KernelCare update was released

1 view
Skip to first unread message

KernelCare

unread,
Dec 9, 2019, 7:04:05 AM12/9/19
to kernelca...@googlegroups.com
Dear Customers,

KernelCare prepared security updates for your system.
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.
You can manually update the server by running:

/usr/bin/kcarectl --update

Changelog:

ubuntu-xenial-lts-bionic-azure:
CVE-2016-10723: Since the page allocator does not yield CPU resources to the owner
of the oom_lock mutex, a local unprivileged user can trivially lock up the system
forever by wasting CPU resources from the page allocator (e.g., via concurrent
page fault events) when the global OOM killer is invoked.
CVE-2018-20669: An issue where a provided address with access_ok() is not checked
was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c
in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL
function call to overwrite arbitrary kernel memory, resulting in a Denial of Service
or privilege escalation.
CVE-2018-20976: An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel
before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
CVE-2019-11486: The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c
in the Linux kernel before 5.0.8 has multiple race conditions.
CVE-2019-16413: The 9p filesystem did not protect i_size_write() properly, which
causes an i_size_read() infinite loop and denial of service on SMP systems.
CVE-2019-16994: In the Linux kernel before 5.0, a memory leak exists in sit_init_net()
in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev,
which may cause denial of service.
CVE-2019-16995: In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize()
in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial
of service.
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause
a denial of service because of unrestricted resource consumption during the mapping
of guest memory, aka CID-6ef36ab967c7.
CVE-2019-5489: The mincore() implementation in mm/mincore.c in the Linux kernel
through 4.19.13 allowed local attackers to observe page cache access patterns
of other processes on the same system, potentially allowing sniffing of secret
information.
cvelist: [CVE-2016-10723, CVE-2018-20669, CVE-2019-16413, CVE-2019-5489, CVE-2019-17351,
CVE-2019-16994, CVE-2019-16995, CVE-2019-11486, CVE-2018-20976]
latest-version: kernel-4.15.0-1061.66
ubuntu-xenial-lts-bionic-gcp:
CVE-2016-10723: Since the page allocator does not yield CPU resources to the owner
of the oom_lock mutex, a local unprivileged user can trivially lock up the system
forever by wasting CPU resources from the page allocator (e.g., via concurrent
page fault events) when the global OOM killer is invoked.
CVE-2018-20669: An issue where a provided address with access_ok() is not checked
was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c
in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL
function call to overwrite arbitrary kernel memory, resulting in a Denial of Service
or privilege escalation.
CVE-2018-20976: An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel
before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
CVE-2019-11486: The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c
in the Linux kernel before 5.0.8 has multiple race conditions.
CVE-2019-16413: The 9p filesystem did not protect i_size_write() properly, which
causes an i_size_read() infinite loop and denial of service on SMP systems.
CVE-2019-16994: In the Linux kernel before 5.0, a memory leak exists in sit_init_net()
in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev,
which may cause denial of service.
CVE-2019-16995: In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize()
in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial
of service.
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause
a denial of service because of unrestricted resource consumption during the mapping
of guest memory, aka CID-6ef36ab967c7.
CVE-2019-5489: The mincore() implementation in mm/mincore.c in the Linux kernel
through 4.19.13 allowed local attackers to observe page cache access patterns
of other processes on the same system, potentially allowing sniffing of secret
information.
cvelist: [CVE-2016-10723, CVE-2018-20669, CVE-2019-16413, CVE-2019-5489, CVE-2019-17351,
CVE-2019-16994, CVE-2019-16995, CVE-2019-11486, CVE-2018-20976]
latest-version: kernel-4.15.0-1040.42~16.04.1
ubuntu-bionic-gcp:
CVE-2016-10723: Since the page allocator does not yield CPU resources to the owner
of the oom_lock mutex, a local unprivileged user can trivially lock up the system
forever by wasting CPU resources from the page allocator (e.g., via concurrent
page fault events) when the global OOM killer is invoked.
CVE-2018-20669: An issue where a provided address with access_ok() is not checked
was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c
in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL
function call to overwrite arbitrary kernel memory, resulting in a Denial of Service
or privilege escalation.
CVE-2018-20976: An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel
before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
