.c
driver, aka CID-fa3a5a1880c9.
CVE-2019-19529: In the Linux kernel before 5.3.11, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c
driver, aka CID-4d6636498c41.
CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that
can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c
driver, aka CID-f7a1337f0d29.
cvelist: [CVE-2019-14895, CVE-2019-14896, CVE-2019-14897, CVE-2019-14901, CVE-2019-16231,
CVE-2019-16233, CVE-2019-19045, CVE-2019-19052, CVE-2019-19083, CVE-2019-19524,
CVE-2019-19529, CVE-2019-19534, CVE-2019-11135]
latest-version: kernel-4.15.0-76.86~16.04.1
ubuntu-bionic-azure:
CVE-2019-0154: Insufficient access control in subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 and E-2100 Processor Families
may allow an authenticated user to potentially enable denial of service via local
access.
CVE-2019-0155: Insufficient access control in a subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6, E-2100 and E-2200 Processor
Families; Intel(R) Graphics Driver for Windows before 26.20.100.6813 (DCH) or
26.20.100.6812 and before 21.20.x.5077 (aka15.45.5077), i915 Linux Driver for
Intel(R) Processor Graphics before versions 5.4-rc7, 5.3.11, 4.19.84, 4.14.154,
4.9.201, 4.4.201 may allow an authenticated user to potentially enable escalation
of privilege via local access.
cvelist: [CVE-2019-0155, CVE-2019-0154]
latest-version: kernel-5.0.0-1028.30~18.04.1

KernelCare

unread,
Feb 10, 2020, 10:56:07 AM2/10/20
to kernelca...@googlegroups.com
Dear Customers,

KernelCare prepared security updates for your system.
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.
You can manually update the server by running:

/usr/bin/kcarectl --update

Changelog:

ubuntu-xenial-aws:
CVE-2019-14615: Insufficient control flow in certain data structures for some Intel(R)
Processors with Intel(R) Processor Graphics may allow an unauthenticated user
to potentially enable information disclosure via local access.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption), aka CID-3f9361695113.
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
cvelist: [CVE-2019-14615, CVE-2019-15291, CVE-2019-18683, CVE-2019-18885, CVE-2019-19057,
CVE-2019-19062, CVE-2019-19063, CVE-2019-19227, CVE-2019-19332]
latest-version: kernel-4.4.0-1100.111
ubuntu-trusty-lts-xenial:
CVE-2019-14615: Insufficient control flow in certain data structures for some Intel(R)
Processors with Intel(R) Processor Graphics may allow an unauthenticated user
to potentially enable information disclosure via local access.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption), aka CID-3f9361695113.
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
cvelist: [CVE-2019-14615, CVE-2019-15291, CVE-2019-18683, CVE-2019-18885, CVE-2019-19057,
CVE-2019-19062, CVE-2019-19063, CVE-2019-19227, CVE-2019-19332]
latest-version: kernel-4.4.0-148.174~14.04.1
ubuntu-xenial-fips:
CVE-2019-14615: Insufficient control flow in certain data structures for some Intel(R)
Processors with Intel(R) Processor Graphics may allow an unauthenticated user
to potentially enable information disclosure via local access.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption), aka CID-3f9361695113.
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
cvelist: [CVE-2019-14615, CVE-2019-15291, CVE-2019-18683, CVE-2019-18885, CVE-2019-19057,
CVE-2019-19062, CVE-2019-19063, CVE-2019-19227, CVE-2019-19332]
latest-version: kernel-4.4.0-1027.32
ubuntu-xenial:
CVE-2019-14615: Insufficient control flow in certain data structures for some Intel(R)
Processors with Intel(R) Processor Graphics may allow an unauthenticated user
to potentially enable information disclosure via local access.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption), aka CID-3f9361695113.
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
cvelist: [CVE-2019-14615, CVE-2019-15291, CVE-2019-18683, CVE-2019-18885, CVE-2019-19057,
CVE-2019-19062, CVE-2019-19063, CVE-2019-19227, CVE-2019-19332]
latest-version: kernel-4.4.0-173.203
ubuntu-trusty-lts-xenial-aws:
CVE-2019-14615: Insufficient control flow in certain data structures for some Intel(R)
Processors with Intel(R) Processor Graphics may allow an unauthenticated user
to potentially enable information disclosure via local access.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption), aka CID-3f9361695113.
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
cvelist: [CVE-2019-14615, CVE-2019-15291, CVE-2019-18683, CVE-2019-18885, CVE-2019-19057,
CVE-2019-19062, CVE-2019-19063, CVE-2019-19227, CVE-2019-19332]
latest-version: kernel-4.4.0-1037.40

KernelCare

unread,
Feb 17, 2020, 5:54:11 AM2/17/20
to kernelca...@googlegroups.com
Dear Customers,

