SUSE: 2020:1085-1 important: the Linux Kernel
Summary
The SUSE Linux Enterprise 12 SP4 RT kernel was updated to 3.12.31 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-8834: KVM on Power8 processors had a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entry plus in kvmppc_{save,restore}_tm, leading to a stack corruption. Because of this, an attacker with the ability to run code in kernel space of a guest VM can cause the host kernel to panic (bnc#1168276). - CVE-2020-11494: An issue was discovered in slc_bump in drivers/net/can/slcan.c, which allowed attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration lacks CONFIG_INIT_STACK_ALL (bnc#1168424). - CVE-2020-10942: In get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted sy...
Read the Full AdvisoryReferences
#1044231 #1050549 #1051510 #1051858 #1056686
#1060463 #1065600 #1065729 #1083647 #1085030
#1104967 #1109911 #1114279 #1118338 #1120386
#1133021 #1136157 #1137325 #1144333 #1145051
#1145929 #1146539 #1148868 #1154385 #1157424
#1158552 #1158983 #1159037 #1159142 #1159198
#1159285 #1160659 #1161951 #1162929 #1162931
#1163403 #1163508 #1163897 #1164078 #1164284
#1164507 #1164893 #1165019 #1165111 #1165182
#1165404 #1165488 #1165527 #1165741 #1165813
#1165873 #1165949 #1165984 #1165985 #1166003
#1166101 #1166102 #1166103 #1166104 #1166632
#1166730 #1166731 #1166732 #1166733 #1166734
#1166735 #1166780 #1166860 #1166861 #1166862
#1166864 #1166866 #1166867 #1166868 #1166870
#1166940 #116...
Read the Full Advisory