KernelCare update was released

2 views
Skip to first unread message

KernelCare

unread,
Mar 25, 2020, 6:33:08 AM3/25/20
to kernelca...@googlegroups.com
Dear Customers,

KernelCare prepared security updates for your system.
Systems with AUTO_UPDATE=True (DEFAULT) in /etc/sysconfig/kcare/kcare.conf will automatically update, and no action is needed for them.
You can manually update the server by running:

/usr/bin/kcarectl --update

Changelog:

pve-6:
CVE-2018-12207: Improper invalidation for page table updates by a virtual guest
operating system for multiple Intel(R) Processors may allow an authenticated user
to potentially enable denial of service of the host system via local access.
CVE-2019-0136: Insufficient access control in the Intel(R) PROSet/Wireless WiFi
Software driver before version 21.10 may allow an unauthenticated user to potentially
enable denial of service via adjacent access.
CVE-2019-0154: Insufficient access control in subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6 and E-2100 Processor Families
may allow an authenticated user to potentially enable denial of service via local
access.
CVE-2019-0155: Insufficient access control in a subsystem for Intel (R) processor
graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families;
Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R)
Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900
Series; Intel(R) Xeon(R) Processor E3-1500 v5 and v6, E-2100 and E-2200 Processor
Families; Intel(R) Graphics Driver for Windows before 26.20.100.6813 (DCH) or
26.20.100.6812 and before 21.20.x.5077 (aka15.45.5077), i915 Linux Driver for
Intel(R) Processor Graphics before versions 5.4-rc7, 5.3.11, 4.19.84, 4.14.154,
4.9.201, 4.4.201 may allow an authenticated user to potentially enable escalation
of privilege via local access.
CVE-2019-10207: A flaw was found in the Linux kernel's Bluetooth implementation
of UART, all versions kernel 3.x.x before 4.18.0 and kernel 5.x.x. An attacker
with local access and write permissions to the Bluetooth hardware could use this
flaw to issue a specially crafted ioctl function call and cause the system to
crash.
CVE-2019-10220: Linux kernel CIFS implementation, version 4.9.0 is vulnerable to
a relative paths injection in directory entry lists.
CVE-2019-13631: In parse_hid_report_descriptor in drivers/input/tablet/gtco.c in
the Linux kernel through 5.2.1, a malicious USB device can send an HID report
that triggers an out-of-bounds write during generation of debugging messages.
CVE-2019-14615: A flaw was found that allowed an attacker to view the state of on
GPU execution unit created by another user on the same system.
CVE-2019-14814: There is heap-based buffer overflow in Linux kernel, all versions
up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows
local users to cause a denial of service(system crash) or possibly execute arbitrary
code.
CVE-2019-14815: kernel is vulnerable to a None
CVE-2019-14816: There is heap-based buffer overflow in kernel, all versions up to,
excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local
users to cause a denial of service(system crash) or possibly execute arbitrary
code.
CVE-2019-14821: An out-of-bounds access issue was found in the Linux kernel, all
versions through 5.3, in the way Linux kernel's KVM hypervisor implements the
Coalesced MMIO write operation. It operates on an MMIO ring buffer 'struct kvm_coalesced_mmio'
object, wherein write indices 'ring->first' and 'ring->last' value could
be supplied by a host user-space process. An unprivileged host user or process
with access to '/dev/kvm' device could use this flaw to crash the host kernel,
resulting in a denial of service or potentially escalating privileges on the system.
CVE-2019-14835: A buffer overflow flaw was found, in versions from 2.6.34 to 5.2.x,
in the way Linux kernel's vhost functionality that translates virtqueue buffers
to IOVs, logged the buffer descriptors during migration. A privileged guest user
able to pass descriptors with invalid length to the host when migration is underway,
could use this flaw to increase their privileges on the host.
CVE-2019-14895: A heap-based buffer overflow was discovered in the Linux kernel,
all versions 3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The flaw
could occur when the station attempts a connection negotiation during the handling
of the remote devices country settings. This could allow the remote device to
cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-14897: A stack-based buffer overflow was found in the Linux kernel, version
kernel-2.6.32, in Marvell WiFi chip driver. An attacker is able to cause a denial
of service (system crash) or, possibly execute arbitrary code, when a STA works
in IBSS mode (allows connecting stations together without the use of an AP) and
connects to another STA.
CVE-2019-14901: A heap overflow flaw was found in the Linux kernel, all versions
3.x.x and 4.x.x before 4.18.0, in Marvell WiFi chip driver. The vulnerability
allows a remote attacker to cause a system crash, resulting in a denial of service,
or execute arbitrary code. The highest threat with this vulnerability is with
the availability of the system. If code execution occurs, the code will run with
the permissions of root. This will affect both confidentiality and integrity of
files on the system.
CVE-2019-15090: An issue was discovered in drivers/scsi/qedi/qedi_dbg.c in the Linux
kernel before 5.1.12. In the qedi_dbg_* family of functions, there is an out-of-bounds
read.
CVE-2019-15098: drivers/net/wireless/ath/ath6kl/usb.c in the Linux kernel through
5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15099: drivers/net/wireless/ath/ath10k/usb.c in the Linux kernel through
5.2.8 has a NULL pointer dereference via an incomplete address in an endpoint
descriptor.
CVE-2019-15117: parse_audio_mixer_unit in sound/usb/mixer.c in the Linux kernel
through 5.2.9 mishandles a short descriptor, leading to out-of-bounds memory access.
CVE-2019-15118: check_input_term in sound/usb/mixer.c in the Linux kernel through
5.2.9 mishandles recursion, leading to kernel stack exhaustion.
CVE-2019-15211: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/v4l2-core/v4l2-dev.c
driver because drivers/media/radio/radio-raremono.c does not properly allocate
memory.
CVE-2019-15212: An issue was discovered in the Linux kernel before 5.1.8. There
is a double-free caused by a malicious USB device in the drivers/usb/misc/rio500.c
driver.
CVE-2019-15215: An issue was discovered in the Linux kernel before 5.2.6. There
is a use-after-free caused by a malicious USB device in the drivers/media/usb/cpia2/cpia2_usb.c
driver.
CVE-2019-15217: An issue was discovered in the Linux kernel before 5.2.3. There
is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/zr364xx/zr364xx.c
driver.
CVE-2019-15218: An issue was discovered in the Linux kernel before 5.1.8. There
is a NULL pointer dereference caused by a malicious USB device in the drivers/media/usb/siano/smsusb.c
driver.
CVE-2019-15220: An issue was discovered in the Linux kernel before 5.2.1. There
is a use-after-free caused by a malicious USB device in the drivers/net/wireless/intersil/p54/p54usb.c
driver.
CVE-2019-15221: An issue was discovered in the Linux kernel before 5.1.17. There
is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/pcm.c
driver.
CVE-2019-15223: An issue was discovered in the Linux kernel before 5.1.8. There
is a NULL pointer dereference caused by a malicious USB device in the sound/usb/line6/driver.c
driver.
CVE-2019-15291: An issue was discovered in the Linux kernel through 5.2.9. There
is a NULL pointer dereference caused by a malicious USB device in the flexcop_usb_probe
function in the drivers/media/usb/b2c2/flexcop-usb.c driver.
CVE-2019-15504: drivers/net/wireless/rsi/rsi_91x_usb.c in the Linux kernel through
5.2.9 has a Double Free via crafted USB device traffic (which may be remote via
usbip or usbredir).
CVE-2019-15505: drivers/media/usb/dvb-usb/technisat-usb2.c in the Linux kernel through
5.2.9 has an out-of-bounds read via crafted USB device traffic (which may be remote
via usbip or usbredir).
CVE-2019-15538: An issue was discovered in xfs_setattr_nonsize in fs/xfs/xfs_iops.c
in the Linux kernel through 5.2.9. XFS partially wedges when a chgrp fails on
account of being out of disk quota. xfs_setattr_nonsize is failing to unlock the
ILOCK after the xfs_qm_vop_chown_reserve call fails. This is primarily a local
DoS attack vector, but it might result as well in remote DoS if the XFS filesystem
is exported for instance via NFS.
CVE-2019-15791: Jann Horn discovered a reference count underflow in the shiftfs
implementation in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-15792: Jann Horn discovered a type confusion vulnerability in the shiftfs
implementation in the Linux kernel. A local attacker could use this to cause a
denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-15793: Jann Horn discovered that the shiftfs implementation in the Linux
kernel did not use the correct file system uid/gid when the user namespace of
a lower file system is not in the init user namespace. A local attacker could
use this to possibly bypass DAC permissions or have some other unspecified impact.
CVE-2019-15794: Jann Horn discovered that the OverlayFS and ShiftFS Drivers in the
Linux kernel did not properly handle reference counting during memory mapping
operations when used in conjunction with AUFS. A local attacker could use this
to cause a denial of service (system crash) or possibly execute arbitrary code.
CVE-2019-15902: 'A backporting error was discovered in the Linux stable/longterm
kernel 4.4.x through 4.4.190, 4.9.x through 4.9.190, 4.14.x through 4.14.141,
4.19.x through 4.19.69, and 5.2.x through 5.2.11. Misuse of the upstream "x86/ptrace:
Fix possible spectre-v1 in ptrace_get_debugreg()" commit reintroduced the Spectre
vulnerability that it aimed to eliminate. This occurred because the backport process
depends on cherry picking specific commits, and because two (correctly ordered)
code lines were swapped.'
CVE-2019-15925: An issue was discovered in the Linux kernel before 5.2.3. An out
of bounds access exists in the function hclge_tm_schd_mode_vnet_base_cfg in the
file drivers/net/ethernet/hisilicon/hns3/hns3pf/hclge_tm.c.
CVE-2019-15926: An issue was discovered in the Linux kernel before 5.2.3. Out of
bounds access exists in the functions ath6kl_wmi_pstream_timeout_event_rx and
ath6kl_wmi_cac_event_rx in the file drivers/net/wireless/ath/ath6kl/wmi.c.
CVE-2019-16229: drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5.2.14
does not check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16231: drivers/net/fjes/fjes_main.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c in the Linux kernel
5.2.14 does not check the alloc_workqueue return value, leading to a NULL pointer
dereference.
CVE-2019-16233: drivers/scsi/qla2xxx/qla_os.c in the Linux kernel 5.2.14 does not
check the alloc_workqueue return value, leading to a NULL pointer dereference.
CVE-2019-16714: In the Linux kernel before 5.2.14, rds6_inc_info_copy in net/rds/recv.c
allows attackers to obtain sensitive information from kernel stack memory because
tos and flags fields are not initialized.
CVE-2019-16746: An issue was discovered in net/wireless/nl80211.c in the Linux kernel
through 5.2.17. It does not check the length of variable elements in a beacon
head, leading to a buffer overflow.
CVE-2019-17052: ax25_create in net/ax25/af_ax25.c in the AF_AX25 network module
in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that
unprivileged users can create a raw socket, aka CID-0614e2b73768.
CVE-2019-17053: ieee802154_create in net/ieee802154/socket.c in the AF_IEEE802154
network module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW,
which means that unprivileged users can create a raw socket, aka CID-e69dbd4619e7.
CVE-2019-17054: atalk_create in net/appletalk/ddp.c in the AF_APPLETALK network
module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means
that unprivileged users can create a raw socket, aka CID-6cc03e8aa36c.
CVE-2019-17055: base_sock_create in drivers/isdn/mISDN/socket.c in the AF_ISDN network
module in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means
that unprivileged users can create a raw socket, aka CID-b91ee4aa2a21.
CVE-2019-17056: llcp_sock_create in net/nfc/llcp_sock.c in the AF_NFC network module
in the Linux kernel through 5.3.2 does not enforce CAP_NET_RAW, which means that
unprivileged users can create a raw socket, aka CID-3a359798b176.
CVE-2019-17351: An issue was discovered in drivers/xen/balloon.c in the Linux kernel
before 5.2.3, as used in Xen through 4.12.x, allowing guest OS users to cause
a denial of service because of unrestricted resource consumption during the mapping
of guest memory, aka CID-6ef36ab967c7.
CVE-2019-17666: rtl_p2p_noa_ie in drivers/net/wireless/realtek/rtlwifi/ps.c in the
Linux kernel through 5.3.6 lacks a certain upper-bound check, leading to a buffer
overflow.