KernelCare prepared security updates for your system.
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.
You can manually update the server by running:

/usr/bin/kcarectl --update

Changelog:

pve-5:
CVE-2019-0154: Insufficient access control in subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 and E-2100 Processor Families
may allow an authenticated user to potentially enable denial of service via local
access.
CVE-2019-0155: Insufficient access control in a subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6, E-2100 and E-2200 Processor
Families; Intel(R) Graphics Driver for Windows before 26.20.100.6813 (DCH) or
26.20.100.6812 and before 21.20.x.5077 (aka15.45.5077), i915 Linux Driver for
Intel(R) Processor Graphics before versions 5.4-rc7, 5.3.11, 4.19.84, 4.14.154,
4.9.201, 4.4.201 may allow an authenticated user to potentially enable escalation
of privilege via local access.
CVE-2019-11135: TSX Asynchronous Abort condition on some CPUs utilizing speculative
execution may allow an authenticated user to potentially enable information disclosure
via a side channel with local access.
CVE-2019-14615: Insufficient control flow in certain data structures for some Intel(R)
Processors with Intel(R) Processor Graphics may allow an unauthenticated user
to potentially enable information disclosure via local access.
CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel,
all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw
could occur when the station attempts a connection negotiation during the handling
of the remote devices country settings. This could allow the remote device to
cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-14896: A heap-based buffer overflow vulnerability was found in the Linux
kernel, version kernel-2.6.32, in Marvell WiFi chip driver. A remote attacker
could cause a denial of service (system crash) or, possibly execute arbitrary
code, when the lbs_ibss_join_existing function is called after a STA connects
to an AP.
CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version
kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial
of service (system crash) or, possibly execute arbitrary code, when a STA works
in IBSS mode (allows connecting stations together without the use of an AP) and
connects to another STA.
CVE-2019-14901: A heap overflow flaw was found in the Linux kernel, all versions
3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability
allows a remote attacker to cause a system crash, resulting in a denial of service,
or execute arbitrary code. The highest threat with this vulnerability is with
the availability of the system. If code execution occurs, the code will run with
the permissions of root. This will affect both confidentiality and integrity of
files on the system.
CVE-2019-15098: drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through
5.2.9 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-16231: drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16233: drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-17052: ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module
in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that
unprivileged users can create a raw socket, aka CID-0614e2b73768.
CVE-2019-17053: ieee802154_create in net/ieee802154/socket.c in the AF_IEEE802154
network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW,
which means that unprivileged users can create a raw socket, aka CID-e69dbd4619e7.
CVE-2019-17054: atalk_create in net/appletalk/ddp.c in the AF_APPLETALK network
module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means
that unprivileged users can create a raw socket, aka CID-6cc03e8aa36c.
CVE-2019-17055: base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network
module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means
that unprivileged users can create a raw socket, aka CID-b91ee4aa2a21.
CVE-2019-17056: llcp_sock_create in net/nfc/llcp_sock.c in the AF_NFC network module
in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that
unprivileged users can create a raw socket, aka CID-3a359798b176.
CVE-2019-17666: rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the
Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer
overflow.
CVE-2019-19045: A memory leak in the mlx5_fpga_conn_create_cq() function in drivers/net/ethernet/mellanox/mlx5/core/fpga/conn.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering mlx5_vector2eqn() failures, aka CID-c8c2a057fdc7.
CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
CVE-2019-19083: Memory leaks in *clock_source_create() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel before 5.3.8 allow attackers to cause a denial of service
(memory consumption). This affects the dce112_clock_source_create() function in
drivers/gpu/drm/amd/display/dc/dce112/dce112_resource.c, the dce100_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce100/dce100_resource.c, the dcn10_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dcn10/dcn10_resource.c, the dcn20_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dcn20/dcn20_resource.c, the dce120_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce120/dce120_resource.c, the dce110_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce110/dce110_resource.c, and the dce80_clock_source_create()
function in drivers/gpu/drm/amd/display/dc/dce80/dce80_resource.c, aka CID-055e547478a1.
CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/input/ff-memless.c
driver, aka CID-fa3a5a1880c9.
CVE-2019-19529: In the Linux kernel before 5.3.11, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c
driver, aka CID-4d6636498c41.
CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that
can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c
driver, aka CID-f7a1337f0d29.
CVE-2020-7053: In the Linux kernel 4.14 longterm through 4.14.165 and 4.19 longterm
through 4.19.96 (and 5.x before 5.2), there is a use-after-free (write) in the
i915_ppgtt_close function in drivers/gpu/drm/i915/i915_gem_gtt.c, aka CID-7dc40713618c.
This is related to i915_gem_context_destroy_ioctl in drivers/gpu/drm/i915/i915_gem_context.c.
cvelist: [CVE-2019-14615, CVE-2020-7053, CVE-2019-14895, CVE-2019-14896, CVE-2019-14897,
CVE-2019-14901, CVE-2019-16231, CVE-2019-16233, CVE-2019-19045, CVE-2019-19052,
CVE-2019-19083, CVE-2019-19524, CVE-2019-19529, CVE-2019-19534, CVE-2019-11135,
CVE-2019-0155, CVE-2019-0154, CVE-2019-15098, CVE-2019-17052, CVE-2019-17053,
CVE-2019-17054, CVE-2019-17055, CVE-2019-17056, CVE-2019-17666]
latest-version: pve-kernel-4.15.18-25-pve_4.15.18-53

