VARIoT IoT vulnerabilities database
| VAR-201909-1558 | No CVE | Schneider Electric Modicon M340 PLC Has Unauthorized Access Vulnerability |
CVSS V2: 2.1 CVSS V3: - Severity: LOW |
Schneider Electric Modicon M340 is a medium-sized PLC of Schneider Electric, which is widely used in the field of industrial control in China.
Schneider Electric Modicon M340 PLC has an unauthorized access vulnerability. An attacker can exploit the vulnerability without having to log in to an account, and delete a user's password by constructing a special link
| VAR-201909-1551 | No CVE | Schneider Electric Modicon M340 PLC Has Click Hijacking Vulnerability |
CVSS V2: 2.1 CVSS V3: - Severity: LOW |
Schneider Electric Modicon M340 is a medium-sized PLC of Schneider Electric, which is widely used in the field of industrial control in China.
Schneider Electric Modicon M340 PLC has a click hijacking vulnerability. Attackers can tamper with user passwords by constructing special links
| VAR-201909-1555 | No CVE | Schneider Electric Modicon M340 PLC Has Unauthorized Access Vulnerability |
CVSS V2: 2.1 CVSS V3: - Severity: LOW |
Schneider Electric Modicon M340 is a medium-sized PLC of Schneider Electric, which is widely used in the field of industrial control in China.
Schneider Electric Modicon M340 PLC has an unauthorized access vulnerability. An attacker can exploit the vulnerabilities without logging in to the administrator account, by constructing special links, tampering with user passwords, and obtaining sensitive information
| VAR-201909-1553 | No CVE | NAPro has a backdoor vulnerability |
CVSS V2: 6.6 CVSS V3: - Severity: MEDIUM |
NAPro is a PLC programming software developed by Nanda Autotech Jiangsu Co., Ltd.
NAPro has a backdoor vulnerability. Attackers can use this vulnerability to log in to the PLC to perform illegal operations
| VAR-201909-1564 | No CVE | Authentication Bypass Vulnerability in Unity Pro XL |
CVSS V2: 6.6 CVSS V3: - Severity: MEDIUM |
Unity Pro XL is a PLC programming software from Schneider Electric.
There is an authentication bypass vulnerability in Unity Pro XL, which can be used by unauthorized attackers to access the PLC
| VAR-201909-1028 | CVE-2019-14239 | plural NXP Kinetis Authentication vulnerabilities in product devices |
CVSS V2: 4.6 CVSS V3: 6.6 Severity: MEDIUM |
On NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x devices, Flash Access Controls (FAC) (a software IP protection method for execute-only access) can be defeated by leveraging a load instruction inside the execute-only region to expose the protected code into a CPU register. NXP Kinetis KV1x , KV3x , K8x Devices have authentication vulnerabilities.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. NXP Semiconductors NXP Kinetis KV1x, etc. are all microcontrollers from NXP Semiconductors in the Netherlands. A security vulnerability exists in NXP Semiconductors NXP Kinetis KV1x, Kinetis KV3x, and Kinetis K8x. An attacker could exploit this vulnerability to bypass Flash Access Controls (FAC) protection
| VAR-201909-0026 | CVE-2019-6175 | Lenovo System Update Input validation vulnerability |
CVSS V2: 7.8 CVSS V3: 7.5 Severity: HIGH |
A denial of service vulnerability was reported in Lenovo System Update versions prior to 5.07.0088 that could allow configuration files to be written to non-standard locations. Lenovo System Update Contains an input validation vulnerability.Service operation interruption (DoS) There is a possibility of being put into a state. Lenovo 3000 C100, etc. are all products of China Lenovo (Lenovo). The Lenovo 3000 C100 is a laptop. The Lenovo 3000 C200 is a laptop. Lenovo ThinkCentre is a desktop computer. Lenovo System Update is one of the system update tools. A denial of service vulnerability exists in several Lenovo products. An attacker could exploit this vulnerability to cause a denial of service. The following products and versions are affected: Lenovo 3000 C100; 3000 C200; 3000 N100; 3000 N200; 3000 V100; 3000 V200; Lenovo 3000 J100; ;3000 S200p;3000 S205;ThinkPad;ThinkCentre;ThinkStation;Lenovo V Series;B Series;K Series;E Series
| VAR-201909-0088 | CVE-2019-3416 | ZTE ZXV10 B860A Input Validation Error Vulnerability |
CVSS V2: 10.0 CVSS V3: 9.8 Severity: CRITICAL |
All versions up to V81511329.1008 of ZTE ZXV10 B860A products are impacted by input validation vulnerability. Due to input validation, unauthorized users can take advantage of this vulnerability to control the user terminal system. ZTE ZXV10 B860A The product contains an input validation vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. ZTE ZXV10 B860A is a network set-top box of China ZTE Corporation
| VAR-201909-0718 | CVE-2019-16518 | Swell Kit Mod Vulnerability in leaking resources to the wrong area in devices |
CVSS V2: 3.3 CVSS V3: 4.3 Severity: MEDIUM |
An issue was discovered on Swell Kit Mod devices that use the Vandy Vape platform. An attacker may be able to trigger an unintended temperature in the victim's mouth and throat via Bluetooth Low Energy (BLE) packets that specify large power or voltage values. Currently there is no information about this vulnerability, please keep an eye on CNNVD or vendor announcements
| VAR-201909-1368 | CVE-2018-21019 | Home Assistant Information Disclosure Vulnerability |
CVSS V2: 5.0 CVSS V3: 7.5 Severity: HIGH |
Home Assistant before 0.67.0 was vulnerable to an information disclosure that allowed an unauthenticated attacker to read the application's error log via components/api.py. This system is mainly used to control home automation equipment
| VAR-201909-1663 | No CVE | Logical flaw in security certification of a model of Dahua webcam |
CVSS V2: 10.0 CVSS V3: - Severity: HIGH |
Zhejiang Dahua Technology Co., Ltd. is a smart IoT solution provider and operator based on video.