CVE-2019-18683: An issue was discovered in drivers/media/platform/vivid in the Linux
kernel through 5.3.8. It is exploitable for privilege escalation on some Linux
distributions where local users have /dev/video0 access, but only if the driver
happens to be loaded. There are multiple race conditions during streaming stopping
in this driver (part of the V4L2 subsystem). These issues are caused by wrong
mutex locking in vivid_stop_generating_vid_cap(), vivid_stop_generating_vid_out(),
sdr_cap_stop_streaming(), and the corresponding kthreads. At least one of these
race conditions leads to a use-after-free.
CVE-2019-18786: In the Linux kernel through 5.3.8, f->fmt.sdr.reserved is uninitialized
in rcar_drif_g_fmt_sdr_cap in drivers/media/platform/rcar_drif.c, which could
cause a memory disclosure problem.
CVE-2019-18811: A memory leak in the sof_set_get_large_ctrl_data() function in sound/soc/sof/ipc.c
in the Linux kernel through 5.3.9 allows attackers to cause a denial of service
(memory consumption) by triggering sof_get_ctrl_copy_params() failures, aka CID-45c1380358b1.
CVE-2019-18813: A memory leak in the dwc3_pci_probe() function in drivers/usb/dwc3/dwc3-pci.c
in the Linux kernel through 5.3.9 allows attackers to cause a denial of service
(memory consumption) by triggering platform_device_add_properties() failures,
aka CID-9bbfceea12a8.
CVE-2019-19045: A memory leak in the mlx5_fpga_conn_create_cq() function in drivers/net/ethernet/mellanox/mlx5/core/fpga/conn.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering mlx5_vector2eqn() failures, aka CID-c8c2a057fdc7.
CVE-2019-19048: A memory leak in the crypto_reportstat() function in drivers/virt/vboxguest/vboxguest_utils.c
in the Linux kernel before 5.3.9 allows attackers to cause a denial of service
(memory consumption) by triggering copy_form_user() failures, aka CID-e0b0cb938864.
CVE-2019-19050: A memory leak in the crypto_reportstat() function in crypto/crypto_user_stat.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_reportstat_alg() failures, aka CID-c03b04dcdba1.
CVE-2019-19051: A memory leak in the i2400m_op_rfkill_sw_toggle() function in drivers/net/wimax/i2400m/op-rfkill.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption), aka CID-6f3ef5c25cc7.
CVE-2019-19052: A memory leak in the gs_can_open() function in drivers/net/can/usb/gs_usb.c
in the Linux kernel before 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-fb5be6a7b486.
CVE-2019-19055: A memory leak in the nl80211_get_ftm_responder_stats() function
in net/wireless/nl80211.c in the Linux kernel through 5.3.11 allows attackers
to cause a denial of service (memory consumption) by triggering nl80211hdr_put()
failures, aka CID-1399c59fa929.
CVE-2019-19057: Two memory leaks in the mwifiex_pcie_init_evt_ring() function in
drivers/net/wireless/marvell/mwifiex/pcie.c in the Linux kernel through 5.3.11
allow attackers to cause a denial of service (memory consumption) by triggering
mwifiex_map_pci_memory() failures, aka CID-d10dcb615c8e.
CVE-2019-19062: A memory leak in the crypto_report() function in crypto/crypto_user_base.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering crypto_report_alg() failures, aka CID-ffdde5932042.
CVE-2019-19063: Two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption), aka CID-3f9361695113.
CVE-2019-19067: '** DISPUTED ** Four memory leaks in the acp_hw_init() function
in drivers/gpu/drm/amd/amdgpu/amdgpu_acp.c in the Linux kernel before 5.3.8 allow
attackers to cause a denial of service (memory consumption) by triggering mfd_add_hotplug_devices()
or pm_genpd_add_device() failures, aka CID-57be09c6e874. NOTE: third parties dispute
the relevance of this because the attacker must already have privileges for module
loading.'
CVE-2019-19071: A memory leak in the rsi_send_beacon() function in drivers/net/wireless/rsi/rsi_91x_mgmt.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering rsi_prepare_beacon() failures, aka CID-d563131ef23c.
CVE-2019-19072: A memory leak in the predicate_parse() function in kernel/trace/trace_events_filter.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption), aka CID-96c5c6e6a5b6.