KernelCare

unread,
Feb 27, 2020, 1:32:11 AM2/27/20
to kernelca...@googlegroups.com
Dear Customers,

KernelCare prepared security updates for your system.
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.
You can manually update the server by running:

/usr/bin/kcarectl --update

Changelog:

ubuntu-xenial-lts-bionic-aws:
CVE-2019-15099: drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through
5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-16229: drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14
does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel
5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer
dereference.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18786: In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized
in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could
cause a memory disclosure problem.
CVE-2019-18809: A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c
in the Linux kernel through 5.3.9 allows attackers to cause a denial of service
(memory consumption), aka CID-2289adbfa559.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption), aka CID-3f9361695113.
CVE-2019-19071: A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19078: A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
CVE-2019-19082: Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption).
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
CVE-2019-19767: The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize,
as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry,
related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
cvelist: [CVE-2019-19332, CVE-2019-19227, CVE-2019-19767, CVE-2019-19078, CVE-2019-19082,
CVE-2019-19063, CVE-2019-19071, CVE-2019-19057, CVE-2019-18809, CVE-2019-18885,
CVE-2019-18786, CVE-2019-18683, CVE-2019-15099, CVE-2019-5108, CVE-2019-20096,
CVE-2019-19965, CVE-2019-19062, CVE-2019-16232, CVE-2019-16229, CVE-2019-15291]
latest-version: kernel-4.15.0-1060.62~16.04.1
ubuntu-bionic:
CVE-2019-15099: drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through
5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-16229: drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14
does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel
5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer
dereference.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18786: In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized
in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could
cause a memory disclosure problem.
CVE-2019-18809: A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c
in the Linux kernel through 5.3.9 allows attackers to cause a denial of service
(memory consumption), aka CID-2289adbfa559.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption), aka CID-3f9361695113.
CVE-2019-19071: A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19078: A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
CVE-2019-19082: Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption).
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
CVE-2019-19767: The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize,
as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry,
related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
cvelist: [CVE-2019-19332, CVE-2019-19227, CVE-2019-19767, CVE-2019-19078, CVE-2019-19082,
CVE-2019-19063, CVE-2019-19071, CVE-2019-19057, CVE-2019-18809, CVE-2019-18885,
CVE-2019-18786, CVE-2019-18683, CVE-2019-15099, CVE-2019-5108, CVE-2019-20096,
CVE-2019-19965, CVE-2019-19062, CVE-2019-16232, CVE-2019-16229, CVE-2019-15291]
latest-version: kernel-4.15.0-88.88
ubuntu-xenial-lts-bionic-azure:
CVE-2019-15099: drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through
5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-16229: drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14
does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel
5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer
dereference.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18786: In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized
in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could
cause a memory disclosure problem.
CVE-2019-18809: A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c
in the Linux kernel through 5.3.9 allows attackers to cause a denial of service
(memory consumption), aka CID-2289adbfa559.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption), aka CID-3f9361695113.
CVE-2019-19071: A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19078: A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
CVE-2019-19082: Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption).
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
CVE-2019-19767: The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize,
as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry,
related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
cvelist: [CVE-2019-19332, CVE-2019-19227, CVE-2019-19767, CVE-2019-19078, CVE-2019-19082,
CVE-2019-19063, CVE-2019-19071, CVE-2019-19057, CVE-2019-18809, CVE-2019-18885,
CVE-2019-18786, CVE-2019-18683, CVE-2019-15099, CVE-2019-5108, CVE-2019-20096,
CVE-2019-19965, CVE-2019-19062, CVE-2019-16232, CVE-2019-16229, CVE-2019-15291]
latest-version: kernel-4.15.0-1071.76
ubuntu-xenial-lts-bionic-gcp:
CVE-2019-15099: drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through
5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-16229: drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14
does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel
5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer
dereference.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18786: In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized
in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could
cause a memory disclosure problem.
CVE-2019-18809: A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c
in the Linux kernel through 5.3.9 allows attackers to cause a denial of service
(memory consumption), aka CID-2289adbfa559.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption), aka CID-3f9361695113.
CVE-2019-19071: A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19078: A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
CVE-2019-19082: Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption).
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
CVE-2019-19767: The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize,
as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry,
related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
cvelist: [CVE-2019-19332, CVE-2019-19227, CVE-2019-19767, CVE-2019-19078, CVE-2019-19082,
CVE-2019-19063, CVE-2019-19071, CVE-2019-19057, CVE-2019-18809, CVE-2019-18885,
CVE-2019-18786, CVE-2019-18683, CVE-2019-15099, CVE-2019-5108, CVE-2019-20096,
CVE-2019-19965, CVE-2019-19062, CVE-2019-16232, CVE-2019-16229, CVE-2019-15291]
latest-version: kernel-4.15.0-1040.42~16.04.1
ubuntu-bionic-gcp:
CVE-2019-15099: drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through
5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-16229: drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14
does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel
5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer
dereference.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18786: In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized
in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could
cause a memory disclosure problem.
CVE-2019-18809: A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c
in the Linux kernel through 5.3.9 allows attackers to cause a denial of service
(memory consumption), aka CID-2289adbfa559.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption), aka CID-3f9361695113.
CVE-2019-19071: A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19078: A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
