2024-06-28 13:17:52 +00:00

165 lines
6.3 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20203255",
"Version": "oval:org.altlinux.errata:def:20203255",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2020-3255: package `kernel-image-std-debug` update to version 5.4.76-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p10"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2020-3255",
"RefURL": "https://errata.altlinux.org/ALT-PU-2020-3255",
"Source": "ALTPU"
},
{
"RefID": "BDU:2020-05831",
"RefURL": "https://bdu.fstec.ru/vul/2020-05831",
"Source": "BDU"
},
{
"RefID": "CVE-2020-25656",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2020-25656",
"Source": "CVE"
}
],
"Description": "This update upgrades kernel-image-std-debug to version 5.4.76-alt1. \nSecurity Fix(es):\n\n * BDU:2020-05831: Уязвимость ядра операционной системы Linux, связанная с использованием памяти после её освобождения, позволяющая нарушителю раскрыть защищаемую информацию\n\n * CVE-2020-25656: A flaw was found in the Linux kernel. A use-after-free was found in the way the console subsystem was using ioctls KDGKBSENT and KDSKBSENT. A local user could use this flaw to get read memory access out of bounds. The highest threat from this vulnerability is to data confidentiality.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "Low",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2020-11-10"
},
"Updated": {
"Date": "2020-11-10"
},
"BDUs": [
{
"ID": "BDU:2020-05831",
"CVSS": "AV:L/AC:M/Au:N/C:P/I:N/A:N",
"CVSS3": "AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-416",
"Href": "https://bdu.fstec.ru/vul/2020-05831",
"Impact": "Low",
"Public": "20201028"
}
],
"CVEs": [
{
"ID": "CVE-2020-25656",
"CVSS": "AV:L/AC:M/Au:N/C:P/I:N/A:N",
"CVSS3": "CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N",
"CWE": "CWE-416",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2020-25656",
"Impact": "Low",
"Public": "20201202"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:10",
"cpe:/o:alt:workstation:10",
"cpe:/o:alt:server:10",
"cpe:/o:alt:server-v:10",
"cpe:/o:alt:education:10",
"cpe:/o:alt:slinux:10",
"cpe:/o:alt:starterkit:p10",
"cpe:/o:alt:kworkstation:10.1",
"cpe:/o:alt:workstation:10.1",
"cpe:/o:alt:server:10.1",
"cpe:/o:alt:server-v:10.1",
"cpe:/o:alt:education:10.1",
"cpe:/o:alt:slinux:10.1",
"cpe:/o:alt:starterkit:10.1",
"cpe:/o:alt:kworkstation:10.2",
"cpe:/o:alt:workstation:10.2",
"cpe:/o:alt:server:10.2",
"cpe:/o:alt:server-v:10.2",
"cpe:/o:alt:education:10.2",
"cpe:/o:alt:slinux:10.2",
"cpe:/o:alt:starterkit:10.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:2001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20203255001",
"Comment": "kernel-headers-modules-std-debug is earlier than 2:5.4.76-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203255002",
"Comment": "kernel-headers-std-debug is earlier than 2:5.4.76-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203255003",
"Comment": "kernel-image-domU-std-debug is earlier than 2:5.4.76-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203255004",
"Comment": "kernel-image-std-debug is earlier than 2:5.4.76-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203255005",
"Comment": "kernel-modules-drm-ancient-std-debug is earlier than 2:5.4.76-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203255006",
"Comment": "kernel-modules-drm-nouveau-std-debug is earlier than 2:5.4.76-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203255007",
"Comment": "kernel-modules-drm-radeon-std-debug is earlier than 2:5.4.76-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203255008",
"Comment": "kernel-modules-drm-std-debug is earlier than 2:5.4.76-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203255009",
"Comment": "kernel-modules-ide-std-debug is earlier than 2:5.4.76-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203255010",
"Comment": "kernel-modules-staging-std-debug is earlier than 2:5.4.76-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20203255011",
"Comment": "kernel-modules-v4l-std-debug is earlier than 2:5.4.76-alt1"
}
]
}
]
}
}
]
}