An update for kernel/ipa is now available for NewStart CGSL MAIN 5.04/CGSL CORE 5.04. NewStart Security has rated this update as having a security impact of important. A Common Vunlnerability Scoring System(CVSS)base score, which gives a detailed severity rating, is available for each vulnerability from the CVElink(s) in the References section.
详细描述
kernel: The python-perf package contains a module that permits applications written in the Python programming language to use the interface to manipulate perf events. ipa: Cross-realm trusts with Active Directory in IPA require working Samba 4 installation. This package is provided for convenience to install all required dependencies at once.
Security Fix(es): kernel: An out-of-bounds write flaw was found in the Linux kernel’s HID drivers. An attacker, able to plug in a malicious USB device, can crash the system or read and write to memory with an incorrect address.(CVE-2019-19532) kernel: A flaw was found in the Linux pinctrl system. It is possible to trigger an of bounds read due to a use after free. This could lead to local information disclosure with no additional execution privileges needed.(CVE-2020-0427) kernel: A flaw was found in the Linux kernel. A use-after-free memory flaw was found in the perf subsystem allowing a local attacker with permission to monitor perf events to corrupt memory and possibly escalate privileges. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.(CVE-2020-14351) kernel: A flaw was found in the Linux kernel. A local attacker, able to inject conntrack netlink configuration, could overflow a local buffer causing crashes or triggering the use of incorrect protocol numbers in ctnetlink_parse_tuple_filter in net/netfilter/nf_conntrack_netlink.c. The highest threat from this vulnerability is to data confidentiality and integrity as well as system availability.(CVE-2020-25211) kernel: A flaw was found in the Linux kernel. Traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone in between the two endpoints to read the traffic unencrypted. The main threat from this vulnerability is to data confidentiality.(CVE-2020-25645) kernel: A flaw in the way reply ICMP packets are limited in the Linux kernel functionality was found that allows to quickly scan open UDP ports. This flaw allows an off-path remote user to effectively bypassing source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software that relies on UDP source port randomization are indirectly affected as well.(CVE-2020-25705) kernel: A locking vulnerability was found in the tty subsystem of the Linux kernel in drivers/tty/tty_jobctrl.c. This flaw allows a local attacker to possibly corrupt memory or escalate privileges. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.(CVE-2020-29661) kernel: A flaw was found in the way memory resources were freed in the unix_stream_recvmsg function in the Linux kernel when a signal was pending. This flaw allows an unprivileged local user to crash the system by exhausting available memory. The highest threat from this vulnerability is to system availability.(CVE-2021-20265) kernel: bugfix ipa: A flaw was found in jQuery. HTML containing
影响组件
kernel
ipa
影响产品
CGSL MAIN 5.04
CGSL CORE 5.04
更新包
{"fix":[{"product":"CGSL MAIN 5.04","pkgs":[{"binary":["kernel-debug-devel-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.x86_64.rpm","kernel-debug-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.x86_64.rpm","kernel-debug-debuginfo-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.x86_64.rpm","kernel-debuginfo-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.x86_64.rpm","perf-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.x86_64.rpm","kernel-abi-whitelists-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.noarch.rpm","kernel-headers-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.x86_64.rpm","kernel-doc-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.noarch.rpm","python-perf-debuginfo-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.x86_64.rpm","perf-debuginfo-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.x86_64.rpm","kernel-sign-keys-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.x86_64.rpm","kernel-tools-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.x86_64.rpm","kernel-debuginfo-common-x86_64-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.x86_64.rpm","kernel-devel-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.x86_64.rpm","kernel-tools-debuginfo-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.x86_64.rpm","kernel-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.x86_64.rpm","kernel-tools-libs-devel-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.x86_64.rpm","kernel-tools-libs-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.x86_64.rpm","python-perf-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.x86_64.rpm"],"source":"kernel-3.10.0-693.21.1.el7.cgslv5_4.55.1018.g3790d29.src.rpm"},{"binary":["ipa-debuginfo-4.6.8-5.el7.centos.4.x86_64.rpm","ipa-python-compat-4.6.8-5.el7.centos.4.noarch.rpm","ipa-server-common-4.6.8-5.el7.centos.4.noarch.rpm","ipa-common-4.6.8-5.el7.centos.4.noarch.rpm","ipa-server-dns-4.6.8-5.el7.centos.4.noarch.rpm","python2-ipaserver-4.6.8-5.el7.centos.4.noarch.rpm","ipa-client-common-4.6.8-5.el7.centos.4.noarch.rpm","ipa-server-4.6.8-5.el7.centos.4.x86_64.rpm","ipa-server-trust-ad-4.6.8-5.el7.centos.4.x86_64.rpm","ipa-client-4.6.8-5.el7.centos.4.x86_64.rpm","python2-ipalib-4.6.8-5.el7.centos.4.noarch.rpm","python2-ipaclient-4.6.8-5.el7.centos.4.noarch.rpm"],"source":"ipa-4.6.8-5.el7.centos.4.src.rpm"}]},{"product":"CGSL CORE 5.04","pkgs":[{"binary":["kernel-tools-debuginfo-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm","kernel-sign-keys-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm","kernel-tools-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm","kernel-tools-libs-devel-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm","python-perf-debuginfo-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm","kernel-debug-devel-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm","kernel-debug-core-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm","kernel-debuginfo-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm","kernel-tools-libs-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm","kernel-modules-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm","perf-debuginfo-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm","perf-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm","kernel-devel-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm","kernel-headers-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm","kernel-doc-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.noarch.rpm","kernel-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm","python-perf-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm","kernel-abi-whitelists-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.noarch.rpm","kernel-debug-modules-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm","kernel-debug-debuginfo-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm","kernel-debuginfo-common-x86_64-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm","kernel-core-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.x86_64.rpm"],"source":"kernel-3.10.0-693.21.1.el7.cgslv5_4.57.952.g813b7c9.lite.src.rpm"},{"binary":["ipa-debuginfo-4.6.8-5.el7.centos.4.x86_64.rpm","ipa-python-compat-4.6.8-5.el7.centos.4.noarch.rpm","ipa-server-common-4.6.8-5.el7.centos.4.noarch.rpm","ipa-common-4.6.8-5.el7.centos.4.noarch.rpm","ipa-server-dns-4.6.8-5.el7.centos.4.noarch.rpm","python2-ipaserver-4.6.8-5.el7.centos.4.noarch.rpm","ipa-client-common-4.6.8-5.el7.centos.4.noarch.rpm","ipa-server-4.6.8-5.el7.centos.4.x86_64.rpm","ipa-server-trust-ad-4.6.8-5.el7.centos.4.x86_64.rpm","ipa-client-4.6.8-5.el7.centos.4.x86_64.rpm","python2-ipalib-4.6.8-5.el7.centos.4.noarch.rpm","python2-ipaclient-4.6.8-5.el7.centos.4.noarch.rpm"],"source":"ipa-4.6.8-5.el7.centos.4.src.rpm"}]}]}