CVE-2019-19082: Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption).
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
CVE-2019-19767: The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize,
as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry,
related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
cvelist: [CVE-2019-19332, CVE-2019-19227, CVE-2019-19767, CVE-2019-19078, CVE-2019-19082,
CVE-2019-19063, CVE-2019-19071, CVE-2019-19057, CVE-2019-18809, CVE-2019-18885,
CVE-2019-18786, CVE-2019-18683, CVE-2019-15099, CVE-2019-5108, CVE-2019-20096,
CVE-2019-19965, CVE-2019-19062, CVE-2019-16232, CVE-2019-16229, CVE-2019-15291]
latest-version: kernel-5.0.0-1026.27~18.04.1
pve-5:
CVE-2019-15099: drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through
5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-16229: drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14
does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel
5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer
dereference.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18786: In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized
in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could
cause a memory disclosure problem.
CVE-2019-18809: A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c
in the Linux kernel through 5.3.9 allows attackers to cause a denial of service
(memory consumption), aka CID-2289adbfa559.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption), aka CID-3f9361695113.
CVE-2019-19071: A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19078: A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
CVE-2019-19082: Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption).
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
CVE-2019-19767: The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize,
as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry,
related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
cvelist: [CVE-2019-19332, CVE-2019-19227, CVE-2019-19767, CVE-2019-19078, CVE-2019-19082,
CVE-2019-19063, CVE-2019-19071, CVE-2019-19057, CVE-2019-18809, CVE-2019-18885,
CVE-2019-18786, CVE-2019-18683, CVE-2019-15099, CVE-2019-5108, CVE-2019-20096,
CVE-2019-19965, CVE-2019-19062, CVE-2019-16232, CVE-2019-16229, CVE-2019-15291]
latest-version: pve-kernel-4.15.18-25-pve_4.15.18-53
ubuntu-bionic-aws:
CVE-2019-15099: drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through
5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-16229: drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14
does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel
5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer
dereference.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18786: In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized
in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could
cause a memory disclosure problem.
CVE-2019-18809: A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c
in the Linux kernel through 5.3.9 allows attackers to cause a denial of service
(memory consumption), aka CID-2289adbfa559.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption), aka CID-3f9361695113.
CVE-2019-19071: A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19078: A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
CVE-2019-19082: Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption).
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
CVE-2019-19767: The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize,
as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry,
related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
cvelist: [CVE-2019-19332, CVE-2019-19227, CVE-2019-19767, CVE-2019-19078, CVE-2019-19082,
CVE-2019-19063, CVE-2019-19071, CVE-2019-19057, CVE-2019-18809, CVE-2019-18885,
CVE-2019-18786, CVE-2019-18683, CVE-2019-15099, CVE-2019-5108, CVE-2019-20096,
CVE-2019-19965, CVE-2019-19062, CVE-2019-16232, CVE-2019-16229, CVE-2019-15291]
latest-version: kernel-4.15.0-1060.62
ubuntu-xenial-lts-bionic:
CVE-2019-15099: drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through
5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-16229: drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14
does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel
5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer
dereference.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18786: In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized
in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could
cause a memory disclosure problem.
CVE-2019-18809: A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c
in the Linux kernel through 5.3.9 allows attackers to cause a denial of service
(memory consumption), aka CID-2289adbfa559.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption), aka CID-3f9361695113.
CVE-2019-19071: A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19078: A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
CVE-2019-19082: Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption).
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
CVE-2019-19767: The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize,
as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry,
related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
cvelist: [CVE-2019-19332, CVE-2019-19227, CVE-2019-19767, CVE-2019-19078, CVE-2019-19082,
CVE-2019-19063, CVE-2019-19071, CVE-2019-19057, CVE-2019-18809, CVE-2019-18885,
CVE-2019-18786, CVE-2019-18683, CVE-2019-15099, CVE-2019-5108, CVE-2019-20096,
CVE-2019-19965, CVE-2019-19062, CVE-2019-16232, CVE-2019-16229, CVE-2019-15291]
latest-version: kernel-4.15.0-88.88~16.04.1
ubuntu-bionic-azure:
CVE-2019-15099: drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through
5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-16229: drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14
does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel
5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer
dereference.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18786: In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized
in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could
cause a memory disclosure problem.
CVE-2019-18809: A memory leak in the af9005_identify_state() function in drivers/media/usb/dvb-usb/af9005.c
in the Linux kernel through 5.3.9 allows attackers to cause a denial of service
(memory consumption), aka CID-2289adbfa559.
CVE-2019-18885: fs/btrfs/volumes.c in the Linux kernel before 5.1 allows a btrfs_verify_dev_extents
NULL pointer dereference via a crafted btrfs image because fs_devices->devices
is mishandled within find_device, aka CID-09ba3bc9dd15.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption), aka CID-3f9361695113.
CVE-2019-19071: A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19078: A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
CVE-2019-19082: Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption).
CVE-2019-19227: In the AppleTalk subsystem in the Linux kernel before 5.1, there
is a potential NULL pointer dereference because register_snap_client may return
NULL. This will lead to denial of service in net/appletalk/aarp.c and net/appletalk/ddp.c,
as demonstrated by unregister_snap_client, aka CID-9804501fa122.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
CVE-2019-19767: The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize,
as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry,
related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
cvelist: [CVE-2019-19332, CVE-2019-19227, CVE-2019-19767, CVE-2019-19078, CVE-2019-19082,
CVE-2019-19063, CVE-2019-19071, CVE-2019-19057, CVE-2019-18809, CVE-2019-18885,
CVE-2019-18786, CVE-2019-18683, CVE-2019-15099, CVE-2019-5108, CVE-2019-20096,
CVE-2019-19965, CVE-2019-19062, CVE-2019-16232, CVE-2019-16229, CVE-2019-15291]
latest-version: kernel-5.0.0-1032.34