CVE-2019-0136: Insufficient access control in the Intel(R) PROSet/Wireless WiFi
Software driver before version 21.10 may allow an unauthenticated user to potentially
enable denial of service via adjacent access.
CVE-2019-10207: A flaw was found in the Linux kernel's Bluetooth implementation
of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker
with local access and write permissions to the Bluetooth hardware could use this
flaw to issue a specially crafted ioctl function call and cause the system to
crash.
CVE-2019-11486: The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c
in the Linux kernel before 5.0.8 has multiple race conditions.
CVE-2019-13631: In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in
the Linux kernel through 5.2.1, a malicious USB device can send an HID report
that triggers an out-of-bounds write during generation of debugging messages.
CVE-2019-15090: An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux
kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds
read.
CVE-2019-15117: parse_audio_mixer_unit in sound/usb/mixer.c in the Linux kernel
through 5.2.9 mishandles a short descriptor, leading to out-of-bounds memory access.
CVE-2019-15118: check_input_term in sound/usb/mixer.c in the Linux kernel through
5.2.9 mishandles recursion, leading to kernel stack exhaustion.
CVE-2019-15211: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c
driver because drivers/media/radio/radio-raremono.c does not properly allocate
memory.
CVE-2019-15212: An issue was discovered in the Linux kernel before 5.1.8. There
is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c
driver.
CVE-2019-15215: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/usb/cpia2/cpia2_usb.c
driver.
CVE-2019-15217: An issue was discovered in the Linux kernel before 5.2.3. There
is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c
driver.
CVE-2019-15218: An issue was discovered in the Linux kernel before 5.1.8. There
is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c
driver.
CVE-2019-15220: An issue was discovered in the Linux kernel before 5.2.1. There
is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c
driver.
CVE-2019-15221: An issue was discovered in the Linux kernel before 5.1.17. There
is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c
driver.
CVE-2019-15223: An issue was discovered in the Linux kernel before 5.1.8. There
is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/driver.c
driver.
CVE-2019-15538: An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c
in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on
account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the
ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local
DoS attack vector, but it might result as well in remote DoS if the XFS filesystem
is exported for instance via NFS.
CVE-2019-15925: An issue was discovered in the Linux kernel before 5.2.3. An out
of bounds access exists in the function hclge_tm_schd_mode_vnet_base_cfg in the
file drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_tm.c.
CVE-2019-15926: An issue was discovered in the Linux kernel before 5.2.3. Out of
bounds access exists in the functions ath6kl_wmi_pstream_timeout_event_rx and
ath6kl_wmi_cac_event_rx in the file drivers/net/wireless/ath/ath6kl/wmi.c.
CVE-2019-16413: The 9p filesystem did not protect i_size_write() properly, which
causes an i_size_read() infinite loop and denial of service on SMP systems.
CVE-2019-16994: In the Linux kernel before 5.0, a memory leak exists in sit_init_net()
in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev,
which may cause denial of service.
CVE-2019-16995: In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize()
in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial
of service.
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause
a denial of service because of unrestricted resource consumption during the mapping
of guest memory, aka CID-6ef36ab967c7.
CVE-2019-5489: The mincore() implementation in mm/mincore.c in the Linux kernel
through 4.19.13 allowed local attackers to observe page cache access patterns
of other processes on the same system, potentially allowing sniffing of secret
information.
CVE-2019-9506: The Bluetooth BR/EDR specification up to and including version 5.1
permits sufficiently low encryption key length and does not prevent an attacker
from influencing the key length negotiation. This allows practical brute-force
attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext
without the victim noticing.
cvelist: [CVE-2016-10723, CVE-2018-20669, CVE-2019-16413, CVE-2019-5489, CVE-2019-17351,
CVE-2019-16994, CVE-2019-16995, CVE-2019-11486, CVE-2018-20976, CVE-2019-10207,
CVE-2019-15118, CVE-2019-15217, CVE-2019-0136, CVE-2019-13631, CVE-2019-15090,
CVE-2019-15117, CVE-2019-15211, CVE-2019-15212, CVE-2019-15215, CVE-2019-15217,
CVE-2019-15218, CVE-2019-15220, CVE-2019-15221, CVE-2019-15223, CVE-2019-15538,
CVE-2019-15925, CVE-2019-15926, CVE-2019-9506]
latest-version: kernel-5.0.0-1026.27~18.04.1
ubuntu-bionic:
CVE-2016-10723: Since the page allocator does not yield CPU resources to the owner
of the oom_lock mutex, a local unprivileged user can trivially lock up the system
