SUSE-SU-2021:3807-1: important: Security update for the Linux Kernel

sle-updates at sle-updates at
Thu Nov 25 17:33:48 UTC 2021

   SUSE Security Update: Security update for the Linux Kernel

Announcement ID:    SUSE-SU-2021:3807-1
Rating:             important
References:         #1094840 #1152489 #1169263 #1170269 #1188601 
                    #1190523 #1190795 #1191628 #1191790 #1191851 
                    #1191958 #1191961 #1191980 #1192045 #1192229 
                    #1192267 #1192273 #1192328 #1192549 #1192718 
                    #1192740 #1192745 #1192750 #1192753 #1192781 
                    #1192802 #1192896 #1192906 #1192918 
Cross-References:   CVE-2021-0941 CVE-2021-20322 CVE-2021-31916
                    CVE-2021-34981 CVE-2021-37159 CVE-2021-43389
CVSS scores:
                    CVE-2021-0941 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
                    CVE-2021-20322 (SUSE): 7.4 CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
                    CVE-2021-31916 (NVD) : 6.7 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
                    CVE-2021-31916 (SUSE): 6.8 CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
                    CVE-2021-34981 (SUSE): 7.5 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
                    CVE-2021-37159 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
                    CVE-2021-37159 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
                    CVE-2021-43389 (SUSE): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Affected Products:
                    SUSE Linux Enterprise Module for Public Cloud 15-SP2

   An update that solves 6 vulnerabilities and has 23 fixes is
   now available.


   The SUSE Linux Enterprise 15 SP2 Azure kernel was updated to receive
   various security and bugfixes.

   The following security bugs were fixed:

   - Unprivileged BPF has been disabled by default to reduce attack surface
     as too many security issues have happened in the past (jsc#SLE-22573)

     You can reenable via systemctl setting
   /proc/sys/kernel/unprivileged_bpf_disabled to 0.
   (kernel.unprivileged_bpf_disabled = 0)

   - CVE-2021-0941: In bpf_skb_change_head of filter.c, there is a possible
     out of bounds read due to a use after free. This could lead to local
     escalation of privilege with System execution privileges needed. User
     interaction is not needed for exploitation (bnc#1192045).
   - CVE-2021-31916: An out-of-bounds (OOB) memory write flaw was found in
     list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module
     in the Linux kernel A bound check failure allowed an attacker with
     special user (CAP_SYS_ADMIN) privilege to gain access to out-of-bounds
     memory leading to a system crash or a leak of internal kernel
     information. The highest threat from this vulnerability is to system
     availability (bnc#1192781).
   - CVE-2021-20322: Make the ipv4 and ipv6 ICMP exception caches less
     predictive to avoid information leaks about UDP ports in use.
   - CVE-2021-34981: Fixed file refcounting in cmtp when cmtp_attach_device
     fails  (bsc#1191961).
   - CVE-2021-43389: There was an array-index-out-of-bounds flaw in the
     detach_capi_ctr function in drivers/isdn/capi/kcapi.c (bnc#1191958).
   - CVE-2021-37159: hso_free_net_device in drivers/net/usb/hso.c called
     unregister_netdev without checking for the NETREG_REGISTERED state,
     leading to a use-after-free and a double free (bnc#1188601).

   The following non-security bugs were fixed:

   - ABI: sysfs-kernel-slab: Document some stats (git-fixes).
   - ALSA: hda: Reduce udelay() at SKL+ position reporting (git-fixes).
   - ALSA: ua101: fix division by zero at probe (git-fixes).
   - ALSA: usb-audio: Add Audient iD14 to mixer map quirk table (git-fixes).
   - ALSA: usb-audio: Add Schiit Hel device to mixer map quirk table
   - ASoC: cs42l42: Correct some register default values (git-fixes).
   - ASoC: cs42l42: Defer probe if request_threaded_irq() returns
     EPROBE_DEFER (git-fixes).
   - ASoC: cs42l42: Do not set defaults for volatile registers (git-fixes).
   - ASoC: dt-bindings: cs42l42: Correct description of ts-inv (git-fixes).
   - ASoC: mediatek: mt8195: Remove unsued irqs_lock (git-fixes).
   - ASoC: rockchip: Use generic dmaengine code (git-fixes).
   - Bluetooth: btmtkuart: fix a memleak in mtk_hci_wmt_sync (git-fixes).
   - Bluetooth: fix init and cleanup of sco_conn.timeout_work (git-fixes).
   - EDAC/sb_edac: Fix top-of-high-memory value for Broadwell/Haswell
   - Eradicate Patch-mainline: No The pre-commit check can reject this
     deprecated tag then.
   - Fix problem with missing installkernel on Tumbleweed.
   - HID: u2fzero: clarify error check and length calculations (git-fixes).
   - HID: u2fzero: properly handle timeouts in usb_submit_urb (git-fixes).
   - Input: elantench - fix misreporting trackpoint coordinates (bsc#1192918).
   - Input: i8042 - Add quirk for Fujitsu Lifebook T725 (bsc#1191980).
   - PCI/ACPI: Check for _OSC support in acpi_pci_osc_control_set()
   - PCI/ACPI: Clarify message about _OSC failure (bsc#1169263).
   - PCI/ACPI: Move _OSC query checks to separate function (bsc#1169263).
   - PCI/ACPI: Move supported and control calculations to separate functions
   - PCI/ACPI: Remove unnecessary osc_lock (bsc#1169263).
   - PCI: aardvark: Do not clear status bits of masked interrupts (git-fixes).
   - PCI: aardvark: Do not spam about PIO Response Status (git-fixes).
   - PCI: aardvark: Do not unmask unused interrupts (git-fixes).
   - PCI: aardvark: Fix checking for link up via LTSSM state (git-fixes).
   - PCI: aardvark: Fix reporting Data Link Layer Link Active (git-fixes).
   - PCI: aardvark: Fix return value of MSI domain .alloc() method
   - PCI: aardvark: Read all 16-bits from PCIE_MSI_PAYLOAD_REG (git-fixes).
   - PCI: pci-bridge-emul: Fix emulation of W1C bits (git-fixes).
   - PCI: uniphier: Serialize INTx masking/unmasking and fix the bit
     operation (git-fixes).
   - Revert "ibmvnic: check failover_pending in login response" (bsc#1190523
   - Revert "platform/x86: i2c-multi-instantiate: Do not create platform
     device for INT3515 ACPI nodes" (git-fixes).
   - Revert "r8152: adjust the settings about MAC clock speed down for
     RTL8153" (git-fixes).
   - Revert "scsi: ufs: fix a missing check of devm_reset_control_get"
   - Revert "x86/kvm: fix vcpu-id indexed array sizes" (git-fixes).
   - USB: iowarrior: fix control-message timeouts (git-fixes).
   - USB: serial: keyspan: fix memleak on probe errors (git-fixes).
   - Update config files: Add CONFIG_BPF_UNPRIV_DEFAULT_OFF is not set
   - Update
     (bsc#1191628 bsc#1192549). dir_cookie is a pointer to the cookie in
     older kernels, not the cookie itself.
   - ata: sata_mv: Fix the error handling of mv_chip_id() (git-fixes).
   - ath10k: Fix missing frame timestamp for beacon/probe-resp (git-fixes).
   - ath10k: fix control-message timeout (git-fixes).
   - ath10k: fix division by zero in send path (git-fixes).
   - ath10k: fix max antenna gain unit (git-fixes).
   - ath6kl: fix control-message timeout (git-fixes).
   - ath6kl: fix division by zero in send path (git-fixes).
   - ath9k: Fix potential interrupt storm on queue reset (git-fixes).
   - auxdisplay: ht16k33: Connect backlight to fbdev (git-fixes).
   - auxdisplay: ht16k33: Fix frame buffer device blanking (git-fixes).
   - auxdisplay: img-ascii-lcd: Fix lock-up when displaying empty string
   - b43: fix a lower bounds test (git-fixes).
   - b43legacy: fix a lower bounds test (git-fixes).
   - bpf: Add kconfig knob for disabling unpriv bpf by default (jsc#SLE-22573)
