SUSE SLED12 / SLES12 Security Update : kernel (SUSE-SU-2022:0364-1)

high Nessus Plugin ID 157899

Language:

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLED12 / SLES12 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2022:0364-1 advisory.

- The vgacon subsystem in the Linux kernel before 5.8.10 mishandles software scrollback. There is a vgacon_scrolldelta out-of-bounds read, aka CID-973c096f6a85. (CVE-2020-28097)

- A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux kernel versions starting from 3.13. (CVE-2021-3564)

- In gadget_dev_desc_UDC_show of configfs.c, there is a possible disclosure of kernel heap memory due to a race condition. This could lead to local information disclosure with System execution privileges needed.
User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID:
A-160822094References: Upstream kernel (CVE-2021-39648)

- In ufshcd_eh_device_reset_handler of ufshcd.c, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed.
User interaction is not needed for exploitation.Product: AndroidVersions: Android kernelAndroid ID:
A-194696049References: Upstream kernel (CVE-2021-39657)

- A read-after-free memory flaw was found in the Linux kernel's garbage collection for Unix domain socket file handlers in the way users call close() and fget() simultaneously and can potentially trigger a race condition. This flaw allows a local user to crash the system or escalate their privileges on the system.
This flaw affects Linux kernel versions prior to 5.16-rc4. (CVE-2021-4083)

- A denial of service flaw for virtual machine guests in the Linux kernel's Xen hypervisor subsystem was found in the way users call some interrupts with high frequency from one of the guests.A local user could use this flaw to starve the resources resulting in a denial of service. (CVE-2021-28711) (CVE-2021-4135)

- A use-after-free exists in drivers/tee/tee_shm.c in the TEE subsystem in the Linux kernel through 5.15.11.
This occurs because of a race condition in tee_shm_get_from_id during an attempt to free a shared memory object. (CVE-2021-44733)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1065729

https://bugzilla.suse.com/1071995

https://bugzilla.suse.com/1082555

https://bugzilla.suse.com/1163405

https://bugzilla.suse.com/1177599

https://bugzilla.suse.com/1183405

https://bugzilla.suse.com/1184209

https://bugzilla.suse.com/1186207

https://bugzilla.suse.com/1186222

https://bugzilla.suse.com/1187428

https://bugzilla.suse.com/1187723

https://bugzilla.suse.com/1188605

https://bugzilla.suse.com/1190973

https://bugzilla.suse.com/1192729

https://bugzilla.suse.com/1193096

https://bugzilla.suse.com/1193234

https://bugzilla.suse.com/1193235

https://bugzilla.suse.com/1193242

https://bugzilla.suse.com/1193507

https://bugzilla.suse.com/1193660

https://bugzilla.suse.com/1193669

https://bugzilla.suse.com/1193727

https://bugzilla.suse.com/1193767

https://bugzilla.suse.com/1193861

https://bugzilla.suse.com/1193864

https://bugzilla.suse.com/1193927

https://bugzilla.suse.com/1194001

https://bugzilla.suse.com/1194027

https://bugzilla.suse.com/1194227

https://bugzilla.suse.com/1194302

https://bugzilla.suse.com/1194410

https://bugzilla.suse.com/1194493

https://bugzilla.suse.com/1194516

https://bugzilla.suse.com/1194529

https://bugzilla.suse.com/1194814

https://bugzilla.suse.com/1194880

https://bugzilla.suse.com/1194888

https://bugzilla.suse.com/1194965

https://bugzilla.suse.com/1194985

https://bugzilla.suse.com/1195065

https://bugzilla.suse.com/1195073

https://bugzilla.suse.com/1195254

https://bugzilla.suse.com/1195272

http://www.nessus.org/u?397f8c83

https://www.suse.com/security/cve/CVE-2020-28097

https://www.suse.com/security/cve/CVE-2021-3564

https://www.suse.com/security/cve/CVE-2021-39648

https://www.suse.com/security/cve/CVE-2021-39657

https://www.suse.com/security/cve/CVE-2021-4083

https://www.suse.com/security/cve/CVE-2021-4135

https://www.suse.com/security/cve/CVE-2021-4149

https://www.suse.com/security/cve/CVE-2021-4197

https://www.suse.com/security/cve/CVE-2021-4202

https://www.suse.com/security/cve/CVE-2021-44733

https://www.suse.com/security/cve/CVE-2022-0322

https://www.suse.com/security/cve/CVE-2022-0330

https://www.suse.com/security/cve/CVE-2022-0435

https://www.suse.com/security/cve/CVE-2022-22942

Plugin Details

Severity: High

ID: 157899

File Name: suse_SU-2022-0364-1.nasl

Version: 1.5

Type: local

Agent: unix

Published: 2/11/2022

Updated: 4/26/2022

Supported Sensors: Agentless Assessment, Frictionless Assessment Agent, Frictionless Assessment AWS, Frictionless Assessment Azure, Nessus Agent

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: High

Base Score: 9

Temporal Score: 7

Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Temporal Vector: E:POC/RL:OF/RC:C

CVSS Score Source: CVE-2022-0435

CVSS v3

Risk Factor: High

Base Score: 8.8

Temporal Score: 7.9

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: E:P/RL:O/RC:C

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:cluster-md-kmp-default, p-cpe:/a:novell:suse_linux:dlm-kmp-default, p-cpe:/a:novell:suse_linux:gfs2-kmp-default, p-cpe:/a:novell:suse_linux:kernel-default, p-cpe:/a:novell:suse_linux:kernel-default-base, p-cpe:/a:novell:suse_linux:kernel-default-devel, p-cpe:/a:novell:suse_linux:kernel-default-extra, p-cpe:/a:novell:suse_linux:kernel-default-kgraft, p-cpe:/a:novell:suse_linux:kernel-default-kgraft-devel, p-cpe:/a:novell:suse_linux:kernel-default-man, p-cpe:/a:novell:suse_linux:kernel-devel, p-cpe:/a:novell:suse_linux:kernel-macros, p-cpe:/a:novell:suse_linux:kernel-obs-build, p-cpe:/a:novell:suse_linux:kernel-source, p-cpe:/a:novell:suse_linux:kernel-syms, p-cpe:/a:novell:suse_linux:kgraft-patch-4_12_14-122_110-default, p-cpe:/a:novell:suse_linux:ocfs2-kmp-default, cpe:/o:novell:suse_linux:12

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 2/10/2022

Vulnerability Publication Date: 5/26/2021

Reference Information

CVE: CVE-2020-28097, CVE-2021-3564, CVE-2021-4083, CVE-2021-4135, CVE-2021-4149, CVE-2021-4197, CVE-2021-4202, CVE-2021-39648, CVE-2021-39657, CVE-2021-44733, CVE-2022-0322, CVE-2022-0330, CVE-2022-0435, CVE-2022-22942

SuSE: SUSE-SU-2022:0364-1