ALT-BU-2021-4034-1
Branch c9f2 update bulletin.
Closed vulnerabilities
BDU:2022-00715
Уязвимость пакета crypto/tls языка программирования Go, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2021-34558
The crypto/tls package of Go through 1.16.5 does not properly assert that the type of public key in an X.509 certificate matches the expected type when doing a RSA based key exchange, allowing a malicious TLS server to cause a TLS client to panic.
- https://golang.org/doc/devel/release#go1.16.minor
- https://golang.org/doc/devel/release#go1.16.minor
- https://groups.google.com/g/golang-announce
- https://groups.google.com/g/golang-announce
- https://groups.google.com/g/golang-announce/c/n9FxMelZGAQ
- https://groups.google.com/g/golang-announce/c/n9FxMelZGAQ
- FEDORA-2021-1bfb61f77c
- FEDORA-2021-1bfb61f77c
- FEDORA-2021-07e4d20196
- FEDORA-2021-07e4d20196
- FEDORA-2021-ffa749f7f7
- FEDORA-2021-ffa749f7f7
- FEDORA-2021-25c0011e78
- FEDORA-2021-25c0011e78
- FEDORA-2021-54f88bebd4
- FEDORA-2021-54f88bebd4
- FEDORA-2021-3a55403080
- FEDORA-2021-3a55403080
- FEDORA-2021-6ac9b98f9e
- FEDORA-2021-6ac9b98f9e
- FEDORA-2021-c35235c250
- FEDORA-2021-c35235c250
- FEDORA-2021-47d259d3cf
- FEDORA-2021-47d259d3cf
- GLSA-202208-02
- GLSA-202208-02
- https://security.netapp.com/advisory/ntap-20210813-0005/
- https://security.netapp.com/advisory/ntap-20210813-0005/
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpujan2022.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
- https://www.oracle.com/security-alerts/cpuoct2021.html
Package kernel-image-std-def updated to version 5.10.47-alt0.c9f for branch c9f2 in task 276518.
Closed vulnerabilities
BDU:2021-00284
Уязвимость ядра операционной системы Linux, связанная с некорректной проверкой криптографической подписи, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2021-03938
Уязвимость компонента kernel/module.c ядра операционной системы Linux, позволяющая нарушителю оказать воздействие на конфиденциальность, целостность и доступность защищаемой информации
BDU:2021-04854
Уязвимость операционной системы Linux вызвана переполнением буфера, позволяющая нарушителю выполнить произвольную команду управления
Modified: 2024-11-21
CVE-2020-26541
The Linux kernel through 5.8.13 does not properly enforce the Secure Boot Forbidden Signature Database (aka dbx) protection mechanism. This affects certs/blacklist.c and certs/system_keyring.c.
Modified: 2024-11-21
CVE-2021-22543
An issue was discovered in Linux: KVM through Improper handling of VM_IO|VM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being freed while still accessible by the VMM and guest. This allows users with the ability to start and control a VM to read/write random pages of memory and can result in local privilege escalation.
- [oss-security] 20210626 Re: CVE-2021-22543 - /dev/kvm LPE
- [oss-security] 20210626 Re: CVE-2021-22543 - /dev/kvm LPE
- https://github.com/google/security-research/security/advisories/GHSA-7wq5-phmq-m584
- https://github.com/google/security-research/security/advisories/GHSA-7wq5-phmq-m584
- [debian-lts-announce] 20211015 [SECURITY] [DLA 2785-1] linux-4.19 security update
- [debian-lts-announce] 20211015 [SECURITY] [DLA 2785-1] linux-4.19 security update
- [debian-lts-announce] 20211216 [SECURITY] [DLA 2843-1] linux security update
- [debian-lts-announce] 20211216 [SECURITY] [DLA 2843-1] linux security update
- FEDORA-2021-fe826f202e
- FEDORA-2021-fe826f202e
- FEDORA-2021-95f2f1cfc7
- FEDORA-2021-95f2f1cfc7
- https://security.netapp.com/advisory/ntap-20210708-0002/
- https://security.netapp.com/advisory/ntap-20210708-0002/
Modified: 2024-11-21
CVE-2021-35039
kernel/module.c in the Linux kernel before 5.12.14 mishandles Signature Verification, aka CID-0c18f29aae7c. Without CONFIG_MODULE_SIG, verification that a kernel module is signed, for loading via init_module, does not occur for a module.sig_enforce=1 command-line argument.
