diff options
author | Ben Hutchings <ben@decadent.org.uk> | 2020-10-28 14:56:16 +0000 |
---|---|---|
committer | Carsten Schoenert <c.schoenert@t-online.de> | 2020-10-31 07:28:59 +0100 |
commit | 5fbf8d4a1efd1f97a8e8e756acbe29c729555969 (patch) | |
tree | 0b410fa8480f44141b7a5f5f23e264cddb604735 | |
parent | 48139faa7f7196d09383c7f2b7915c0586f1bb84 (diff) |
Add DLA-2417-1
-rw-r--r-- | english/lts/security/2020/dla-2417.data | 10 | ||||
-rw-r--r-- | english/lts/security/2020/dla-2417.wml | 63 |
2 files changed, 73 insertions, 0 deletions
diff --git a/english/lts/security/2020/dla-2417.data b/english/lts/security/2020/dla-2417.data new file mode 100644 index 00000000000..21c0532f90f --- /dev/null +++ b/english/lts/security/2020/dla-2417.data @@ -0,0 +1,10 @@ +<define-tag pagetitle>DLA-2417-1 linux-4.19</define-tag> +<define-tag report_date>2020-10-28</define-tag> +<define-tag secrefs>CVE-2020-12351 CVE-2020-12352 CVE-2020-25211 CVE-2020-25643 CVE-2020-25645 Bug#908712</define-tag> +<define-tag packages>linux-4.19</define-tag> +<define-tag isvulnerable>yes</define-tag> +<define-tag fixed>yes</define-tag> +<define-tag fixed-section>no</define-tag> + +#use wml::debian::security + diff --git a/english/lts/security/2020/dla-2417.wml b/english/lts/security/2020/dla-2417.wml new file mode 100644 index 00000000000..5bcdc7aaeed --- /dev/null +++ b/english/lts/security/2020/dla-2417.wml @@ -0,0 +1,63 @@ +<define-tag description>LTS security update</define-tag> +<define-tag moreinfo> +<p>Several vulnerabilities have been discovered in the Linux kernel that +may lead to the execution of arbitrary code, privilege escalation, +denial of service or information leaks.</p> + +<ul> + +<li><a href="https://security-tracker.debian.org/tracker/CVE-2020-12351">CVE-2020-12351</a> + + <p>Andy Nguyen discovered a flaw in the Bluetooth implementation in the + way L2CAP packets with A2MP CID are handled. A remote attacker in + short distance knowing the victim's Bluetooth device address can + send a malicious l2cap packet and cause a denial of service or + possibly arbitrary code execution with kernel privileges.</p></li> + +<li><a href="https://security-tracker.debian.org/tracker/CVE-2020-12352">CVE-2020-12352</a> + + <p>Andy Nguyen discovered a flaw in the Bluetooth implementation. Stack + memory is not properly initialised when handling certain AMP + packets. A remote attacker in short distance knowing the victim's + Bluetooth device address address can retrieve kernel stack + information.</p></li> + +<li><a href="https://security-tracker.debian.org/tracker/CVE-2020-25211">CVE-2020-25211</a> + + <p>A flaw was discovered in netfilter subsystem. A local attacker + able to inject conntrack Netlink configuration can cause a denial + of service.</p></li> + +<li><a href="https://security-tracker.debian.org/tracker/CVE-2020-25643">CVE-2020-25643</a> + + <p>ChenNan Of Chaitin Security Research Lab discovered a flaw in the + hdlc_ppp module. Improper input validation in the ppp_cp_parse_cr() + function may lead to memory corruption and information disclosure.</p></li> + +<li><a href="https://security-tracker.debian.org/tracker/CVE-2020-25645">CVE-2020-25645</a> + + <p>A flaw was discovered in the interface driver for GENEVE + encapsulated traffic when combined with IPsec. If IPsec is + configured to encrypt traffic for the specific UDP port used by the + GENEVE tunnel, tunneled data isn't correctly routed over the + encrypted link and sent unencrypted instead.</p></li> + +</ul> + +<p>For Debian 9 stretch, these problems have been fixed in version +4.19.152-1~deb9u1.</p> + +<p>We recommend that you upgrade your linux-4.19 packages.</p> + +<p>For the detailed security status of linux-4.19 please refer to +its security tracker page at: +<a href="https://security-tracker.debian.org/tracker/linux-4.19">https://security-tracker.debian.org/tracker/linux-4.19</a></p> + +<p>Further information about Debian LTS security advisories, how to apply +these updates to your system and frequently asked questions can be +found at: <a href="https://wiki.debian.org/LTS">https://wiki.debian.org/LTS</a></p> +</define-tag> + +# do not modify the following line +#include "$(ENGLISHDIR)/lts/security/2020/dla-2417.data" +# $Id: $ |