ALT-BU-2020-3620-1
Branch sisyphus update bulletin.
Package matrix-synapse updated to version 1.8.0-alt1 for branch sisyphus in task 245100.
Closed vulnerabilities
Modified: 2024-11-21
CVE-2019-18835
Matrix Synapse before 1.5.0 mishandles signature checking on some federation APIs. Events sent over /send_join, /send_leave, and /invite may not be correctly signed, or may not come from the expected servers.
Closed bugs
Update to 2.44
Closed bugs
libdwarf-devel: file conflict with libdw-devel
Package kernel-image-un-def updated to version 5.4.15-alt1 for branch sisyphus in task 245170.
Closed vulnerabilities
BDU:2021-05741
Уязвимость реализации файла исходного кода arch/powerpc/kvm/book3s_hv_rmhandlers.S ядра операционных систем Linux, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2021-43056
An issue was discovered in the Linux kernel for powerpc before 5.14.15. It allows a malicious KVM guest to crash the host, when the host is running on Power8, due to an arch/powerpc/kvm/book3s_hv_rmhandlers.S implementation bug in the handling of the SRR1 register values.
- [oss-security] 20211028 Re: Linux kernel: powerpc: KVM guest can trigger host crash on Power8
- [oss-security] 20211028 Re: Linux kernel: powerpc: KVM guest can trigger host crash on Power8
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.14.15
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.14.15
- https://git.kernel.org/linus/cdeb5d7d890e14f3b70e8087e745c4a6a7d9f337
- https://git.kernel.org/linus/cdeb5d7d890e14f3b70e8087e745c4a6a7d9f337
- FEDORA-2021-4fed2b55c4
- FEDORA-2021-4fed2b55c4
- FEDORA-2021-4320606094
- FEDORA-2021-4320606094
- FEDORA-2021-ed8c2e1098
- FEDORA-2021-ed8c2e1098
- https://lore.kernel.org/linuxppc-dev/87pmrtbbdt.fsf%40mpe.ellerman.id.au/T/#u
- https://lore.kernel.org/linuxppc-dev/87pmrtbbdt.fsf%40mpe.ellerman.id.au/T/#u