forever by wasting CPU resources from the page allocator (e.g., via concurrent
page fault events) when the global OOM killer is invoked.
CVE-2018-20669: An issue where a provided address with access_ok() is not checked
was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c
in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL
function call to overwrite arbitrary kernel memory, resulting in a Denial of Service
or privilege escalation.
CVE-2018-20976: An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel
before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
CVE-2019-11486: The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c
in the Linux kernel before 5.0.8 has multiple race conditions.
CVE-2019-16413: The 9p filesystem did not protect i_size_write() properly, which
causes an i_size_read() infinite loop and denial of service on SMP systems.
CVE-2019-16994: In the Linux kernel before 5.0, a memory leak exists in sit_init_net()
in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev,
which may cause denial of service.
CVE-2019-16995: In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize()
in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial
of service.
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause
a denial of service because of unrestricted resource consumption during the mapping
of guest memory, aka CID-6ef36ab967c7.
CVE-2019-5489: The mincore() implementation in mm/mincore.c in the Linux kernel
through 4.19.13 allowed local attackers to observe page cache access patterns
of other processes on the same system, potentially allowing sniffing of secret
information.
cvelist: [CVE-2016-10723, CVE-2018-20669, CVE-2019-16413, CVE-2019-5489, CVE-2019-17351,
CVE-2019-16994, CVE-2019-16995, CVE-2019-11486, CVE-2018-20976]
latest-version: kernel-4.15.0-72.81
ubuntu-bionic-hwe:
CVE-2016-10723: Since the page allocator does not yield CPU resources to the owner
of the oom_lock mutex, a local unprivileged user can trivially lock up the system
forever by wasting CPU resources from the page allocator (e.g., via concurrent
page fault events) when the global OOM killer is invoked.
CVE-2018-20669: An issue where a provided address with access_ok() is not checked
was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c
in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL
function call to overwrite arbitrary kernel memory, resulting in a Denial of Service
or privilege escalation.
CVE-2018-20976: An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel
before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
CVE-2019-0136: Insufficient access control in the Intel(R) PROSet/Wireless WiFi
Software driver before version 21.10 may allow an unauthenticated user to potentially
enable denial of service via adjacent access.
CVE-2019-10207: A flaw was found in the Linux kernel's Bluetooth implementation
of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker
with local access and write permissions to the Bluetooth hardware could use this
flaw to issue a specially crafted ioctl function call and cause the system to
crash.
CVE-2019-11486: The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c
in the Linux kernel before 5.0.8 has multiple race conditions.
CVE-2019-13631: In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in
the Linux kernel through 5.2.1, a malicious USB device can send an HID report
that triggers an out-of-bounds write during generation of debugging messages.
CVE-2019-15090: An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux
kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds
read.
CVE-2019-15117: parse_audio_mixer_unit in sound/usb/mixer.c in the Linux kernel
through 5.2.9 mishandles a short descriptor, leading to out-of-bounds memory access.
CVE-2019-15118: check_input_term in sound/usb/mixer.c in the Linux kernel through
5.2.9 mishandles recursion, leading to kernel stack exhaustion.
CVE-2019-15211: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c
driver because drivers/media/radio/radio-raremono.c does not properly allocate
memory.
CVE-2019-15212: An issue was discovered in the Linux kernel before 5.1.8. There
is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c
driver.
CVE-2019-15215: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/usb/cpia2/cpia2_usb.c
driver.
CVE-2019-15217: An issue was discovered in the Linux kernel before 5.2.3. There
is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c
driver.
CVE-2019-15218: An issue was discovered in the Linux kernel before 5.1.8. There
is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c
driver.
CVE-2019-15220: An issue was discovered in the Linux kernel before 5.2.1. There
is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c
driver.
CVE-2019-15221: An issue was discovered in the Linux kernel before 5.1.17. There
is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c
driver.
CVE-2019-15223: An issue was discovered in the Linux kernel before 5.1.8. There
is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/driver.c
driver.
CVE-2019-15538: An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c