There is a logic flaw in the security authentication of a certain Dahua webcam. Attackers can forge data packets and call interfaces to execute arbitrary commands.
| VAR-201909-1526 | CVE-2019-14816 | Red Hat Security Advisory 2020-0174-01 |
CVSS V2: 7.2 CVSS V3: 7.8 Severity: HIGH |
There is heap-based buffer overflow in kernel, all versions up to, excluding 5.3, in the marvell wifi chip driver in Linux kernel, that allows local users to cause a denial of service(system crash) or possibly execute arbitrary code. 7) - aarch64, noarch, ppc64le
3.
Bug Fix(es):
* Kernel panic on job cleanup, related to SyS_getdents64 (BZ#1702057)
* Kernel modules generated incorrectly when system is localized to
non-English language (BZ#1705285)
* RHEL-Alt-7.6 - Fixup tlbie vs store ordering issue on POWER9 (BZ#1756270)
4. ==========================================================================
Kernel Live Patch Security Notice 0058-1
October 22, 2019
linux vulnerability
==========================================================================
A security issue affects these releases of Ubuntu:
| Series | Base kernel | Arch | flavors |
|------------------+--------------+----------+------------------|
| Ubuntu 18.04 LTS | 4.15.0 | amd64 | aws |
| Ubuntu 18.04 LTS | 4.15.0 | amd64 | generic |
| Ubuntu 18.04 LTS | 4.15.0 | amd64 | lowlatency |
| Ubuntu 18.04 LTS | 4.15.0 | amd64 | oem |
| Ubuntu 18.04 LTS | 5.0.0 | amd64 | azure |
| Ubuntu 14.04 LTS | 4.4.0 | amd64 | generic |
| Ubuntu 14.04 LTS | 4.4.0 | amd64 | lowlatency |
| Ubuntu 16.04 LTS | 4.4.0 | amd64 | aws |
| Ubuntu 16.04 LTS | 4.4.0 | amd64 | generic |
| Ubuntu 16.04 LTS | 4.4.0 | amd64 | lowlatency |
| Ubuntu 16.04 LTS | 4.15.0 | amd64 | azure |
| Ubuntu 16.04 LTS | 4.15.0 | amd64 | generic |
| Ubuntu 16.04 LTS | 4.15.0 | amd64 | lowlatency |
Summary:
Several security issues were fixed in the kernel.
Software Description:
- linux: Linux kernel
Details:
It was discovered that a race condition existed in the GFS2 file system in
the Linux kernel. A local attacker could possibly use this to cause a
denial of service (system crash). (CVE-2016-10905)
It was discovered that a use-after-free error existed in the block layer
subsystem of the Linux kernel when certain failure conditions occurred. (CVE-2018-20856)
It was discovered that the USB gadget Midi driver in the Linux kernel
contained a double-free vulnerability when handling certain error
conditions. A local attacker could use this to cause a denial of service
(system crash). (CVE-2018-20961)
It was discovered that the XFS file system in the Linux kernel did not
properly handle mount failures in some situations. (CVE-2018-20976)
It was discovered that the RSI 91x Wi-Fi driver in the Linux kernel did not
did not handle detach operations correctly, leading to a use-after-free
vulnerability.
(CVE-2018-21008)
It was discovered that the Intel Wi-Fi device driver in the Linux kernel
did not properly validate certain Tunneled Direct Link Setup (TDLS). A
physically proximate attacker could use this to cause a denial of service
(Wi-Fi disconnect). (CVE-2019-0136)
It was discovered that the Linux kernel on ARM processors allowed a tracing
process to modify a syscall after a seccomp decision had been made on that
syscall. A local attacker could possibly use this to bypass seccomp
restrictions. (CVE-2019-2054)
It was discovered that an integer overflow existed in the Binder
implementation of the Linux kernel, leading to a buffer overflow. A local
attacker could use this to escalate privileges. (CVE-2019-2181)
It was discovered that the Marvell Wireless LAN device driver in the Linux
kernel did not properly validate the BSS descriptor. (CVE-2019-3846)
It was discovered that a heap buffer overflow existed in the Marvell
Wireless LAN device driver for the Linux kernel. (CVE-2019-10126)
It was discovered that the Bluetooth UART implementation in the Linux
kernel did not properly check for missing tty operations. A local attacker
could use this to cause a denial of service. (CVE-2019-10207)
Jonathan Looney discovered that an integer overflow existed in the Linux
kernel when handling TCP Selective Acknowledgments (SACKs). A remote
attacker could use this to cause a denial of service (system crash).
(CVE-2019-11477)
Jonathan Looney discovered that the TCP retransmission queue implementation
in the Linux kernel could be fragmented when handling certain TCP Selective
Acknowledgment (SACK) sequences. A remote attacker could use this to cause
a denial of service. (CVE-2019-11478)
It was discovered that the ext4 file system implementation in the Linux
kernel did not properly zero out memory in some situations. A local
attacker could use this to expose sensitive information (kernel memory).
(CVE-2019-11833)
It was discovered that the PowerPC dlpar implementation in the Linux kernel
did not properly check for allocation errors in some situations. A local
attacker could possibly use this to cause a denial of service (system
crash). (CVE-2019-12614)
It was discovered that the floppy driver in the Linux kernel did not
properly validate meta data, leading to a buffer overread. A local attacker
could use this to cause a denial of service (system crash).
(CVE-2019-14283)
It was discovered that the floppy driver in the Linux kernel did not
properly validate ioctl() calls, leading to a division-by-zero. A local
attacker could use this to cause a denial of service (system crash).