   - bpf: Disallow unprivileged bpf by default (jsc#SLE-22573).
   - bpf: Fix potential race in tail call compatibility check (git-fixes).
   - btrfs: block-group: Rework documentation of check_system_chunk function
   - btrfs: fix deadlock between chunk allocation and chunk btree
     modifications (bsc#1192896).
   - btrfs: fix memory ordering between normal and ordered work functions
   - btrfs: update comments for chunk allocation -ENOSPC cases (bsc#1192896).
   - cgroup/cpuset: Change references of cpuset_mutex to cpuset_rwsem
   - config: disable unprivileged BPF by default (jsc#SLE-22573)
   - crypto: caam - disable pkc for non-E SoCs (git-fixes).
   - crypto: pcrypt - Delay write to padata->info (git-fixes).
   - crypto: qat - detect PFVF collision after ACK (git-fixes).
   - crypto: qat - disregard spurious PFVF interrupts (git-fixes).
   - driver core: add a min_align_mask field to struct device_dma_parameters
   - drm/amdgpu: fix warning for overflow check (git-fixes).
   - drm/msm: Fix potential NULL dereference in DPU SSPP (git-fixes).
   - drm/sun4i: Fix macros in sun8i_csc.h (git-fixes).
   - drm/v3d: fix wait for TMU write combiner flush (git-fixes).
   - drm: prevent spectre issue in vmw_execbuf_ioctl (bsc#1192802).
   - exfat: fix erroneous discard when clear cluster bit (git-fixes).
   - exfat: handle wrong stream entry size in exfat_readdir() (git-fixes).
   - exfat: properly set s_time_gran (bsc#1192328).
   - exfat: truncate atimes to 2s granularity (bsc#1192328).
   - firmware/psci: fix application of sizeof to pointer (git-fixes).
   - ftrace: Fix scripts/ due to new binutils (bsc#1192267).
   - fuse: fix page stealing (bsc#1192718).
   - genirq: Provide IRQCHIP_AFFINITY_PRE_STARTUP (bsc#1152489).
   - gpio: mpc8xxx: Use 'devm_gpiochip_add_data()' to simplify the code and
     avoid a leak (git-fixes).
   - hwmon: (pmbus/lm25066) Add offset coefficients (git-fixes).
   - hwmon: (pmbus/lm25066) Let compiler determine outer dimension of
     lm25066_coeff (git-fixes).
   - hwmon: Fix possible memleak in __hwmon_device_register() (git-fixes).
   - hwrng: mtk - Force runtime pm ops for sleep ops (git-fixes).
   - ibmvnic: Process crqs after enabling interrupts (bsc#1192273 ltc#194629).
   - ibmvnic: check failover_pending in login response (bsc#1190523
   - ibmvnic: delay complete() (bsc#1094840 ltc#167098 git-fixes).
   - ibmvnic: do not stop queue in xmit (bsc#1192273 ltc#194629).
   - iio: dac: ad5446: Fix ad5622_write() return value (git-fixes).
   - kABI: Fix kABI after 36950f2da1ea (bsc#1191851).
   - kernel-*-subpackage: Add dependency on kernel scriptlets (bsc#1192740).
   - libertas: Fix possible memory leak in probe and disconnect (git-fixes).
   - libertas_tf: Fix possible memory leak in probe and disconnect
   - media: TDA1997x: handle short reads of hdmi info frame (git-fixes).
   - media: cedrus: Fix SUNXI tile size calculation (git-fixes).
   - media: cx23885: Fix snd_card_free call on null card pointer (git-fixes).
   - media: cxd2880-spi: Fix a null pointer dereference on error handling
     path (git-fixes).
   - media: dvb-frontends: mn88443x: Handle errors of clk_prepare_enable()
   - media: dvb-usb: fix ununit-value in az6027_rc_query (git-fixes).
   - media: em28xx: Do not use ops->suspend if it is NULL (git-fixes).
   - media: em28xx: add missing em28xx_close_extension (git-fixes).
   - media: i2c: ths8200 needs V4L2_ASYNC (git-fixes).
   - media: ite-cir: IR receiver stop working after receive overflow
   - media: mtk-vpu: Fix a resource leak in the error handling path of
     'mtk_vpu_probe()' (git-fixes).
   - media: mxl111sf: change mutex_init() location (git-fixes).
   - media: radio-wl1273: Avoid card name truncation (git-fixes).
   - media: si470x: Avoid card name truncation (git-fixes).
   - media: staging/intel-ipu3: css: Fix wrong size comparison
     imgu_css_fw_init (git-fixes).
   - media: tm6000: Avoid card name truncation (git-fixes).
   - media: v4l2-ioctl: Fix check_ext_ctrls (git-fixes).
   - media: v4l2-ioctl: S_CTRL output the right value (git-fixes).