in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on
account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the
ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local
DoS attack vector, but it might result as well in remote DoS if the XFS filesystem
is exported for instance via NFS.
CVE-2019-15925: An issue was discovered in the Linux kernel before 5.2.3. An out
of bounds access exists in the function hclge_tm_schd_mode_vnet_base_cfg in the
file drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_tm.c.
CVE-2019-15926: An issue was discovered in the Linux kernel before 5.2.3. Out of
bounds access exists in the functions ath6kl_wmi_pstream_timeout_event_rx and
ath6kl_wmi_cac_event_rx in the file drivers/net/wireless/ath/ath6kl/wmi.c.
CVE-2019-16413: The 9p filesystem did not protect i_size_write() properly, which
causes an i_size_read() infinite loop and denial of service on SMP systems.
CVE-2019-16994: In the Linux kernel before 5.0, a memory leak exists in sit_init_net()
in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev,
which may cause denial of service.
CVE-2019-16995: In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize()
in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial
of service.
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause
a denial of service because of unrestricted resource consumption during the mapping
of guest memory, aka CID-6ef36ab967c7.
CVE-2019-5489: The mincore() implementation in mm/mincore.c in the Linux kernel
through 4.19.13 allowed local attackers to observe page cache access patterns
of other processes on the same system, potentially allowing sniffing of secret
information.
CVE-2019-9506: The Bluetooth BR/EDR specification up to and including version 5.1
permits sufficiently low encryption key length and does not prevent an attacker
from influencing the key length negotiation. This allows practical brute-force
attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext
without the victim noticing.
cvelist: [CVE-2016-10723, CVE-2018-20669, CVE-2019-16413, CVE-2019-5489, CVE-2019-17351,
CVE-2019-16994, CVE-2019-16995, CVE-2019-11486, CVE-2018-20976, CVE-2019-10207,
CVE-2019-15118, CVE-2019-15217, CVE-2019-0136, CVE-2019-13631, CVE-2019-15090,
CVE-2019-15117, CVE-2019-15211, CVE-2019-15212, CVE-2019-15215, CVE-2019-15217,
CVE-2019-15218, CVE-2019-15220, CVE-2019-15221, CVE-2019-15223, CVE-2019-15538,
CVE-2019-15925, CVE-2019-15926, CVE-2019-9506]
latest-version: kernel-5.0.0-37.40~18.04.1
ubuntu-xenial-lts-bionic:
CVE-2016-10723: Since the page allocator does not yield CPU resources to the owner
of the oom_lock mutex, a local unprivileged user can trivially lock up the system
forever by wasting CPU resources from the page allocator (e.g., via concurrent
page fault events) when the global OOM killer is invoked.
CVE-2018-20669: An issue where a provided address with access_ok() is not checked
was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c
in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL
function call to overwrite arbitrary kernel memory, resulting in a Denial of Service
or privilege escalation.
CVE-2018-20976: An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel
before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
CVE-2019-11486: The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c
in the Linux kernel before 5.0.8 has multiple race conditions.
CVE-2019-16413: The 9p filesystem did not protect i_size_write() properly, which
causes an i_size_read() infinite loop and denial of service on SMP systems.
CVE-2019-16994: In the Linux kernel before 5.0, a memory leak exists in sit_init_net()
in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev,
which may cause denial of service.
CVE-2019-16995: In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize()
in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial
of service.
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause
a denial of service because of unrestricted resource consumption during the mapping
of guest memory, aka CID-6ef36ab967c7.
CVE-2019-5489: The mincore() implementation in mm/mincore.c in the Linux kernel
through 4.19.13 allowed local attackers to observe page cache access patterns
of other processes on the same system, potentially allowing sniffing of secret
information.
cvelist: [CVE-2016-10723, CVE-2018-20669, CVE-2019-16413, CVE-2019-5489, CVE-2019-17351,
CVE-2019-16994, CVE-2019-16995, CVE-2019-11486, CVE-2018-20976]
latest-version: kernel-4.15.0-72.81~16.04.1
ubuntu-bionic-azure:
CVE-2016-10723: Since the page allocator does not yield CPU resources to the owner
of the oom_lock mutex, a local unprivileged user can trivially lock up the system
forever by wasting CPU resources from the page allocator (e.g., via concurrent
page fault events) when the global OOM killer is invoked.
CVE-2018-20669: An issue where a provided address with access_ok() is not checked
was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_execbuffer.c
in the Linux kernel through 4.19.13. A local attacker can craft a malicious IOCTL
function call to overwrite arbitrary kernel memory, resulting in a Denial of Service
or privilege escalation.
CVE-2018-20976: An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel
before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
CVE-2019-0136: Insufficient access control in the Intel(R) PROSet/Wireless WiFi
Software driver before version 21.10 may allow an unauthenticated user to potentially
enable denial of service via adjacent access.
CVE-2019-10207: A flaw was found in the Linux kernel's Bluetooth implementation
of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker
with local access and write permissions to the Bluetooth hardware could use this
flaw to issue a specially crafted ioctl function call and cause the system to
crash.
CVE-2019-11486: The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c
in the Linux kernel before 5.0.8 has multiple race conditions.
CVE-2019-13631: In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in
the Linux kernel through 5.2.1, a malicious USB device can send an HID report
that triggers an out-of-bounds write during generation of debugging messages.
CVE-2019-15090: An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux
kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds
read.
CVE-2019-15117: parse_audio_mixer_unit in sound/usb/mixer.c in the Linux kernel
through 5.2.9 mishandles a short descriptor, leading to out-of-bounds memory access.
CVE-2019-15118: check_input_term in sound/usb/mixer.c in the Linux kernel through
5.2.9 mishandles recursion, leading to kernel stack exhaustion.
CVE-2019-15211: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c
driver because drivers/media/radio/radio-raremono.c does not properly allocate
memory.
CVE-2019-15212: An issue was discovered in the Linux kernel before 5.1.8. There
is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c
driver.
CVE-2019-15215: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/usb/cpia2/cpia2_usb.c
driver.
CVE-2019-15217: An issue was discovered in the Linux kernel before 5.2.3. There
is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c
driver.
CVE-2019-15218: An issue was discovered in the Linux kernel before 5.1.8. There
is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c
driver.
CVE-2019-15220: An issue was discovered in the Linux kernel before 5.2.1. There
is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c
driver.
CVE-2019-15221: An issue was discovered in the Linux kernel before 5.1.17. There
is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c
driver.
CVE-2019-15223: An issue was discovered in the Linux kernel before 5.1.8. There
is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/driver.c
driver.
CVE-2019-15538: An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c
in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on
account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the
ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local
DoS attack vector, but it might result as well in remote DoS if the XFS filesystem
is exported for instance via NFS.
CVE-2019-15925: An issue was discovered in the Linux kernel before 5.2.3. An out
of bounds access exists in the function hclge_tm_schd_mode_vnet_base_cfg in the
file drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_tm.c.
CVE-2019-15926: An issue was discovered in the Linux kernel before 5.2.3. Out of
bounds access exists in the functions ath6kl_wmi_pstream_timeout_event_rx and
ath6kl_wmi_cac_event_rx in the file drivers/net/wireless/ath/ath6kl/wmi.c.
CVE-2019-16413: The 9p filesystem did not protect i_size_write() properly, which
causes an i_size_read() infinite loop and denial of service on SMP systems.
CVE-2019-16994: In the Linux kernel before 5.0, a memory leak exists in sit_init_net()
in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel_dev,
which may cause denial of service.
CVE-2019-16995: In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize()
in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which may cause denial
of service.
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause
a denial of service because of unrestricted resource consumption during the mapping
of guest memory, aka CID-6ef36ab967c7.
CVE-2019-5489: The mincore() implementation in mm/mincore.c in the Linux kernel
through 4.19.13 allowed local attackers to observe page cache access patterns
of other processes on the same system, potentially allowing sniffing of secret
information.
CVE-2019-9506: The Bluetooth BR/EDR specification up to and including version 5.1
permits sufficiently low encryption key length and does not prevent an attacker
from influencing the key length negotiation. This allows practical brute-force
attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext
without the victim noticing.
cvelist: [CVE-2016-10723, CVE-2018-20669, CVE-2019-16413, CVE-2019-5489, CVE-2019-17351,
CVE-2019-16994, CVE-2019-16995, CVE-2019-11486, CVE-2018-20976, CVE-2019-10207,
CVE-2019-15118, CVE-2019-15217, CVE-2019-0136, CVE-2019-13631, CVE-2019-15090,
CVE-2019-15117, CVE-2019-15211, CVE-2019-15212, CVE-2019-15215, CVE-2019-15217,
CVE-2019-15218, CVE-2019-15220, CVE-2019-15221, CVE-2019-15223, CVE-2019-15538,
CVE-2019-15925, CVE-2019-15926, CVE-2019-9506]
latest-version: kernel-5.0.0-1023.24~18.04.1