KernelCare

unread,
Feb 27, 2020, 1:49:12 AM2/27/20
to kernelca...@googlegroups.com
Dear Customers,

KernelCare prepared security updates for your system.
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.
You can manually update the server by running:

/usr/bin/kcarectl --update

Changelog:

ubuntu-xenial-aws:
CVE-2019-15220: An issue was discovered in the Linux kernel before 5.2.1. There
is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c
driver.
CVE-2019-15221: An issue was discovered in the Linux kernel before 5.1.17. There
is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c
driver.
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause
a denial of service because of unrestricted resource consumption during the mapping
of guest memory, aka CID-6ef36ab967c7.
CVE-2019-19051: A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption), aka CID-6f3ef5c25cc7.
CVE-2019-19056: A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allows attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-db8fd2cde932.
CVE-2019-19066: A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.
CVE-2019-19068: A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-a2cdd07488e6.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-2101: 'In uvc_parse_standard_control of uvc_driver.c, there is a possible
out-of-bound read due to improper input validation. This could lead to local information
disclosure with no additional execution privileges needed. User interaction is
not needed for exploitation. Product: Android. Versions: Android kernel. Android
ID: A-111760968.'
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
cvelist: [CVE-2019-15220, CVE-2019-15221, CVE-2019-17351, CVE-2019-19051, CVE-2019-19056,
CVE-2019-19066, CVE-2019-19068, CVE-2019-19965, CVE-2019-20096, CVE-2019-5108,
CVE-2019-2101]
latest-version: kernel-4.4.0-1102.113
ubuntu-trusty-lts-xenial:
CVE-2019-15220: An issue was discovered in the Linux kernel before 5.2.1. There
is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c
driver.
CVE-2019-15221: An issue was discovered in the Linux kernel before 5.1.17. There
is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c
driver.
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause
a denial of service because of unrestricted resource consumption during the mapping
of guest memory, aka CID-6ef36ab967c7.
CVE-2019-19051: A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption), aka CID-6f3ef5c25cc7.
CVE-2019-19056: A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allows attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-db8fd2cde932.
CVE-2019-19066: A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.
CVE-2019-19068: A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-a2cdd07488e6.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-2101: 'In uvc_parse_standard_control of uvc_driver.c, there is a possible
out-of-bound read due to improper input validation. This could lead to local information
disclosure with no additional execution privileges needed. User interaction is
not needed for exploitation. Product: Android. Versions: Android kernel. Android
ID: A-111760968.'
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
cvelist: [CVE-2019-15220, CVE-2019-15221, CVE-2019-17351, CVE-2019-19051, CVE-2019-19056,
CVE-2019-19066, CVE-2019-19068, CVE-2019-19965, CVE-2019-20096, CVE-2019-5108,
CVE-2019-2101]
latest-version: kernel-4.4.0-148.174~14.04.1
ubuntu-xenial-fips:
CVE-2019-15220: An issue was discovered in the Linux kernel before 5.2.1. There
is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c
driver.
CVE-2019-15221: An issue was discovered in the Linux kernel before 5.1.17. There
is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c
driver.
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause
a denial of service because of unrestricted resource consumption during the mapping
of guest memory, aka CID-6ef36ab967c7.
CVE-2019-19051: A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption), aka CID-6f3ef5c25cc7.
CVE-2019-19056: A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allows attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-db8fd2cde932.
CVE-2019-19066: A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.
CVE-2019-19068: A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-a2cdd07488e6.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-2101: 'In uvc_parse_standard_control of uvc_driver.c, there is a possible
out-of-bound read due to improper input validation. This could lead to local information