(CVE-2019-14284)
Wen Huang discovered that the Marvell Wi-Fi device driver in the Linux
kernel did not properly perform bounds checking, leading to a heap
overflow. (CVE-2019-14814)
Wen Huang discovered that the Marvell Wi-Fi device driver in the Linux
kernel did not properly perform bounds checking, leading to a heap
overflow. (CVE-2019-14815)
Wen Huang discovered that the Marvell Wi-Fi device driver in the Linux
kernel did not properly perform bounds checking, leading to a heap
overflow. (CVE-2019-14816)
Matt Delco discovered that the KVM hypervisor implementation in the Linux
kernel did not properly perform bounds checking when handling coalesced
MMIO write operations. A local attacker with write access to /dev/kvm could
use this to cause a denial of service (system crash). (CVE-2019-14821)
Peter Pi discovered a buffer overflow in the virtio network backend
(vhost_net) implementation in the Linux kernel. (CVE-2019-14835)
Update instructions:
The problem can be corrected by updating your livepatches to the following
versions:
| Kernel | Version | flavors |
|--------------------------+----------+--------------------------|
| 4.4.0-148.174 | 58.1 | lowlatency, generic |
| 4.4.0-148.174~14.04.1 | 58.1 | lowlatency, generic |
| 4.4.0-150.176 | 58.1 | generic, lowlatency |
| 4.4.0-150.176~14.04.1 | 58.1 | lowlatency, generic |
| 4.4.0-151.178 | 58.1 | lowlatency, generic |
| 4.4.0-151.178~14.04.1 | 58.1 | generic, lowlatency |
| 4.4.0-154.181 | 58.1 | lowlatency, generic |
| 4.4.0-154.181~14.04.1 | 58.1 | generic, lowlatency |
| 4.4.0-157.185 | 58.1 | lowlatency, generic |
| 4.4.0-157.185~14.04.1 | 58.1 | generic, lowlatency |
| 4.4.0-159.187 | 58.1 | lowlatency, generic |
| 4.4.0-159.187~14.04.1 | 58.1 | generic, lowlatency |
| 4.4.0-161.189 | 58.1 | lowlatency, generic |
| 4.4.0-161.189~14.04.1 | 58.1 | lowlatency, generic |
| 4.4.0-164.192 | 58.1 | lowlatency, generic |
| 4.4.0-164.192~14.04.1 | 58.1 | lowlatency, generic |
| 4.4.0-165.193 | 58.1 | generic, lowlatency |
| 4.4.0-1083.93 | 58.1 | aws |
| 4.4.0-1084.94 | 58.1 | aws |
| 4.4.0-1085.96 | 58.1 | aws |
| 4.4.0-1087.98 | 58.1 | aws |
| 4.4.0-1088.99 | 58.1 | aws |
| 4.4.0-1090.101 | 58.1 | aws |
| 4.4.0-1092.103 | 58.1 | aws |
| 4.4.0-1094.105 | 58.1 | aws |
| 4.15.0-50.54 | 58.1 | generic, lowlatency |
| 4.15.0-50.54~16.04.1 | 58.1 | generic, lowlatency |
| 4.15.0-51.55 | 58.1 | generic, lowlatency |
| 4.15.0-51.55~16.04.1 | 58.1 | generic, lowlatency |
| 4.15.0-52.56 | 58.1 | lowlatency, generic |
| 4.15.0-52.56~16.04.1 | 58.1 | generic, lowlatency |
| 4.15.0-54.58 | 58.1 | generic, lowlatency |
| 4.15.0-54.58~16.04.1 | 58.1 | generic, lowlatency |
| 4.15.0-55.60 | 58.1 | generic, lowlatency |
| 4.15.0-58.64 | 58.1 | generic, lowlatency |
| 4.15.0-58.64~16.04.1 | 58.1 | lowlatency, generic |
| 4.15.0-60.67 | 58.1 | lowlatency, generic |
| 4.15.0-60.67~16.04.1 | 58.1 | generic, lowlatency |
| 4.15.0-62.69 | 58.1 | generic, lowlatency |
| 4.15.0-62.69~16.04.1 | 58.1 | lowlatency, generic |
| 4.15.0-64.73 | 58.1 | generic, lowlatency |
| 4.15.0-64.73~16.04.1 | 58.1 | lowlatency, generic |
| 4.15.0-65.74 | 58.1 | lowlatency, generic |
| 4.15.0-1038.43 | 58.1 | oem |
| 4.15.0-1039.41 | 58.1 | aws |
| 4.15.0-1039.44 | 58.1 | oem |
| 4.15.0-1040.42 | 58.1 | aws |
| 4.15.0-1041.43 | 58.1 | aws |
| 4.15.0-1043.45 | 58.1 | aws |
| 4.15.0-1043.48 | 58.1 | oem |
| 4.15.0-1044.46 | 58.1 | aws |
| 4.15.0-1045.47 | 58.1 | aws |
| 4.15.0-1045.50 | 58.1 | oem |
| 4.15.0-1047.49 | 58.1 | aws |
| 4.15.0-1047.51 | 58.1 | azure |
| 4.15.0-1048.50 | 58.1 | aws |
| 4.15.0-1049.54 | 58.1 | azure |
| 4.15.0-1050.52 | 58.1 | aws |
| 4.15.0-1050.55 | 58.1 | azure |
| 4.15.0-1050.57 | 58.1 | oem |
| 4.15.0-1051.53 | 58.1 | aws |
| 4.15.0-1051.56 | 58.1 | azure |
| 4.15.0-1052.57 | 58.1 | azure |
| 4.15.0-1055.60 | 58.1 | azure |
| 4.15.0-1056.61 | 58.1 | azure |
| 4.15.0-1056.65 | 58.1 | oem |
| 4.15.0-1057.62 | 58.1 | azure |
| 4.15.0-1057.66 | 58.1 | oem |
| 4.15.0-1059.64 | 58.1 | azure |
| 5.0.0-1014.14~18.04.1 | 58.1 | azure |
| 5.0.0-1016.17~18.04.1 | 58.1 | azure |
| 5.0.0-1018.19~18.04.1 | 58.1 | azure |
| 5.0.0-1020.21~18.04.1 | 58.1 | azure |
Support Information:
Kernels older than the levels listed below do not receive livepatch
updates. Please upgrade your kernel as soon as possible.