KernelCare

unread,
Dec 11, 2019, 4:13:06 AM12/11/19
to kernelca...@googlegroups.com
Dear Customers,

KernelCare prepared security updates for your system.
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.
You can manually update the server by running:

/usr/bin/kcarectl --update

Changelog:

ubuntu-xenial-lts-bionic-aws:
CVE-2016-10723: Since the page allocator does not yield CPU resources to the owner
of the oom_lock mutex, a local unprivileged user can trivially lock up the sys
CVE-2018-20669: An issue where a provided address with access_ok() is not checked
was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_e
CVE-2018-20976: An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel
before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
CVE-2019-11486: The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c
in the Linux kernel before 5.0.8 has multiple race conditions.
CVE-2019-16413: The 9p filesystem did not protect i_size_write() properly, which
causes an i_size_read() infinite loop and denial of service on SMP systems.
CVE-2019-16994: In the Linux kernel before 5.0, a memory leak exists in sit_init_net()
in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel
CVE-2019-16995: In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize()
in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which ma
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to caus
CVE-2019-5489: The mincore() implementation in mm/mincore.c in the Linux kernel
through 4.19.13 allowed local attackers to observe page cache access patterns
of
cvelist: [CVE-2016-10723, CVE-2018-20669, CVE-2019-16413, CVE-2019-5489, CVE-2019-17351,
CVE-2019-16994, CVE-2019-16995, CVE-2019-11486, CVE-2018-20976]
latest-version: kernel-4.15.0-1056.58~16.04.1
ubuntu-bionic-aws:
CVE-2016-10723: Since the page allocator does not yield CPU resources to the owner
of the oom_lock mutex, a local unprivileged user can trivially lock up the sys
CVE-2018-20669: An issue where a provided address with access_ok() is not checked
was discovered in i915_gem_execbuffer2_ioctl in drivers/gpu/drm/i915/i915_gem_e
CVE-2018-20976: An issue was discovered in fs/xfs/xfs_super.c in the Linux kernel
before 4.18. A use after free exists, related to xfs_fs_fill_super failure.
CVE-2019-11486: The Siemens R3964 line discipline driver in drivers/tty/n_r3964.c
in the Linux kernel before 5.0.8 has multiple race conditions.
CVE-2019-16413: The 9p filesystem did not protect i_size_write() properly, which
causes an i_size_read() infinite loop and denial of service on SMP systems.
CVE-2019-16994: In the Linux kernel before 5.0, a memory leak exists in sit_init_net()
in net/ipv6/sit.c when register_netdev() fails to register sitn->fb_tunnel
CVE-2019-16995: In the Linux kernel before 5.0.3, a memory leak exits in hsr_dev_finalize()
in net/hsr/hsr_device.c if hsr_add_port fails to add a port, which ma
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to caus
CVE-2019-5489: The mincore() implementation in mm/mincore.c in the Linux kernel
through 4.19.13 allowed local attackers to observe page cache access patterns
of
cvelist: [CVE-2016-10723, CVE-2018-20669, CVE-2019-16413, CVE-2019-5489, CVE-2019-17351,
CVE-2019-16994, CVE-2019-16995, CVE-2019-11486, CVE-2018-20976]
latest-version: kernel-4.15.0-1056.58