disclosure with no additional execution privileges needed. User interaction is
not needed for exploitation. Product: Android. Versions: Android kernel. Android
ID: A-111760968.'
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
cvelist: [CVE-2019-15220, CVE-2019-15221, CVE-2019-17351, CVE-2019-19051, CVE-2019-19056,
CVE-2019-19066, CVE-2019-19068, CVE-2019-19965, CVE-2019-20096, CVE-2019-5108,
CVE-2019-2101]
latest-version: kernel-4.4.0-1027.32
ubuntu-xenial:
CVE-2019-15220: An issue was discovered in the Linux kernel before 5.2.1. There
is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c
driver.
CVE-2019-15221: An issue was discovered in the Linux kernel before 5.1.17. There
is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c
driver.
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause
a denial of service because of unrestricted resource consumption during the mapping
of guest memory, aka CID-6ef36ab967c7.
CVE-2019-19051: A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption), aka CID-6f3ef5c25cc7.
CVE-2019-19056: A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allows attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-db8fd2cde932.
CVE-2019-19066: A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.
CVE-2019-19068: A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-a2cdd07488e6.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-2101: 'In uvc_parse_standard_control of uvc_driver.c, there is a possible
out-of-bound read due to improper input validation. This could lead to local information
disclosure with no additional execution privileges needed. User interaction is
not needed for exploitation. Product: Android. Versions: Android kernel. Android
ID: A-111760968.'
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
cvelist: [CVE-2019-15220, CVE-2019-15221, CVE-2019-17351, CVE-2019-19051, CVE-2019-19056,
CVE-2019-19066, CVE-2019-19068, CVE-2019-19965, CVE-2019-20096, CVE-2019-5108,
CVE-2019-2101]
latest-version: kernel-4.4.0-174.204
ubuntu-trusty-lts-xenial-aws:
CVE-2019-15220: An issue was discovered in the Linux kernel before 5.2.1. There
is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c
driver.
CVE-2019-15221: An issue was discovered in the Linux kernel before 5.1.17. There
is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c
driver.
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause
a denial of service because of unrestricted resource consumption during the mapping
of guest memory, aka CID-6ef36ab967c7.
CVE-2019-19051: A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption), aka CID-6f3ef5c25cc7.
CVE-2019-19056: A memory leak in the mwifiex_pcie_alloc_cmdrsp_buf() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allows attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-db8fd2cde932.
CVE-2019-19066: A memory leak in the bfad_im_get_stats() function in drivers/scsi/bfa/bfad_attr.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering bfa_port_get_stats() failures, aka CID-0e62395da2bd.
CVE-2019-19068: A memory leak in the rtl8xxxu_submit_int_urb() function in drivers/net/wireless/realtek/rtl8xxxu/rtl8xxxu_core.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-a2cdd07488e6.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-20096: In the Linux kernel before 5.1, there is a memory leak in __feat_register_sp()
in net/dccp/feat.c, which may cause denial of service, aka CID-1d3ff0950e2b.
CVE-2019-2101: 'In uvc_parse_standard_control of uvc_driver.c, there is a possible
out-of-bound read due to improper input validation. This could lead to local information
disclosure with no additional execution privileges needed. User interaction is
not needed for exploitation. Product: Android. Versions: Android kernel. Android
ID: A-111760968.'
CVE-2019-5108: An exploitable denial-of-service vulnerability exists in the Linux
kernel prior to mainline 5.3. An attacker could exploit this vulnerability by
triggering AP to send IAPP location updates for stations before the required authentication
process has completed. This could lead to different denial-of-service scenarios,
either by causing CAM table attacks, or by leading to traffic flapping if faking
already existing clients in other nearby APs of the same wireless infrastructure.
An attacker can forge Authentication and Association Request packets to trigger
this vulnerability.
cvelist: [CVE-2019-15220, CVE-2019-15221, CVE-2019-17351, CVE-2019-19051, CVE-2019-19056,
CVE-2019-19066, CVE-2019-19068, CVE-2019-19965, CVE-2019-20096, CVE-2019-5108,
CVE-2019-2101]
latest-version: kernel-4.4.0-1037.40