CVE-2019-19076: A memory leak in the nfp_abm_u32_knode_replace() function in drivers/net/ethernet/netronome/nfp/abm/cls.c
in the Linux kernel before 5.3.6 allows attackers to cause a denial of service
(memory consumption), aka CID-78beef629fd9.
CVE-2019-19077: A memory leak in the bnxt_re_create_srq() function in drivers/infiniband/hw/bnxt_re/ib_verbs.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering copy to udata failures, aka CID-4a9d46a9fe14.
CVE-2019-19078: A memory leak in the ath10k_usb_hif_tx_sg() function in drivers/net/wireless/ath/ath10k/usb.c
in the Linux kernel through 5.3.11 allows attackers to cause a denial of service
(memory consumption) by triggering usb_submit_urb() failures, aka CID-b8d17e7d93d2.
CVE-2019-19082: Memory leaks in *create_resource_pool() functions under drivers/gpu/drm/amd/display/dc
in the Linux kernel through 5.3.11 allow attackers to cause a denial of service
(memory consumption). This affects the dce120_create_resource_pool() function
in drivers/gpu/drm/amd/display/dc/dce120/dce120_resource.c, the dce110_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dce110/dce110_resource.c, the dce100_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dce100/dce100_resource.c, the dcn10_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dcn10/dcn10_resource.c, and the dce112_create_resource_pool()
function in drivers/gpu/drm/amd/display/dc/dce112/dce112_resource.c, aka CID-104c307147ad.
CVE-2019-19241: In the Linux kernel before 5.4.2, the io_uring feature leads to
requests that inadvertently have UID 0 and full capabilities, aka CID-181e448d8709.
This is related to fs/io-wq.c, fs/io_uring.c, and net/socket.c. For example, an
attacker can bypass intended restrictions on adding an IPv4 address to the loopback
interface. This occurs because IORING_OP_SENDMSG operations, although requested
in the context of an unprivileged user, are sometimes performed by a kernel worker
thread without considering that context.
CVE-2019-19252: vcs_write in drivers/tty/vt/vc_screen.c in the Linux kernel through
5.3.13 does not prevent write access to vcsu devices.
CVE-2019-19332: An out-of-bounds memory write issue was found in the way the Linux
kernel's KVM hypervisor handled the 'KVM_GET_EMULATED_CPUID' ioctl(2) request
to get CPUID features emulated by the KVM hypervisor. A user or process able to
access the '/dev/kvm' device could use this flaw to crash the system, resulting
in a denial of service.
CVE-2019-19524: In the Linux kernel before 5.3.12, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/input/ff-memless.c
driver, aka CID-fa3a5a1880c9.
CVE-2019-19529: In the Linux kernel before 5.3.11, there is a use-after-free bug
that can be caused by a malicious USB device in the drivers/net/can/usb/mcba_usb.c
driver, aka CID-4d6636498c41.
CVE-2019-19532: In the Linux kernel before 5.3.9, there are multiple out-of-bounds
write bugs that can be caused by a malicious USB device in the Linux kernel HID
drivers, aka CID-d9d4b1e46d95. This affects drivers/hid/hid-axff.c, drivers/hid/hid-dr.c,
drivers/hid/hid-emsff.c, drivers/hid/hid-gaff.c, drivers/hid/hid-holtekff.c, drivers/hid/hid-lg2ff.c,
drivers/hid/hid-lg3ff.c, drivers/hid/hid-lg4ff.c, drivers/hid/hid-lgff.c, drivers/hid/hid-logitech-hidpp.c,
drivers/hid/hid-microsoft.c, drivers/hid/hid-sony.c, drivers/hid/hid-tmff.c, and
drivers/hid/hid-zpff.c.
CVE-2019-19534: In the Linux kernel before 5.3.11, there is an info-leak bug that
can be caused by a malicious USB device in the drivers/net/can/usb/peak_usb/pcan_usb_core.c
driver, aka CID-f7a1337f0d29.
CVE-2019-19602: fpregs_state_valid in arch/x86/include/asm/fpu/internal.h in the
Linux kernel before 5.4.2, when GCC 9 is used, allows context-dependent attackers
to cause a denial of service (memory corruption) or possibly have unspecified
other impact because of incorrect fpu_fpregs_owner_ctx caching, as demonstrated
by mishandling of signal-based non-cooperative preemption in Go 1.14 prereleases
on amd64, aka CID-59c4bd853abc.