KernelCare

unread,
Dec 13, 2019, 2:47:05 AM12/13/19
to kernelca...@googlegroups.com
Dear Customers,

KernelCare prepared security updates for your system.
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.
You can manually update the server by running:

/usr/bin/kcarectl --update

Changelog:

ubuntu-xenial-lts-bionic-aws:
CVE-2018-12207: Improper invalidation for page table updates by a virtual guest
operating system for multiple Intel(R) Processors may allow an authenticated user
to potentially enable denial of service of the host system via local access.
cvelist: [CVE-2018-12207]
latest-version: kernel-4.15.0-1056.58~16.04.1
ubuntu-bionic:
CVE-2018-12207: Improper invalidation for page table updates by a virtual guest
operating system for multiple Intel(R) Processors may allow an authenticated user
to potentially enable denial of service of the host system via local access.
cvelist: [CVE-2018-12207]
latest-version: kernel-4.15.0-72.81
ubuntu-xenial-lts-bionic-azure:
CVE-2018-12207: Improper invalidation for page table updates by a virtual guest
operating system for multiple Intel(R) Processors may allow an authenticated user
to potentially enable denial of service of the host system via local access.
cvelist: [CVE-2018-12207]
latest-version: kernel-4.15.0-1061.66
ubuntu-xenial-lts-bionic-gcp:
CVE-2018-12207: Improper invalidation for page table updates by a virtual guest
operating system for multiple Intel(R) Processors may allow an authenticated user
to potentially enable denial of service of the host system via local access.
cvelist: [CVE-2018-12207]
latest-version: kernel-4.15.0-1040.42~16.04.1
ubuntu-bionic-gcp:
CVE-2018-12207: Improper invalidation for page table updates by a virtual guest
operating system for multiple Intel(R) Processors may allow an authenticated user
to potentially enable denial of service of the host system via local access.
cvelist: [CVE-2018-12207]
latest-version: kernel-5.0.0-1026.27~18.04.1
ubuntu-bionic-aws:
CVE-2018-12207: Improper invalidation for page table updates by a virtual guest
operating system for multiple Intel(R) Processors may allow an authenticated user
to potentially enable denial of service of the host system via local access.
cvelist: [CVE-2018-12207]
latest-version: kernel-4.15.0-1056.58
ubuntu-bionic-hwe:
CVE-2018-12207: Improper invalidation for page table updates by a virtual guest
operating system for multiple Intel(R) Processors may allow an authenticated user
to potentially enable denial of service of the host system via local access.
cvelist: [CVE-2018-12207]
latest-version: kernel-5.0.0-37.40~18.04.1
ubuntu-xenial-lts-bionic:
CVE-2018-12207: Improper invalidation for page table updates by a virtual guest
operating system for multiple Intel(R) Processors may allow an authenticated user
to potentially enable denial of service of the host system via local access.
cvelist: [CVE-2018-12207]
latest-version: kernel-4.15.0-72.81~16.04.1
ubuntu-bionic-azure:
CVE-2018-12207: Improper invalidation for page table updates by a virtual guest
operating system for multiple Intel(R) Processors may allow an authenticated user
to potentially enable denial of service of the host system via local access.
cvelist: [CVE-2018-12207]
latest-version: kernel-5.0.0-1027.29~18.04.1
Reply all
Reply to author
Forward
0 new messages