| Series | Version | Flavors |
|------------------+------------------+--------------------------|
| Ubuntu 18.04 LTS | 4.15.0-1039 | aws |
| Ubuntu 16.04 LTS | 4.4.0-1083 | aws |
| Ubuntu 18.04 LTS | 5.0.0-1000 | azure |
| Ubuntu 16.04 LTS | 4.15.0-1047 | azure |
| Ubuntu 18.04 LTS | 4.15.0-50 | generic lowlatency |
| Ubuntu 16.04 LTS | 4.15.0-50 | generic lowlatency |
| Ubuntu 14.04 LTS | 4.4.0-148 | generic lowlatency |
| Ubuntu 18.04 LTS | 4.15.0-1038 | oem |
| Ubuntu 16.04 LTS | 4.4.0-148 | generic lowlatency |
References:
CVE-2016-10905, CVE-2018-20856, CVE-2018-20961, CVE-2018-20976,
CVE-2018-21008, CVE-2019-0136, CVE-2019-2054, CVE-2019-2181,
CVE-2019-3846, CVE-2019-10126, CVE-2019-10207, CVE-2019-11477,
CVE-2019-11478, CVE-2019-11833, CVE-2019-12614, CVE-2019-14283,
CVE-2019-14284, CVE-2019-14814, CVE-2019-14815, CVE-2019-14816,
CVE-2019-14821, CVE-2019-14835
--
ubuntu-security-announce mailing list
ubuntu-security-announce@lists.ubuntu.com
Modify settings or unsubscribe at: https://lists.ubuntu.com/mailman/listinfo/ubuntu-security-announce
. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
=====================================================================
Red Hat Security Advisory
Synopsis: Important: kernel security and bug fix update
Advisory ID: RHSA-2020:0374-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2020:0374
Issue date: 2020-02-04
CVE Names: CVE-2019-14816 CVE-2019-14895 CVE-2019-14898
CVE-2019-14901 CVE-2019-17133
=====================================================================
1. Summary:
An update for kernel is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Client Optional (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode (v. 7) - noarch, x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64
Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64
3.
Bug Fix(es):
* [Azure][7.8] Include patch "PCI: hv: Avoid use of hv_pci_dev->pci_slot
after freeing it" (BZ#1766089)
* [Hyper-V][RHEL7.8] When accelerated networking is enabled on RedHat,
network interface(eth0) moved to new network namespace does not obtain IP
address. (BZ#1766093)
* [Azure][RHEL 7.6] hv_vmbus probe pass-through GPU card failed
(BZ#1766097)
* SMB3: Do not error out on large file transfers if server responds with
STATUS_INSUFFICIENT_RESOURCES (BZ#1767621)
* Since RHEL commit 5330f5d09820 high load can cause dm-multipath path
failures (BZ#1770113)
* Hard lockup in free_one_page()->_raw_spin_lock() because sosreport
command is reading from /proc/pagetypeinfo (BZ#1770732)
* patchset for x86/atomic: Fix smp_mb__{before,after}_atomic() (BZ#1772812)
* fix compat statfs64() returning EOVERFLOW for when _FILE_OFFSET_BITS=64
(BZ#1775678)
* Guest crash after load cpuidle-haltpoll driver (BZ#1776289)
* RHEL 7.7 long I/O stalls with bnx2fc from not masking off scope bits of
retry delay value (BZ#1776290)
* Multiple "mv" processes hung on a gfs2 filesystem (BZ#1777297)
* Moving Egress IP will result in conntrack sessions being DESTROYED
(BZ#1779564)
* core: backports from upstream (BZ#1780033)
* kernel BUG at arch/powerpc/platforms/pseries/lpar.c:482! (BZ#1780148)
* Race between tty_open() and flush_to_ldisc() using the
tty_struct->driver_data field. (BZ#1780163)
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
The system must be rebooted for this update to take effect.
5. Package List:
Red Hat Enterprise Linux Client (v. 7):
Source:
kernel-3.10.0-1062.12.1.el7.src.rpm
noarch:
kernel-abi-whitelists-3.10.0-1062.12.1.el7.noarch.rpm
kernel-doc-3.10.0-1062.12.1.el7.noarch.rpm
x86_64:
bpftool-3.10.0-1062.12.1.el7.x86_64.rpm
bpftool-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debug-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debug-devel-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-devel-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-headers-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-libs-3.10.0-1062.12.1.el7.x86_64.rpm
perf-3.10.0-1062.12.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
python-perf-3.10.0-1062.12.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
Red Hat Enterprise Linux Client Optional (v. 7):
x86_64:
bpftool-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-1062.12.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
Red Hat Enterprise Linux ComputeNode (v. 7):
Source:
kernel-3.10.0-1062.12.1.el7.src.rpm
noarch:
kernel-abi-whitelists-3.10.0-1062.12.1.el7.noarch.rpm
kernel-doc-3.10.0-1062.12.1.el7.noarch.rpm
x86_64:
bpftool-3.10.0-1062.12.1.el7.x86_64.rpm
bpftool-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debug-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debug-devel-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-devel-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-headers-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-libs-3.10.0-1062.12.1.el7.x86_64.rpm
perf-3.10.0-1062.12.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
python-perf-3.10.0-1062.12.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
x86_64:
bpftool-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-1062.12.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source:
kernel-3.10.0-1062.12.1.el7.src.rpm
noarch:
kernel-abi-whitelists-3.10.0-1062.12.1.el7.noarch.rpm
kernel-doc-3.10.0-1062.12.1.el7.noarch.rpm
ppc64:
bpftool-3.10.0-1062.12.1.el7.ppc64.rpm
bpftool-debuginfo-3.10.0-1062.12.1.el7.ppc64.rpm
kernel-3.10.0-1062.12.1.el7.ppc64.rpm
kernel-bootwrapper-3.10.0-1062.12.1.el7.ppc64.rpm
kernel-debug-3.10.0-1062.12.1.el7.ppc64.rpm
kernel-debug-debuginfo-3.10.0-1062.12.1.el7.ppc64.rpm
kernel-debug-devel-3.10.0-1062.12.1.el7.ppc64.rpm
kernel-debuginfo-3.10.0-1062.12.1.el7.ppc64.rpm
kernel-debuginfo-common-ppc64-3.10.0-1062.12.1.el7.ppc64.rpm
kernel-devel-3.10.0-1062.12.1.el7.ppc64.rpm
kernel-headers-3.10.0-1062.12.1.el7.ppc64.rpm
kernel-tools-3.10.0-1062.12.1.el7.ppc64.rpm
kernel-tools-debuginfo-3.10.0-1062.12.1.el7.ppc64.rpm
kernel-tools-libs-3.10.0-1062.12.1.el7.ppc64.rpm
perf-3.10.0-1062.12.1.el7.ppc64.rpm
perf-debuginfo-3.10.0-1062.12.1.el7.ppc64.rpm
python-perf-3.10.0-1062.12.1.el7.ppc64.rpm
python-perf-debuginfo-3.10.0-1062.12.1.el7.ppc64.rpm
ppc64le:
bpftool-3.10.0-1062.12.1.el7.ppc64le.rpm
bpftool-debuginfo-3.10.0-1062.12.1.el7.ppc64le.rpm
kernel-3.10.0-1062.12.1.el7.ppc64le.rpm
kernel-bootwrapper-3.10.0-1062.12.1.el7.ppc64le.rpm
kernel-debug-3.10.0-1062.12.1.el7.ppc64le.rpm
kernel-debug-debuginfo-3.10.0-1062.12.1.el7.ppc64le.rpm
kernel-debuginfo-3.10.0-1062.12.1.el7.ppc64le.rpm
kernel-debuginfo-common-ppc64le-3.10.0-1062.12.1.el7.ppc64le.rpm
kernel-devel-3.10.0-1062.12.1.el7.ppc64le.rpm
kernel-headers-3.10.0-1062.12.1.el7.ppc64le.rpm
kernel-tools-3.10.0-1062.12.1.el7.ppc64le.rpm
kernel-tools-debuginfo-3.10.0-1062.12.1.el7.ppc64le.rpm
kernel-tools-libs-3.10.0-1062.12.1.el7.ppc64le.rpm
perf-3.10.0-1062.12.1.el7.ppc64le.rpm
perf-debuginfo-3.10.0-1062.12.1.el7.ppc64le.rpm
python-perf-3.10.0-1062.12.1.el7.ppc64le.rpm
python-perf-debuginfo-3.10.0-1062.12.1.el7.ppc64le.rpm
s390x:
bpftool-3.10.0-1062.12.1.el7.s390x.rpm
bpftool-debuginfo-3.10.0-1062.12.1.el7.s390x.rpm
kernel-3.10.0-1062.12.1.el7.s390x.rpm
kernel-debug-3.10.0-1062.12.1.el7.s390x.rpm
kernel-debug-debuginfo-3.10.0-1062.12.1.el7.s390x.rpm
kernel-debug-devel-3.10.0-1062.12.1.el7.s390x.rpm
kernel-debuginfo-3.10.0-1062.12.1.el7.s390x.rpm
kernel-debuginfo-common-s390x-3.10.0-1062.12.1.el7.s390x.rpm
kernel-devel-3.10.0-1062.12.1.el7.s390x.rpm
kernel-headers-3.10.0-1062.12.1.el7.s390x.rpm
kernel-kdump-3.10.0-1062.12.1.el7.s390x.rpm
kernel-kdump-debuginfo-3.10.0-1062.12.1.el7.s390x.rpm
kernel-kdump-devel-3.10.0-1062.12.1.el7.s390x.rpm
perf-3.10.0-1062.12.1.el7.s390x.rpm
perf-debuginfo-3.10.0-1062.12.1.el7.s390x.rpm
python-perf-3.10.0-1062.12.1.el7.s390x.rpm
python-perf-debuginfo-3.10.0-1062.12.1.el7.s390x.rpm
x86_64:
bpftool-3.10.0-1062.12.1.el7.x86_64.rpm
bpftool-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debug-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debug-devel-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-devel-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-headers-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-libs-3.10.0-1062.12.1.el7.x86_64.rpm
perf-3.10.0-1062.12.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
python-perf-3.10.0-1062.12.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
Red Hat Enterprise Linux Server Optional (v. 7):
ppc64:
bpftool-debuginfo-3.10.0-1062.12.1.el7.ppc64.rpm
kernel-debug-debuginfo-3.10.0-1062.12.1.el7.ppc64.rpm
kernel-debuginfo-3.10.0-1062.12.1.el7.ppc64.rpm
kernel-debuginfo-common-ppc64-3.10.0-1062.12.1.el7.ppc64.rpm
kernel-tools-debuginfo-3.10.0-1062.12.1.el7.ppc64.rpm
kernel-tools-libs-devel-3.10.0-1062.12.1.el7.ppc64.rpm
perf-debuginfo-3.10.0-1062.12.1.el7.ppc64.rpm
python-perf-debuginfo-3.10.0-1062.12.1.el7.ppc64.rpm
ppc64le:
bpftool-debuginfo-3.10.0-1062.12.1.el7.ppc64le.rpm
kernel-debug-debuginfo-3.10.0-1062.12.1.el7.ppc64le.rpm
kernel-debug-devel-3.10.0-1062.12.1.el7.ppc64le.rpm
kernel-debuginfo-3.10.0-1062.12.1.el7.ppc64le.rpm
kernel-debuginfo-common-ppc64le-3.10.0-1062.12.1.el7.ppc64le.rpm
kernel-tools-debuginfo-3.10.0-1062.12.1.el7.ppc64le.rpm
kernel-tools-libs-devel-3.10.0-1062.12.1.el7.ppc64le.rpm
perf-debuginfo-3.10.0-1062.12.1.el7.ppc64le.rpm
python-perf-debuginfo-3.10.0-1062.12.1.el7.ppc64le.rpm
x86_64:
bpftool-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-1062.12.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
Red Hat Enterprise Linux Workstation (v. 7):
Source:
kernel-3.10.0-1062.12.1.el7.src.rpm
noarch:
kernel-abi-whitelists-3.10.0-1062.12.1.el7.noarch.rpm
kernel-doc-3.10.0-1062.12.1.el7.noarch.rpm
x86_64:
bpftool-3.10.0-1062.12.1.el7.x86_64.rpm
bpftool-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debug-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debug-devel-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-devel-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-headers-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-libs-3.10.0-1062.12.1.el7.x86_64.rpm
perf-3.10.0-1062.12.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
python-perf-3.10.0-1062.12.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
Red Hat Enterprise Linux Workstation Optional (v. 7):
x86_64:
bpftool-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-1062.12.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1062.12.1.el7.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2019-14816
https://access.redhat.com/security/cve/CVE-2019-14895
https://access.redhat.com/security/cve/CVE-2019-14898
https://access.redhat.com/security/cve/CVE-2019-14901
https://access.redhat.com/security/cve/CVE-2019-17133
https://access.redhat.com/security/updates/classification/#important
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2020 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBXjnG/NzjgjWX9erEAQiZpA/+PrziwQc9nitsDyWqtq556llAnWG2YjEK
kzbq/d3Vp+7i0aaOHXNG9b6XDgR8kPSLnb/2tCUBQKmLeWEptgY6s24mXXkiAHry