KernelCare

unread,
Feb 27, 2020, 2:00:10 AM2/27/20
to kernelca...@googlegroups.com
Dear Customers,

KernelCare prepared security updates for your system.
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.
You can manually update the server by running:

/usr/bin/kcarectl --update

Changelog:

ubuntu-bionic-azure:
CVE-2019-15099: drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through
5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-16229: drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14
does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel
5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer
dereference.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18786: In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized
in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could
cause a memory disclosure problem.
CVE-2019-18811: A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c
in the Linux kernel through 5.3.9 allows attackers to cause a denial of service
(memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380358b1.
CVE-2019-19050: A memory leak in the crypto_reportstat() function in crypto/crypto_user_stat.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_reportstat_alg() failures, aka CID-c03b04dcdba1.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption), aka CID-3f9361695113.
CVE-2019-19071: A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19077: A memory leak in the bnxt_re_create_srq() function in drivers/infiniband/hw/bnxt_re/ib_verbs.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering copy to udata failures, aka CID-4a9d46a9fe14.
CVE-2019-19078: A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
CVE-2019-19082: Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption).
CVE-2019-19241: In the Linux kernel before 5.4.2, the io_uring feature leads to
requests that inadvertently have UID 0 and full capabilities, aka CID-181e448d8709.
This is related to fs/io-wq.c, fs/io_uring.c, and net/socket.c. For example, an
attacker can bypass intended restrictions on adding an IPv4 address to the loopback
interface. This occurs because IORING_OP_SENDMSG operations, although requested
in the context of an unprivileged user, are sometimes performed by a kernel worker
thread without considering that context.
CVE-2019-19252: vcs_write in drivers/tty/vt/vc_screen.c in the Linux kernel through
5.3.13 does not prevent write access to vcsu devices, aka CID-0c9acb1af77a.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
CVE-2019-19602: fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the
Linux kernel before 5.4.2, when GCC 9 is used, allows context-dependent attackers
to cause a denial of service (memory corruption) or possibly have unspecified
other impact because of incorrect fpu_fpregs_owner_ctx caching, as demonstrated
by mishandling of signal-based non-cooperative preemption in Go 1.14 prereleases
on amd64, aka CID-59c4bd853abc.
CVE-2019-19767: The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize,
as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry,
related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVE-2019-19947: In the Linux kernel through 5.4.6, there are information leaks of
uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c
driver, aka CID-da2311a6385c.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
cvelist: [CVE-2019-15099, CVE-2019-15291, CVE-2019-16229, CVE-2019-16232, CVE-2019-18683,
CVE-2019-18786, CVE-2019-18811, CVE-2019-19050, CVE-2019-19057, CVE-2019-19062,
CVE-2019-19063, CVE-2019-19071, CVE-2019-19077, CVE-2019-19078, CVE-2019-19082,
CVE-2019-19252, CVE-2019-19332, CVE-2019-19602, CVE-2019-19767, CVE-2019-19947,
CVE-2019-19965, CVE-2019-19241]
latest-version: kernel-5.0.0-1032.34
ubuntu-bionic-hwe:
CVE-2019-15099: drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through
5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-16229: drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14
does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel
5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer
dereference.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18786: In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized
in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could
cause a memory disclosure problem.
CVE-2019-18811: A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c
in the Linux kernel through 5.3.9 allows attackers to cause a denial of service
(memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380358b1.
CVE-2019-19050: A memory leak in the crypto_reportstat() function in crypto/crypto_user_stat.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_reportstat_alg() failures, aka CID-c03b04dcdba1.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption), aka CID-3f9361695113.
CVE-2019-19071: A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19077: A memory leak in the bnxt_re_create_srq() function in drivers/infiniband/hw/bnxt_re/ib_verbs.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering copy to udata failures, aka CID-4a9d46a9fe14.
CVE-2019-19078: A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
CVE-2019-19082: Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption).
CVE-2019-19241: In the Linux kernel before 5.4.2, the io_uring feature leads to
requests that inadvertently have UID 0 and full capabilities, aka CID-181e448d8709.
This is related to fs/io-wq.c, fs/io_uring.c, and net/socket.c. For example, an
attacker can bypass intended restrictions on adding an IPv4 address to the loopback
