2024-04-16 14:26:14 +00:00

175 lines
7.2 KiB
JSON
Raw Blame History

This file contains ambiguous Unicode characters

This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

{
"Definition": [
{
"ID": "oval:org.altlinux.errata:def:20212042",
"Version": "oval:org.altlinux.errata:def:20212042",
"Class": "patch",
"Metadata": {
"Title": "ALT-PU-2021-2042: package `kernel-image-un-def` update to version 5.10.45-alt1",
"AffectedList": [
{
"Family": "unix",
"Platforms": [
"ALT Linux branch p9"
],
"Products": [
"ALT Server",
"ALT Virtualization Server",
"ALT Workstation",
"ALT Workstation K",
"ALT Education",
"Simply Linux",
"Starterkit"
]
}
],
"References": [
{
"RefID": "ALT-PU-2021-2042",
"RefURL": "https://errata.altlinux.org/ALT-PU-2021-2042",
"Source": "ALTPU"
},
{
"RefID": "BDU:2021-04862",
"RefURL": "https://bdu.fstec.ru/vul/2021-04862",
"Source": "BDU"
},
{
"RefID": "CVE-2021-28691",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-28691",
"Source": "CVE"
},
{
"RefID": "CVE-2021-3564",
"RefURL": "https://nvd.nist.gov/vuln/detail/CVE-2021-3564",
"Source": "CVE"
}
],
"Description": "This update upgrades kernel-image-un-def to version 5.10.45-alt1. \nSecurity Fix(es):\n\n * BDU:2021-04862: Уязвимость функции hci_dev_do_open() подсистемы инициализации устройства HCI ядра операционной системы Linux, связанная с повторным освобождением памяти, позволяющая нарушителю вызвать отказ в обслуживании\n\n * CVE-2021-28691: Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sending a malformed packet. Such kernel thread termination will lead to a use-after-free in Linux netback when the backend is destroyed, as the kernel thread associated with queue 0 will have already exited and thus the call to kthread_stop will be performed against a stale pointer.\n\n * CVE-2021-3564: A flaw double-free memory corruption in the Linux kernel HCI device initialization subsystem was found in the way user attach malicious HCI TTY Bluetooth device. A local user could use this flaw to crash the system. This flaw affects all the Linux kernel versions starting from 3.13.",
"Advisory": {
"From": "errata.altlinux.org",
"Severity": "High",
"Rights": "Copyright 2024 BaseALT Ltd.",
"Issued": {
"Date": "2021-06-23"
},
"Updated": {
"Date": "2021-06-23"
},
"BDUs": [
{
"ID": "BDU:2021-04862",
"CVSS": "AV:L/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-415",
"Href": "https://bdu.fstec.ru/vul/2021-04862",
"Impact": "Low",
"Public": "20210517"
}
],
"CVEs": [
{
"ID": "CVE-2021-28691",
"CVSS": "AV:L/AC:L/Au:N/C:P/I:P/A:P",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"CWE": "CWE-416",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-28691",
"Impact": "High",
"Public": "20210629"
},
{
"ID": "CVE-2021-3564",
"CVSS": "AV:L/AC:L/Au:N/C:N/I:N/A:P",
"CVSS3": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
"CWE": "CWE-415",
"Href": "https://nvd.nist.gov/vuln/detail/CVE-2021-3564",
"Impact": "Low",
"Public": "20210608"
}
],
"AffectedCPEs": {
"CPEs": [
"cpe:/o:alt:kworkstation:9",
"cpe:/o:alt:workstation:9",
"cpe:/o:alt:server:9",
"cpe:/o:alt:server-v:9",
"cpe:/o:alt:education:9",
"cpe:/o:alt:slinux:9",
"cpe:/o:alt:starterkit:p9",
"cpe:/o:alt:kworkstation:9.1",
"cpe:/o:alt:workstation:9.1",
"cpe:/o:alt:server:9.1",
"cpe:/o:alt:server-v:9.1",
"cpe:/o:alt:education:9.1",
"cpe:/o:alt:slinux:9.1",
"cpe:/o:alt:starterkit:9.1",
"cpe:/o:alt:kworkstation:9.2",
"cpe:/o:alt:workstation:9.2",
"cpe:/o:alt:server:9.2",
"cpe:/o:alt:server-v:9.2",
"cpe:/o:alt:education:9.2",
"cpe:/o:alt:slinux:9.2",
"cpe:/o:alt:starterkit:9.2"
]
}
}
},
"Criteria": {
"Operator": "AND",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:1001",
"Comment": "ALT Linux must be installed"
}
],
"Criterias": [
{
"Operator": "OR",
"Criterions": [
{
"TestRef": "oval:org.altlinux.errata:tst:20212042001",
"Comment": "kernel-doc-un is earlier than 1:5.10.45-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212042002",
"Comment": "kernel-headers-modules-un-def is earlier than 1:5.10.45-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212042003",
"Comment": "kernel-headers-un-def is earlier than 1:5.10.45-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212042004",
"Comment": "kernel-image-domU-un-def is earlier than 1:5.10.45-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212042005",
"Comment": "kernel-image-un-def is earlier than 1:5.10.45-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212042006",
"Comment": "kernel-modules-drm-ancient-un-def is earlier than 1:5.10.45-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212042007",
"Comment": "kernel-modules-drm-nouveau-un-def is earlier than 1:5.10.45-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212042008",
"Comment": "kernel-modules-drm-un-def is earlier than 1:5.10.45-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212042009",
"Comment": "kernel-modules-ide-un-def is earlier than 1:5.10.45-alt1"
},
{
"TestRef": "oval:org.altlinux.errata:tst:20212042010",
"Comment": "kernel-modules-staging-un-def is earlier than 1:5.10.45-alt1"
}
]
}
]
}
}
]
}