plZ40Xlmca9cjPQCSET7IkQyHlYcUsc9orUT3g1PsZ0uOxPQZ1ivB1utn6nyhbSg
9Az/e/9ai7R++mv4zJ7UDrDzuGPv5SOtyIcfuUyYdbuZO9OrmFsbWCRwG+cVvXJ6
q6uXlIpcWx4H7key9SiboU/VSXXPQ0E5vv1A72biDgCXhm2kYWEJXSwlLH2jJJo7
DfujB4+NSnDVp7Qu0aF/YsEiR9JQfGOOrfuNsmOSdK3Bx3p8LkS4Fd9y3H/fCwjI
EOoXerSgeGjB5E/DtH24HKu1FB5ZniDJP69itCIONokq6BltVZsQRvZxpXQdmvpz
hTJIkYqnuvrkv2liCc8Dr7P7EK0SBPhwhmcBMcAcPHE8BbOtEkcGzF2f2/p/CQci
N0c4UhB2p+eSLq+W4qG4W/ZyyUh2oYdvPjPCrziT1qHOR4ilw9fH9b+jCxmAM7Lh
wqj3yMR9YhUrEBRUUokA/wjggmI88u6I8uQatbf6Keqj1v1CykMKF3AEC5qfxwGz
hk0YzSh0YK6DfybzNxcZK/skcp0Ga0vD+El/nXFI0WGXB8LsQiOUBgfp1JyAlXT6
IwzrfQ6EsXE=
=mofI
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://www.redhat.com/mailman/listinfo/rhsa-announce
.
Here are the details from the Slackware 14.2 ChangeLog:
+--------------------------+
patches/packages/linux-4.4.199/*: Upgraded.
These updates fix various bugs and security issues.
If you use lilo to boot your machine, be sure lilo.conf points to the correct
kernel and initrd and run lilo as root to update the bootloader.
If you use elilo to boot your machine, you should run eliloconfig to copy the
kernel and initrd to the EFI System Partition.
For more information, see:
Fixed in 4.4.191:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-3900
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15118
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10906
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-10905
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10638
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15117
Fixed in 4.4.193:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14835
Fixed in 4.4.194:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14816
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14814
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15505
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14821
Fixed in 4.4.195:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17053
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17052
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17056
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17055
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17054
Fixed in 4.4.196:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-2215
Fixed in 4.4.197:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-16746
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2018-20976
Fixed in 4.4.198:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17075
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-17133
Fixed in 4.4.199:
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-15098
(* Security fix *)
+--------------------------+
Where to find the new packages:
+-----------------------------+
Thanks to the friendly folks at the OSU Open Source Lab
(http://osuosl.org) for donating FTP and rsync hosting
to the Slackware project! :-)
Also see the "Get Slack" section on http://slackware.com for
additional mirror sites near you.
Updated packages for Slackware 14.2:
ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/linux-4.4.199/kernel-generic-4.4.199-i586-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/linux-4.4.199/kernel-generic-smp-4.4.199_smp-i686-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/linux-4.4.199/kernel-headers-4.4.199_smp-x86-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/linux-4.4.199/kernel-huge-4.4.199-i586-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/linux-4.4.199/kernel-huge-smp-4.4.199_smp-i686-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/linux-4.4.199/kernel-modules-4.4.199-i586-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/linux-4.4.199/kernel-modules-smp-4.4.199_smp-i686-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware-14.2/patches/packages/linux-4.4.199/kernel-source-4.4.199_smp-noarch-1.txz
Updated packages for Slackware x86_64 14.2:
ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/linux-4.4.199/kernel-generic-4.4.199-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/linux-4.4.199/kernel-headers-4.4.199-x86-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/linux-4.4.199/kernel-huge-4.4.199-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/linux-4.4.199/kernel-modules-4.4.199-x86_64-1.txz
ftp://ftp.slackware.com/pub/slackware/slackware64-14.2/patches/packages/linux-4.4.199/kernel-source-4.4.199-noarch-1.txz
MD5 signatures:
+-------------+
Slackware 14.2 packages:
0e523f42e759ecc2399f36e37672f110 kernel-generic-4.4.199-i586-1.txz
ee6451f5362008b46fee2e08e3077b21 kernel-generic-smp-4.4.199_smp-i686-1.txz
a8338ef88f2e3ea9c74d564c36ccd420 kernel-headers-4.4.199_smp-x86-1.txz
cd9e9c241e4eec2fba1dae658a28870e kernel-huge-4.4.199-i586-1.txz
842030890a424023817d42a83a86a7f4 kernel-huge-smp-4.4.199_smp-i686-1.txz
257db024bb4501548ac9118dbd2d9ae6 kernel-modules-4.4.199-i586-1.txz
96377cbaf7bca55aaca70358c63151a7 kernel-modules-smp-4.4.199_smp-i686-1.txz
0673e86466f9e624964d95107cf6712f kernel-source-4.4.199_smp-noarch-1.txz
Slackware x86_64 14.2 packages:
6d1ff428e7cad6caa8860acc402447a1 kernel-generic-4.4.199-x86_64-1.txz
dadc091dc725b8227e0d1e35098d6416 kernel-headers-4.4.199-x86-1.txz
f5f4c034203f44dd1513ad3504c42515 kernel-huge-4.4.199-x86_64-1.txz
a5337cd8b2ca80d4d93b9e9688e42b03 kernel-modules-4.4.199-x86_64-1.txz
5dd6e46c04f37b97062dc9e52cc38add kernel-source-4.4.199-noarch-1.txz
Installation instructions:
+------------------------+
Upgrade the packages as root:
# upgradepkg kernel-*.txz
If you are using an initrd, you'll need to rebuild it.