   - memory: fsl_ifc: fix leak of irq and nand_irq in fsl_ifc_ctrl_probe
   - memstick: avoid out-of-range warning (git-fixes).
   - memstick: jmb38x_ms: use appropriate free function in
     jmb38x_ms_alloc_host() (git-fixes).
   - mm/hugetlb: initialize hugetlb_usage in mm_init (bsc#1192906).
   - mmc: mxs-mmc: disable regulator on error and in the remove function
   - mmc: sdhci-omap: Fix NULL pointer exception if regulator is not
     configured (git-fixes).
   - mmc: sdhci: Map more voltage level to SDHCI_POWER_330 (git-fixes).
   - mt76: mt76x02: fix endianness warnings in mt76x02_mac.c (git-fixes).
   - mwifiex: Send DELBA requests according to spec (git-fixes).
   - mwifiex: fix division by zero in fw download path (git-fixes).
   - net: dsa: felix: re-enable TX flow control in ocelot_port_flush()
   - net: mscc: ocelot: fix hardware timestamp dequeue logic.
   - net: mscc: ocelot: warn when a PTP IRQ is raised for an unknown skb
   - nvme-pci: set min_align_mask (bsc#1191851).
   - ocfs2: do not zero pages beyond i_size (bsc#1190795).
   - ocfs2: fix data corruption on truncate (bsc#1190795).
   - pinctrl: core: fix possible memory leak in pinctrl_enable() (git-fixes).
   - platform/x86: thinkpad_acpi: Fix bitwise vs. logical warning (git-fixes).
   - power: supply: bq27xxx: Fix kernel crash on IRQ handler register error
   - power: supply: max17042_battery: Prevent int underflow in
     set_soc_threshold (git-fixes).
   - power: supply: max17042_battery: use VFSOC for capacity when no rsns
   - printk/console: Allow to disable console output by using console="" or
     console=null (bsc#1192753).
   - printk: handle blank console arguments passed in (bsc#1192753).
   - qtnfmac: fix potential Spectre vulnerabilities (bsc#1192802).
   - r8152: Add macpassthru support for ThinkPad Thunderbolt 3 Dock Gen 2
   - r8152: Disable PLA MCU clock speed down (git-fixes).
   - r8152: add a helper function about setting EEE (git-fixes).
   - r8152: disable U2P3 for RTL8153B (git-fixes).
   - r8152: divide the tx and rx bottom functions (git-fixes).
   - r8152: do not enable U1U2 with USB_SPEED_HIGH for RTL8153B (git-fixes).
   - r8152: fix runtime resume for linking change (git-fixes).
   - r8152: limit the RX buffer size of RTL8153A for USB 2.0 (git-fixes).
   - r8152: replace array with linking list for rx information (git-fixes).
   - r8152: reset flow control patch when linking on for RTL8153B (git-fixes).
   - r8152: saving the settings of EEE (git-fixes).
   - r8152: separate the rx buffer size (git-fixes).
   - r8152: use alloc_pages for rx buffer (git-fixes).
   - regulator: dt-bindings: samsung,s5m8767: correct
     s5m8767,pmic-buck-default-dvs-idx property (git-fixes).
   - regulator: s5m8767: do not use reset value as DVS voltage if GPIO DVS is
     disabled (git-fixes).
   - rndis_host: set proper input size for OID_GEN_PHYSICAL_MEDIUM request
   - rsi: Fix module dev_oper_mode parameter description (git-fixes).
   - rsi: fix control-message timeout (git-fixes).
   - rsi: stop thread firstly in rsi_91x_init() error handling (git-fixes).
   - rtl8187: fix control-message timeouts (git-fixes).
   - s390/qeth: Fix deadlock in remove_discipline (git-fixes).
   - s390/qeth: fix NULL deref in qeth_clear_working_pool_list() (git-fixes).
   - s390/qeth: fix deadlock during failing recovery (git-fixes).
   - scsi: BusLogic: Fix missing pr_cont() use (git-fixes).
   - scsi: FlashPoint: Rename si_flags field (git-fixes).
   - scsi: be2iscsi: Fix an error handling path in beiscsi_dev_probe()
   - scsi: core: Fix spelling in a source code comment (git-fixes).
   - scsi: csiostor: Add module softdep on cxgb4 (git-fixes).
   - scsi: csiostor: Uninitialized data in csio_ln_vnp_read_cbfn()
   - scsi: dc395: Fix error case unwinding (git-fixes).
   - scsi: fdomain: Fix error return code in fdomain_probe() (git-fixes).
   - scsi: iscsi: Fix iface sysfs attr detection (git-fixes).
   - scsi: libsas: Use _safe() loop in sas_resume_port() (git-fixes).
   - scsi: mpt3sas: Fix error return value in _scsih_expander_add()
