2024-04-16 14:26:14 +00:00

199 lines
8.3 KiB
JSON
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20231358",
"Version": "oval:org.altlinux.errata:def:20231358",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2023-1358: package `kernel-image-std-def` update to version 5.4.233-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p9"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2023-1358",
"RefURL": "https://errata.altlinux.org/ALT-PU-2023-1358",
"Source": "ALTPU"
},
{
"RefID": "BDU:2023-01205",
"RefURL": "https://bdu.fstec.ru/vul/2023-01205",
"Source": "BDU"
},
{
"RefID": "BDU:2023-02532",
"RefURL": "https://bdu.fstec.ru/vul/2023-02532",
"Source": "BDU"
},
{
"RefID": "CVE-2023-0459",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-0459",
"Source": "CVE"
},
{
"RefID": "CVE-2023-1078",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2023-1078",
"Source": "CVE"
}
],
"Description": "This update upgrades kernel-image-std-def to version 5.4.233-alt1. \nSecurity Fix(es):\n\n * BDU:2023-01205: Уязвимость функции rds_rm_zerocopy_callback() в модуле net/rds/message.c ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании\n\n * BDU:2023-02532: Уязвимость функции _copy_from_user() в модуле lib/usercopy.c ядра операционной системы Linux, позволяющая нарушителю раскрыть защищаемую информацию\n\n * CVE-2023-0459: Copy_from_user on 64-bit versions of the Linux kernel does not implement the __uaccess_begin_nospec allowing a user to bypass the \"access_ok\" check and pass a kernel pointer to copy_from_user(). This would allow an attacker to leak information. We recommend upgrading beyond commit 74e19ef0ff8061ef55957c3abd71614ef0f42f47\n\n * CVE-2023-1078: A flaw was found in the Linux Kernel in RDS (Reliable Datagram Sockets) protocol. The rds_rm_zerocopy_callback() uses list_entry() on the head of a list causing a type confusion. Local user can trigger this with rds_message_put(). Type confusion leads to `struct rds_msg_zcopy_info *info` actually points to something else that is potentially controlled by local user. It is known how to trigger this, which causes an out of bounds access, and a lock corruption.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2023-02-28"
},
"Updated": {
"Date": "2023-02-28"
},
"BDUs": [
{
"ID": "BDU:2023-01205",
"CVSS": "AV:L/AC:L/Au:S/C:C/I:C/A:C",
"CVSS3": "AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-476, CWE-787, CWE-843",
"Href": "https://bdu.fstec.ru/vul/2023-01205",
"Impact": "High",
"Public": "20230209"
},
{
"ID": "BDU:2023-02532",
"CVSS": "AV:L/AC:L/Au:S/C:C/I:N/A:N",
"CVSS3": "AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-200, CWE-203, CWE-264, CWE-763",
"Href": "https://bdu.fstec.ru/vul/2023-02532",
"Impact": "Low",
"Public": "20230221"
}
],
"CVEs": [
{
"ID": "CVE-2023-0459",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-763",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-0459",
"Impact": "Low",
"Public": "20230525"
},
{
"ID": "CVE-2023-1078",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-843",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2023-1078",
"Impact": "High",
"Public": "20230327"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:9",
"cpe:/o:alt:workstation:9",
"cpe:/o:alt:server:9",
"cpe:/o:alt:server-v:9",
"cpe:/o:alt:education:9",
"cpe:/o:alt:slinux:9",
"cpe:/o:alt:starterkit:p9",
"cpe:/o:alt:kworkstation:9.1",
"cpe:/o:alt:workstation:9.1",
"cpe:/o:alt:server:9.1",
"cpe:/o:alt:server-v:9.1",
"cpe:/o:alt:education:9.1",
"cpe:/o:alt:slinux:9.1",
"cpe:/o:alt:starterkit:9.1",
"cpe:/o:alt:kworkstation:9.2",
"cpe:/o:alt:workstation:9.2",
"cpe:/o:alt:server:9.2",
"cpe:/o:alt:server-v:9.2",
"cpe:/o:alt:education:9.2",
"cpe:/o:alt:slinux:9.2",
"cpe:/o:alt:starterkit:9.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:1001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20231358001",
"Comment": "kernel-doc-std is earlier than 2:5.4.233-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231358002",
"Comment": "kernel-headers-modules-std-def is earlier than 2:5.4.233-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231358003",
"Comment": "kernel-headers-std-def is earlier than 2:5.4.233-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231358004",
"Comment": "kernel-image-domU-std-def is earlier than 2:5.4.233-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231358005",
"Comment": "kernel-image-std-def is earlier than 2:5.4.233-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231358006",
"Comment": "kernel-modules-drm-ancient-std-def is earlier than 2:5.4.233-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231358007",
"Comment": "kernel-modules-drm-nouveau-std-def is earlier than 2:5.4.233-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231358008",
"Comment": "kernel-modules-drm-radeon-std-def is earlier than 2:5.4.233-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231358009",
"Comment": "kernel-modules-drm-std-def is earlier than 2:5.4.233-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231358010",
"Comment": "kernel-modules-ide-std-def is earlier than 2:5.4.233-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231358011",
"Comment": "kernel-modules-midgard-be-m1000-std-def is earlier than 2:5.4.233-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231358012",
"Comment": "kernel-modules-staging-std-def is earlier than 2:5.4.233-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20231358013",
"Comment": "kernel-modules-v4l-std-def is earlier than 2:5.4.233-alt1"
}
]
}
]
}
}
]
}