For a 32-bit SMP machine, use this command (substitute the appropriate
kernel version if you are not running Slackware 14.2):
# /usr/share/mkinitrd/mkinitrd_command_generator.sh -k 4.4.199-smp | bash
For a 64-bit machine, or a 32-bit uniprocessor machine, use this command
(substitute the appropriate kernel version if you are not running
Slackware 14.2):
# /usr/share/mkinitrd/mkinitrd_command_generator.sh -k 4.4.199 | bash
Please note that "uniprocessor" has to do with the kernel you are running,
not with the CPU. Most systems should run the SMP kernel (if they can)
regardless of the number of cores the CPU has. If you aren't sure which
kernel you are running, run "uname -a". If you see SMP there, you are
running the SMP kernel and should use the 4.4.199-smp version when running
mkinitrd_command_generator. Note that this is only for 32-bit -- 64-bit
systems should always use 4.4.199 as the version.
If you are using lilo or elilo to boot the machine, you'll need to ensure
that the machine is properly prepared before rebooting.
If using LILO:
By default, lilo.conf contains an image= line that references a symlink
that always points to the correct kernel. No editing should be required
unless your machine uses a custom lilo.conf. If that is the case, be sure
that the image= line references the correct kernel file. Either way,
you'll need to run "lilo" as root to reinstall the boot loader.
If using elilo:
Ensure that the /boot/vmlinuz symlink is pointing to the kernel you wish
to use, and then run eliloconfig to update the EFI System Partition.
+-----+
Slackware Linux Security Team
http://slackware.com/gpg-key
security@slackware.com
+------------------------------------------------------------------------+
| To leave the slackware-security mailing list: |
+------------------------------------------------------------------------+
| Send an email to majordomo@slackware.com with this text in the body of |
| the email message: |
| |
| unsubscribe slackware-security |
| |
| You will get a confirmation message back containing instructions to |
| complete the process. Please do not reply to this email address.
Enhancement(s):
* Selective backport: perf: Sync with upstream v4.16 (BZ#1782748)
4. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 16.04 LTS for Ubuntu
14.04 ESM. (CVE-2019-15902)
Update instructions:
The problem can be corrected by updating your system to the following
package versions:
Ubuntu 14.04 ESM:
linux-image-4.4.0-1056-aws 4.4.0-1056.60
linux-image-4.4.0-166-generic 4.4.0-166.195~14.04.1
linux-image-4.4.0-166-generic-lpae 4.4.0-166.195~14.04.1
linux-image-4.4.0-166-lowlatency 4.4.0-166.195~14.04.1
linux-image-4.4.0-166-powerpc-e500mc 4.4.0-166.195~14.04.1
linux-image-4.4.0-166-powerpc-smp 4.4.0-166.195~14.04.1
linux-image-4.4.0-166-powerpc64-emb 4.4.0-166.195~14.04.1
linux-image-4.4.0-166-powerpc64-smp 4.4.0-166.195~14.04.1
linux-image-aws 4.4.0.1056.57
linux-image-generic-lpae-lts-xenial 4.4.0.166.145
linux-image-generic-lts-xenial 4.4.0.166.145
linux-image-lowlatency-lts-xenial 4.4.0.166.145
linux-image-powerpc-e500mc-lts-xenial 4.4.0.166.145
linux-image-powerpc-smp-lts-xenial 4.4.0.166.145
linux-image-powerpc64-emb-lts-xenial 4.4.0.166.145
linux-image-powerpc64-smp-lts-xenial 4.4.0.166.145
linux-image-virtual-lts-xenial 4.4.0.166.145
After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed.
Unless you manually uninstalled the standard kernel metapackages
(e.g. linux-generic, linux-generic-lts-RELEASE, linux-virtual,
linux-powerpc), a standard system upgrade will automatically perform
this as well. Please note that the RDS protocol is blacklisted in Ubuntu by
default. 8) - aarch64, noarch, ppc64le, s390x, x86_64
3.
Bug Fix(es):
* [Azure][8.1] Include patch "PCI: hv: Avoid use of hv_pci_dev->pci_slot
after freeing it" (BZ#1764635)
* block layer: update to v5.3 (BZ#1777766)
* backport xfs: fix missing ILOCK unlock when xfs_setattr_nonsize fails due
to EDQUOT (BZ#1778692)
* Backport important bugfixes from upstream post 5.3 (BZ#1778693)
* LUN path recovery issue with Emulex LPe32002 HBA in RHEL 8.0 Server
during storage side cable pull testing (BZ#1781108)
* cifs tasks enter D state and error out with "CIFS VFS: SMB signature
verification returned error = -5" (BZ#1781110)
* Update CIFS to linux 5.3 (except RDMA and conflicts) (BZ#1781113)
* RHEL8.0 - Regression to RHEL7.6 by changing force_latency found during
RHEL8.0 validation for SAP HANA on POWER (BZ#1781114)
* blk-mq: overwirte performance drops on real MQ device (BZ#1782181)
4. 7) - noarch, x86_64
3.