   - scsi: qedf: Add pointer checks in qedf_update_link_speed() (git-fixes).
   - scsi: qedf: Fix error codes in qedf_alloc_global_queues() (git-fixes).
   - scsi: qedi: Fix error codes in qedi_alloc_global_queues() (git-fixes).
   - scsi: qla2xxx: Fix a memory leak in an error path of
     qla2x00_process_els() (git-fixes).
   - scsi: qla2xxx: Make sure that aborted commands are freed (git-fixes).
   - scsi: smartpqi: Fix an error code in pqi_get_raid_map() (git-fixes).
   - scsi: snic: Fix an error message (git-fixes).
   - scsi: ufs-pci: Add quirk for broken auto-hibernate for Intel EHL
   - scsi: ufs: ufshcd-pltfrm: Fix memory leak due to probe defer (git-fixes).
   - serial: 8250_dw: Drop wrong use of ACPI_PTR() (git-fixes).
   - serial: xilinx_uartps: Fix race condition causing stuck TX (git-fixes).
   - series.conf: cleanup
   - series.conf: cleanup
   - series.conf: whitespace and comment cleanup No effect on expanded tree.
   - staging: r8712u: fix control-message timeout (git-fixes).
   - staging: rtl8192u: fix control-message timeouts (git-fixes).
   - stmmac: platform: Fix signedness bug in stmmac_probe_config_dt()
   - swiotlb-xen: avoid double free (git-fixes).
   - swiotlb: Split size parameter to map/unmap APIs (bsc#1191851).
   - swiotlb: add a IO_TLB_SIZE define (bsc#1191851).
   - swiotlb: clean up swiotlb_tbl_unmap_single (bsc#1191851).
   - swiotlb: do not modify orig_addr in swiotlb_tbl_sync_single
   - swiotlb: factor out a nr_slots helper (bsc#1191851).
   - swiotlb: factor out an io_tlb_offset helper (bsc#1191851).
   - swiotlb: refactor swiotlb_tbl_map_single (bsc#1191851).
   - swiotlb: respect min_align_mask (bsc#1191851).
   - tpm: Check for integer overflow in tpm2_map_response_body() (git-fixes).
   - tracing/histogram: Do not copy the fixed-size char array field over the
     field size (git-fixes).
   - tracing: Increase PERF_MAX_TRACE_SIZE to handle Sentinel1 and docker
     together (bsc#1192745).
   - tracing: use %ps format string to print symbols (git-fixes).
   - usb: gadget: hid: fix error code in do_config() (git-fixes).
   - usb: max-3421: Use driver data instead of maintaining a list of bound
     devices (git-fixes).
   - usb: musb: Balance list entry in musb_gadget_queue (git-fixes).
   - usbnet: fix error return code in usbnet_probe() (git-fixes).
   - usbnet: sanity check for maxpacket (git-fixes).
   - video: fbdev: chipsfb: use memset_io() instead of memset() (git-fixes).
   - virtio-gpu: fix possible memory allocation failure (git-fixes).
   - wcn36xx: Add ability for wcn36xx_smd_dump_cmd_req to pass two's
     complement (git-fixes).
   - wcn36xx: Fix HT40 capability for 2Ghz band (git-fixes).
   - wcn36xx: add proper DMA memory barriers in rx path (git-fixes).
   - x86/Xen: swap NX determination and GDT setup on BSP (git-fixes).
   - x86/ioapic: Force affinity setup before startup (bsc#1152489).
   - x86/msi: Force affinity setup before startup (bsc#1152489).
   - x86/sme: Use #define USE_EARLY_PGTABLE_L5 in mem_encrypt_identity.c
   - x86/xen: Mark cpu_bringup_and_idle() as dead_end_function (git-fixes).
   - xen-pciback: Fix return in pm_ctrl_init() (git-fixes).
   - xen/privcmd: fix error handling in mmap-resource processing (git-fixes).
   - xen/x86: fix PV trap handling on secondary processors (git-fixes).
   - xen: Fix implicit type conversion (git-fixes).
   - xfs: do not allow log writes if the data device is readonly

Special Instructions and Notes:

   Please reboot the system after installing this update.

Patch Instructions:

   To install this SUSE Security Update use the SUSE recommended installation methods
   like YaST online_update or "zypper patch".

   Alternatively you can run the command listed for your product:

   - SUSE Linux Enterprise Module for Public Cloud 15-SP2:

      zypper in -t patch SUSE-SLE-Module-Public-Cloud-15-SP2-2021-3807=1

Package List:

   - SUSE Linux Enterprise Module for Public Cloud 15-SP2 (noarch):


   - SUSE Linux Enterprise Module for Public Cloud 15-SP2 (x86_64):



More information about the sle-updates mailing list