- [oss-security] 20210706 CVE-2021-35039: Linux kernel loading unsigned kernel modules via init_module syscall
- [oss-security] 20210706 CVE-2021-35039: Linux kernel loading unsigned kernel modules via init_module syscall
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.14
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.12.14
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0c18f29aae7ce3dadd26d8ee3505d07cc982df75
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=0c18f29aae7ce3dadd26d8ee3505d07cc982df75
- https://github.com/torvalds/linux/commit/0c18f29aae7ce3dadd26d8ee3505d07cc982df75
- https://github.com/torvalds/linux/commit/0c18f29aae7ce3dadd26d8ee3505d07cc982df75
- [debian-lts-announce] 20211015 [SECURITY] [DLA 2785-1] linux-4.19 security update
- [debian-lts-announce] 20211015 [SECURITY] [DLA 2785-1] linux-4.19 security update
- https://security.netapp.com/advisory/ntap-20210813-0004/
- https://security.netapp.com/advisory/ntap-20210813-0004/
- https://www.openwall.com/lists/oss-security/2021/07/06/3
- https://www.openwall.com/lists/oss-security/2021/07/06/3
Closed vulnerabilities
BDU:2021-02467
Уязвимость компонента Server: DML системы управления базами данных Oracle MySQL Server, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-02468
Уязвимость компонента Server: DML системы управления базами данных Oracle MySQL Server, позволяющая нарушителю вызвать отказ в обслуживании
BDU:2021-03770
Уязвимость модификации wsrep_notify_cmd базы данных MariaDB, связанная с отсутствием мер по очистке входных данных, позволяющая нарушителю получить доступ к конфиденциальной информации или вызвать отказ в обслуживании
BDU:2022-02835
Уязвимость компонента InnoDB системы управления базами данных MySQL Server, позволяющая нарушителю вызвать отказ в обслуживании
Modified: 2024-11-21
CVE-2021-2154
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 5.7.33 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
- FEDORA-2021-68db93b130
- FEDORA-2021-68db93b130
- FEDORA-2021-27187ac9dd
- FEDORA-2021-27187ac9dd
- FEDORA-2021-179f2fbb88
- FEDORA-2021-179f2fbb88
- GLSA-202105-27
- GLSA-202105-27
- GLSA-202105-28
- GLSA-202105-28
- https://security.netapp.com/advisory/ntap-20210513-0002/
- https://security.netapp.com/advisory/ntap-20210513-0002/
- https://www.oracle.com/security-alerts/cpuapr2021.html
- https://www.oracle.com/security-alerts/cpuapr2021.html
Modified: 2024-11-21
CVE-2021-2166
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 5.7.33 and prior and 8.0.23 and prior. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.9 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H).
- FEDORA-2021-01189f6361
- FEDORA-2021-01189f6361
- FEDORA-2021-68db93b130
- FEDORA-2021-68db93b130
- FEDORA-2021-27187ac9dd
- FEDORA-2021-27187ac9dd
- FEDORA-2021-b8b7829a83
- FEDORA-2021-b8b7829a83
- FEDORA-2021-179f2fbb88
- FEDORA-2021-179f2fbb88
- FEDORA-2021-5b6c69a73a
- FEDORA-2021-5b6c69a73a
- GLSA-202105-27
- GLSA-202105-27
- GLSA-202105-28
- GLSA-202105-28
- https://security.netapp.com/advisory/ntap-20210513-0002/
- https://security.netapp.com/advisory/ntap-20210513-0002/
- https://www.oracle.com/security-alerts/cpuapr2021.html
- https://www.oracle.com/security-alerts/cpuapr2021.html
Modified: 2024-11-21
CVE-2021-27928
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection, in which a database SUPER user can execute OS commands after modifying wsrep_provider and wsrep_notify_cmd. NOTE: this does not affect an Oracle product.
- http://packetstormsecurity.com/files/162177/MariaDB-10.2-Command-Execution.html
- http://packetstormsecurity.com/files/162177/MariaDB-10.2-Command-Execution.html
- https://jira.mariadb.org/browse/MDEV-25179
- https://jira.mariadb.org/browse/MDEV-25179
- [debian-lts-announce] 20210323 [SECURITY] [DLA 2605-1] mariadb-10.1 security update
- [debian-lts-announce] 20210323 [SECURITY] [DLA 2605-1] mariadb-10.1 security update
- https://mariadb.com/kb/en/mariadb-10237-release-notes/
- https://mariadb.com/kb/en/mariadb-10237-release-notes/
- https://mariadb.com/kb/en/mariadb-10328-release-notes/
- https://mariadb.com/kb/en/mariadb-10328-release-notes/
- https://mariadb.com/kb/en/mariadb-10418-release-notes/
- https://mariadb.com/kb/en/mariadb-10418-release-notes/
- https://mariadb.com/kb/en/mariadb-1059-release-notes/
- https://mariadb.com/kb/en/mariadb-1059-release-notes/
- https://mariadb.com/kb/en/security/
- https://mariadb.com/kb/en/security/
- GLSA-202105-28
- GLSA-202105-28
Modified: 2024-11-21
CVE-2021-46657
get_sort_by_table in MariaDB before 10.6.2 allows an application crash via certain subquery uses of ORDER BY.
Modified: 2024-11-21
CVE-2021-46666
MariaDB before 10.6.2 allows an application crash because of mishandling of a pushdown from a HAVING clause to a WHERE clause.
Modified: 2024-11-21
CVE-2022-21451
Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 5.7.37 and prior and 8.0.28 and prior. Difficult to exploit vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of MySQL Server. CVSS 3.1 Base Score 4.4 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H).
Closed bugs
Сломалась сборка mariadb