Protect yourself against future threats.
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 =========================================================================== AUSCERT External Security Bulletin Redistribution ESB-2019.3691 linux-4.9 security update 2 October 2019 =========================================================================== AusCERT Security Bulletin Summary --------------------------------- Product: linux-4.9 Publisher: Debian Operating System: Debian GNU/Linux 8 Debian GNU/Linux 9 Impact/Access: Increased Privileges -- Existing Account Denial of Service -- Existing Account Resolution: Patch/Upgrade CVE Names: CVE-2019-15902 CVE-2019-15118 CVE-2019-15117 CVE-2019-14835 CVE-2019-14821 CVE-2019-1511 Reference: ESB-2019.3613 Original Bulletin: https://lists.debian.org/debian-lts-announce/2019/10/msg00000.html - --------------------------BEGIN INCLUDED TEXT-------------------- Package : linux-4.9 Version : 4.9.189-3+deb9u1~deb8u1 CVE ID : CVE-2019-14821 CVE-2019-14835 CVE-2019-15117 CVE-2019-1511= 8=20 CVE-2019-15902 Several vulnerabilities have been discovered in the Linux kernel that may lead to a privilege escalation, denial of service or information leaks. CVE-2019-14821 Matt Delco reported a race condition in KVM's coalesced MMIO facility, which could lead to out-of-bounds access in the kernel. A local attacker permitted to access /dev/kvm could use this to cause a denial of service (memory corruption or crash) or possibly for privilege escalation. CVE-2019-14835 Peter Pi of Tencent Blade Team discovered a missing bounds check in vhost_net, the network back-end driver for KVM hosts, leading to a buffer overflow when the host begins live migration of a VM. An attacker in control of a VM could use this to cause a denial of service (memory corruption or crash) or possibly for privilege escalation on the host. CVE-2019-15117 Hui Peng and Mathias Payer reported a missing bounds check in the usb-audio driver's descriptor parsing code, leading to a buffer over-read. An attacker able to add USB devices could possibly use this to cause a denial of service (crash). CVE-2019-15118 Hui Peng and Mathias Payer reported unbounded recursion in the usb-audio driver's descriptor parsing code, leading to a stack overflow. An attacker able to add USB devices could use this to cause a denial of service (memory corruption or crash) or possibly for privilege escalation. On the amd64 architecture this is mitigated by a guard page on the kernel stack, so that it is only possible to cause a crash. CVE-2019-15902 Brad Spengler reported that a backporting error reintroduced a spectre-v1 vulnerability in the ptrace subsystem in the ptrace_get_debugreg() function. For Debian 8 "Jessie", these problems have been fixed in version 4.9.189-3+deb9u1~deb8u1. We recommend that you upgrade your linux-4.9 packages. Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS Ben Hutchings - Debian developer, member of kernel, installer and LTS teams - --------------------------END INCLUDED TEXT-------------------- You have received this e-mail bulletin as a result of your organisation's registration with AusCERT. The mailing list you are subscribed to is maintained within your organisation, so if you do not wish to continue receiving these bulletins you should contact your local IT manager. If you do not know who that is, please send an email to auscert@auscert.org.au and we will forward your request to the appropriate person. NOTE: Third Party Rights This security bulletin is provided as a service to AusCERT's members. As AusCERT did not write the document quoted above, AusCERT has had no control over its content. The decision to follow or act on information or advice contained in this security bulletin is the responsibility of each user or organisation, and should be considered in accordance with your organisation's site policies and procedures. AusCERT takes no responsibility for consequences which may arise from following or acting on information or advice contained in this security bulletin. NOTE: This is only the original release of the security bulletin. It may not be updated when updates to the original are made. If downloading at a later date, it is recommended that the bulletin is retrieved directly from the author's website to ensure that the information is still current. Contact information for the authors of the original document is included in the Security Bulletin above. If you have any questions or need further information, please contact them directly. Previous advisories and external security bulletins can be retrieved from: https://www.auscert.org.au/bulletins/ =========================================================================== Australian Computer Emergency Response Team The University of Queensland Brisbane Qld 4072 Internet Email: auscert@auscert.org.au Facsimile: (07) 3365 7031 Telephone: (07) 3365 4417 (International: +61 7 3365 4417) AusCERT personnel answer during Queensland business hours which are GMT+10:00 (AEST). On call after hours for member emergencies only. =========================================================================== -----BEGIN PGP SIGNATURE----- Comment: http://www.auscert.org.au/render.html?it=1967 iQIVAwUBXZQEAWaOgq3Tt24GAQgN0A//bWXa5vSFBJ6IzAGQ1DF6rtMoSjHMaOJL UKAmiK9lxG93qcrFKwolGo3vrkWg30ggNbHrH9X5QLFokccBBMThIf/tP7DGTL4T l5/pJHOXPm+ChUr+DAyWy74Pb9FFQaKi4GvHhGmvgHg5Jv0k2PKL7jaxrZXWChDb 145nxnMX0ZMU5KI1ICaHKsixq8cq9AHw/bOeurauAnWxLZtRBXrFJP85Gw841JXU lqlGptx0V1FDOeYSWZAAZckf4P16O2DzdShbqbmpgQsGjdukLNuek70JrSsh3yN5 ygs1VkffVy6uW8P9hwxfhM3OuTtSLi+LWrhS0trgfRVnSwFDBKYektJfvCLM4J3z z7+g8HB4cR3GZ0ZY+uDwio+S/18MSY/aRHzWHy21Wfjb/hj3mtKkqBoM38gqWeiE HjJLeeSs3uEhnGzKbyz71nq95MgMXB9vtvybuKTaRYoqr9htV+OoSFtEk3dpVZQi uo8DDVbjU6oUCIIFviT5g69iAwzsG1utUbevs6zNq2Pfo3RYI4J/pAY+5NfnrEht iIltD5ITa59wjGLHOVtzmFstEnYdtbBZ5uovEHJN8eBLZ/GVpNSrMbJXGBbHOORy MF8VXBHhY2rJK6vDDQvtSHpsADyNr0sKKKaogV+Fw7N+UXPq0tIEn1WX4vu4/baB eDAzsHDDTzk= =3loD -----END PGP SIGNATURE-----