CVE-2019-19767: The Linux kernel before 5.4.2 mishandles ext4_expand_extra_isize,
as demonstrated by use-after-free errors in __ext4_expand_extra_isize and ext4_xattr_set_entry,
related to fs/ext4/inode.c and fs/ext4/super.c, aka CID-4ea99936a163.
CVE-2019-19922: kernel/sched/fair.c in the Linux kernel before 5.3.9, when cpu.cfs_quota_us
is used (e.g., with Kubernetes), allows attackers to cause a denial of service
against non-cpu-bound applications by generating a workload that triggers unwanted
slice expiration, aka CID-de53fd7aedb1. (In other words, although this slice expiration
would typically be seen with benign workloads, it is possible that an attacker
could calculate how many stray requests are required to force an entire Kubernetes
cluster into a low-performance state caused by slice expiration, and ensure that
a DDoS attack sent that number of stray requests. An attack does not affect the
stability of the kernel; it only causes mismanagement of application execution.)
CVE-2019-19947: In the Linux kernel through 5.4.6, there are information leaks of
uninitialized memory to a USB device in the drivers/net/can/usb/kvaser_usb/kvaser_usb_leaf.c
driver, aka CID-da2311a6385c.
CVE-2019-19965: In the Linux kernel through 5.4.6, there is a NULL pointer dereference
in drivers/scsi/libsas/sas_discover.c because of mishandling of port disconnection
during discovery, related to a PHY down race condition, aka CID-f70267f379b5.
CVE-2019-9506: The Bluetooth BR/EDR specification up to and including version 5.1
permits sufficiently low encryption key length and does not prevent an attacker
from influencing the key length negotiation. This allows practical brute-force
attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext
without the victim noticing.
cvelist: [CVE-2019-19922, CVE-2019-19071, CVE-2019-19332, CVE-2019-19067, CVE-2019-16714,
CVE-2019-18786, CVE-2019-19057, CVE-2019-19077, CVE-2019-15902, CVE-2019-15926,
CVE-2019-0154, CVE-2019-19532, CVE-2019-15505, CVE-2019-9506, CVE-2019-19052,
CVE-2019-15793, CVE-2019-19055, CVE-2019-19252, CVE-2019-18813, CVE-2019-14895,
CVE-2019-15223, CVE-2019-10220, CVE-2019-15215, CVE-2019-17056, CVE-2019-16231,
CVE-2019-15792, CVE-2019-15217, CVE-2019-15099, CVE-2019-14615, CVE-2019-15218,
CVE-2019-0155, CVE-2019-15504, CVE-2019-14901, CVE-2019-16229, CVE-2019-19076,
CVE-2019-19947, CVE-2019-17666, CVE-2019-15212, CVE-2019-19534, CVE-2019-15117,
CVE-2019-19524, CVE-2019-19078, CVE-2019-16746, CVE-2019-19051, CVE-2019-19045,
CVE-2019-19062, CVE-2019-15090, CVE-2019-14835, CVE-2019-16233, CVE-2019-19529,
CVE-2019-13631, CVE-2019-19063, CVE-2019-14816, CVE-2019-10207, CVE-2019-18811,
CVE-2019-15211, CVE-2019-19241, CVE-2019-14821, CVE-2019-17055, CVE-2019-14814,
CVE-2019-19048, CVE-2019-17053, CVE-2019-19072, CVE-2019-15291, CVE-2019-15220,
CVE-2019-19050, CVE-2019-15538, CVE-2019-16232, CVE-2019-19965, CVE-2019-18683,
CVE-2019-0136, CVE-2019-15098, CVE-2019-19602, CVE-2019-15221, CVE-2019-17054,
CVE-2019-19767, CVE-2019-14815, CVE-2018-12207, CVE-2019-19082, CVE-2019-14897,
CVE-2019-17351, CVE-2019-17052, CVE-2019-15925, CVE-2019-15118, CVE-2019-15794,
CVE-2019-15791]
latest-version: pve-kernel-5.3.18-2-pve_5.3.18-2
Reply all
Reply to author
Forward
0 new messages