Bug Fix(es):
* patchset for x86/atomic: Fix smp_mb__{before,after}_atomic() [kernel-rt]
(BZ#1772522)
* kernel-rt: update to the RHEL7.7.z batch#4 source tree (BZ#1780322)
* kvm nx_huge_pages_recovery_ratio=0 is needed to meet KVM-RT low latency
requirement (BZ#1781157)
* kernel-rt: hard lockup panic in during execution of CFS bandwidth period
timer (BZ#1788057)
4
| VAR-201909-0757 | CVE-2019-16649 | plural Supermicro Vulnerabilities related to the use of hard-coded credentials in products |
CVSS V2: 5.0 CVSS V3: 10.0 Severity: CRITICAL |
On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devices. Attackers can use captured credentials to connect virtual USB devices to the server managed by the BMC. plural Supermicro The product contains a vulnerability related to the use of hard-coded credentials.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. SuperMicro Supermicro X10 and so on are all server motherboards of American SuperMicro company. A security vulnerability exists in the virtual media service in several Supermicro products. The following products and versions are affected: SuperMicro Supermicro H11; Supermicro H12; Supermicro M11; Supermicro X9; Supermicro X10; Supermicro X11
| VAR-201909-0725 | CVE-2019-16650 | Supermicro Vulnerability in Permission Management |
CVSS V2: 7.5 CVSS V3: 10.0 Severity: CRITICAL |
On Supermicro X10 and X11 products, a client's access privileges may be transferred to a different client that later has the same socket file descriptor number. In opportunistic circumstances, an attacker can simply connect to the virtual media service, and then connect virtual USB devices to the server managed by the BMC. Supermicro Contains a privilege management vulnerability.Information is obtained, information is altered, and service operation is disrupted (DoS) There is a possibility of being put into a state. SuperMicro Supermicro X10 and Supermicro X11 are both server motherboards of SuperMicro Corporation in the United States. A security vulnerability exists in SuperMicro Supermicro X10 and Supermicro X11
| VAR-201909-0756 | CVE-2019-16645 | Embedthis GoAhead Injection vulnerability in |
CVSS V2: 5.0 CVSS V3: 8.6 Severity: HIGH |
An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker. This could potentially be used in a phishing attack. Embedthis GoAhead There is an injection vulnerability in.Information may be tampered with. Embedthis Software GoAhead is an embedded Web server of American Embedthis Software company. A security vulnerability exists in Embedthis Software GoAhead version 2.5.0
| VAR-201909-0723 | CVE-2019-16533 | DrayTek Vigor2925 Cross-site scripting vulnerability in device firmware |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
On DrayTek Vigor2925 devices with firmware 3.8.4.3, Incorrect Access Control exists in loginset.htm, and can be used to trigger XSS. NOTE: this is an end-of-life product. DrayTek Vigor2925 The device firmware contains a cross-site scripting vulnerability.Information may be obtained and information may be altered. DrayTek Vigor2925 is a wireless firewall router produced by DrayTek, Taiwan. The vulnerability is caused by the lack of correct verification of client data in the WEB application. Attackers can use this vulnerability to execute client code
| VAR-201909-0724 | CVE-2019-16534 | DrayTek Vigor2925 Cross-Site Scripting Vulnerability |
CVSS V2: 4.3 CVSS V3: 6.1 Severity: MEDIUM |
On DrayTek Vigor2925 devices with firmware 3.8.4.3, XSS exists via a crafted WAN name on the General Setup screen. NOTE: this is an end-of-life product. DrayTek Vigor2925 The device firmware contains a cross-site scripting vulnerability.Information may be obtained and information may be altered. DrayTek Vigor2925 is a wireless firewall router from DrayTek, Taiwan. A cross-site scripting vulnerability exists in DrayTek Vigor 2925 with firmware version 3.8.4.3 that could allow an attacker to execute client-side code. The vulnerability stems from the lack of correct validation of client data in WEB applications
| VAR-201909-1376 | CVE-2019-11327 | Topcon Positioning Net-G5 GNSS Receiver Path traversal vulnerability in device firmware |
CVSS V2: 4.0 CVSS V3: 4.9 Severity: MEDIUM |
An issue was discovered on Topcon Positioning Net-G5 GNSS Receiver devices with firmware 5.2.2. The web interface of the product has a local file inclusion vulnerability. An attacker with administrative privileges can craft a special URL to read arbitrary files from the device's files system. Topcon Positioning Net-G5 GNSS Receiver is a multi-frequency GNSS (Global Navigation Satellite System) receiver from Topcon, Japan
| VAR-201909-1668 | No CVE | Command execution vulnerability exists in sweeping robot of Shenzhen Shanchuan Robot Co., Ltd. |
CVSS V2: 7.6 CVSS V3: - Severity: HIGH |
Shenzhen Shanchuan Robot Co., Ltd. is a high-tech enterprise focusing on the research and development, production and sales of sweeping robots.
There is a command execution vulnerability in the sweeping robot of Shenzhen Shanchuan Robot Co., Ltd. An attacker can use this vulnerability to interact with the server to execute commands remotely, posing information leakage and operational security risks.
| VAR-201909-0994 | CVE-2019-13528 | Niagara AX and Niagara Authentication vulnerability |
CVSS V2: 2.1 CVSS V3: 4.4 Severity: MEDIUM |
A specific utility may allow an attacker to gain read access to privileged files in the Niagara AX 3.8u4 (JACE 3e, JACE 6e, JACE 7, JACE-8000), Niagara 4.4u3 (JACE 3e, JACE 6e, JACE 7, JACE-8000), and Niagara 4.7u1 (JACE-8000, Edge 10). Niagara AX and Niagara Contains an authentication vulnerability.Information may be obtained