interface. This occurs because IORING_OP_SENDMSG operations, although requested
in the context of an unprivileged user, are sometimes performed by a kernel worker
thread without considering that context.
CVE-2019-19252: vcs_write in drivers/tty/vt/vc_screen.c in the Linux kernel through
5.3.13 does not prevent write access to vcsu devices, aka CID-0c9acb1af77a.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
CVE-2019-19602: fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the
Linux kernel before 5.4.2, when GCC 9 is used, allows context-dependent attackers
to cause a denial of service (memory corruption) or possibly have unspecified
other impact because of incorrect fpu_fpregs_owner_ctx caching, as demonstrated
by mishandling of signal-based non-cooperative preemption in Go 1.14 prereleases
on amd64, aka CID-59c4bd853abc.
CVE-2019-19767: The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize,
as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry,
related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVE-2019-19947: In the Linux kernel through 5.4.6, there are information leaks of
uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c
driver, aka CID-da2311a6385c.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
cvelist: [CVE-2019-15099, CVE-2019-15291, CVE-2019-16229, CVE-2019-16232, CVE-2019-18683,
CVE-2019-18786, CVE-2019-18811, CVE-2019-19050, CVE-2019-19057, CVE-2019-19062,
CVE-2019-19063, CVE-2019-19071, CVE-2019-19077, CVE-2019-19078, CVE-2019-19082,
CVE-2019-19252, CVE-2019-19332, CVE-2019-19602, CVE-2019-19767, CVE-2019-19947,
CVE-2019-19965, CVE-2019-19241]
latest-version: kernel-5.3.0-40.32~18.04.1
ubuntu-bionic-gcp:
CVE-2019-15099: drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through
5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-16229: drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14
does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel
5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer
dereference.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18786: In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized
in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could
cause a memory disclosure problem.
CVE-2019-18811: A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c
in the Linux kernel through 5.3.9 allows attackers to cause a denial of service
(memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380358b1.
CVE-2019-19050: A memory leak in the crypto_reportstat() function in crypto/crypto_user_stat.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_reportstat_alg() failures, aka CID-c03b04dcdba1.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption), aka CID-3f9361695113.
CVE-2019-19071: A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19077: A memory leak in the bnxt_re_create_srq() function in drivers/infiniband/hw/bnxt_re/ib_verbs.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering copy to udata failures, aka CID-4a9d46a9fe14.
CVE-2019-19078: A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
CVE-2019-19082: Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption).
CVE-2019-19241: In the Linux kernel before 5.4.2, the io_uring feature leads to
requests that inadvertently have UID 0 and full capabilities, aka CID-181e448d8709.
This is related to fs/io-wq.c, fs/io_uring.c, and net/socket.c. For example, an
attacker can bypass intended restrictions on adding an IPv4 address to the loopback
interface. This occurs because IORING_OP_SENDMSG operations, although requested
in the context of an unprivileged user, are sometimes performed by a kernel worker
thread without considering that context.
CVE-2019-19252: vcs_write in drivers/tty/vt/vc_screen.c in the Linux kernel through
5.3.13 does not prevent write access to vcsu devices, aka CID-0c9acb1af77a.
CVE-2019-19332: An out-of-bounds memory write issue was found in the Linux Kernel,
version 3.13 through 5.4, in the way the Linux kernel's KVM hypervisor handled
the 'KVM_GET_EMULATED_CPUID' ioctl(2) request to get CPUID features emulated by
the KVM hypervisor. A user or process able to access the '/dev/kvm' device could
use this flaw to crash the system, resulting in a denial of service.
CVE-2019-19602: fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the
Linux kernel before 5.4.2, when GCC 9 is used, allows context-dependent attackers
to cause a denial of service (memory corruption) or possibly have unspecified
other impact because of incorrect fpu_fpregs_owner_ctx caching, as demonstrated
by mishandling of signal-based non-cooperative preemption in Go 1.14 prereleases
on amd64, aka CID-59c4bd853abc.
CVE-2019-19767: The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize,
as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry,
related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVE-2019-19947: In the Linux kernel through 5.4.6, there are information leaks of
uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c
driver, aka CID-da2311a6385c.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
cvelist: [CVE-2019-15099, CVE-2019-15291, CVE-2019-16229, CVE-2019-16232, CVE-2019-18683,
CVE-2019-18786, CVE-2019-18811, CVE-2019-19050, CVE-2019-19057, CVE-2019-19062,
CVE-2019-19063, CVE-2019-19071, CVE-2019-19077, CVE-2019-19078, CVE-2019-19082,
CVE-2019-19252, CVE-2019-19332, CVE-2019-19602, CVE-2019-19767, CVE-2019-19947,
CVE-2019-19965, CVE-2019-19241]
latest-version: kernel-5.0.0-1026.27~18.04.1
Reply all
Reply to author
Forward
0 new messages