OESA-2021-1318
Dashboard / Vulnerabilities / OESA-2021-1318
OESA-2021-1318
Summary: kernel security update
Details: The Linux Kernel, the operating system core itself. Security Fix(es): A lack of CPU resource in the Linux kernel tracing module functionality in versions prior to 5.14-rc3 was found in the way user uses trace ring buffer in a specific way. Only privileged local users (with CAP_SYS_ADMIN capability) could use this flaw to starve the resources causing denial of service.(CVE-2021-3679) drivers/usb/host/max3421-hcd.c in the Linux kernel before 5.13.6 allows physically proximate attackers to cause a denial of service (use-after-free and panic) by removing a MAX-3421 USB device in certain situations.(CVE-2021-38204) drivers/net/ethernet/xilinx/xilinx_emaclite.c in the Linux kernel before 5.13.3 makes it easier for attackers to defeat an ASLR protection mechanism because it prints a kernel pointer (i.e., the real IOMEM pointer).(CVE-2021-38205) net/netfilter/nf_conntrack_standalone.c in the Linux kernel before 5.12.2 allows observation of changes in any net namespace because these changes are leaked into all other net namespaces. This is related to the NF_SYSCTL_CT_MAX, NF_SYSCTL_CT_EXPECT_MAX, and NF_SYSCTL_CT_BUCKETS sysctls.(CVE-2021-38209) fs/nfs/nfs4client.c in the Linux kernel before 5.13.4 has incorrect connection-setup ordering, which allows operators of remote NFSv4 servers to cause a denial of service (hanging of mounts) by arranging for those servers to be unreachable during trunking detection.(CVE-2021-38199) drivers/net/ethernet/xilinx/ll_temac_main.c in the Linux kernel before 5.12.13 allows remote attackers to cause a denial of service (buffer overflow and lockup) by sending heavy network traffic for about ten minutes.(CVE-2021-38207) net/nfc/llcp_sock.c in the Linux kernel before 5.12.10 allows local unprivileged users to cause a denial of service (NULL pointer dereference and BUG) by making a getsockname call after a certain type of failure of a bind call.(CVE-2021-38208)
References: https://openeuler.org/en/security/safety-bulletin/detail.html?id=openEuler-SA-2021-1318, https://nvd.nist.gov/vuln/detail/CVE-2021-3679, https://nvd.nist.gov/vuln/detail/CVE-2021-38204, https://nvd.nist.gov/vuln/detail/CVE-2021-38205, https://nvd.nist.gov/vuln/detail/CVE-2021-38209, https://nvd.nist.gov/vuln/detail/CVE-2021-38199, https://nvd.nist.gov/vuln/detail/CVE-2021-38207, https://nvd.nist.gov/vuln/detail/CVE-2021-38208
Affected packages
Package
Name: kernel
Purl: pkg:rpm/openEuler/kernel&distro=openEuler-20.03-LTS-SP1
Affected ranges
Type: ECOSYSTEM
Events:
