-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

===========================================================================
             AUSCERT External Security Bulletin Redistribution

                               ESB-2019.3691
                         linux-4.9 security update
                              2 October 2019

===========================================================================

        AusCERT Security Bulletin Summary
        ---------------------------------

Product:           linux-4.9
Publisher:         Debian
Operating System:  Debian GNU/Linux 8
                   Debian GNU/Linux 9
Impact/Access:     Increased Privileges -- Existing Account
                   Denial of Service    -- Existing Account
Resolution:        Patch/Upgrade
CVE Names:         CVE-2019-15902 CVE-2019-15118 CVE-2019-15117
                   CVE-2019-14835 CVE-2019-14821 CVE-2019-1511

Reference:         ESB-2019.3613

Original Bulletin: 
   https://lists.debian.org/debian-lts-announce/2019/10/msg00000.html

- --------------------------BEGIN INCLUDED TEXT--------------------

Package        : linux-4.9
Version        : 4.9.189-3+deb9u1~deb8u1
CVE ID         : CVE-2019-14821 CVE-2019-14835 CVE-2019-15117 CVE-2019-1511=
8=20
                 CVE-2019-15902

Several vulnerabilities have been discovered in the Linux kernel that
may lead to a privilege escalation, denial of service or information
leaks.

CVE-2019-14821

    Matt Delco reported a race condition in KVM's coalesced MMIO
    facility, which could lead to out-of-bounds access in the kernel.
    A local attacker permitted to access /dev/kvm could use this to
    cause a denial of service (memory corruption or crash) or possibly
    for privilege escalation.

CVE-2019-14835

    Peter Pi of Tencent Blade Team discovered a missing bounds check
    in vhost_net, the network back-end driver for KVM hosts, leading
    to a buffer overflow when the host begins live migration of a VM.
    An attacker in control of a VM could use this to cause a denial of
    service (memory corruption or crash) or possibly for privilege
    escalation on the host.

CVE-2019-15117

    Hui Peng and Mathias Payer reported a missing bounds check in the
    usb-audio driver's descriptor parsing code, leading to a buffer
    over-read.  An attacker able to add USB devices could possibly use
    this to cause a denial of service (crash).

CVE-2019-15118

    Hui Peng and Mathias Payer reported unbounded recursion in the
    usb-audio driver's descriptor parsing code, leading to a stack
    overflow.  An attacker able to add USB devices could use this to
    cause a denial of service (memory corruption or crash) or possibly
    for privilege escalation.  On the amd64 architecture this is
    mitigated by a guard page on the kernel stack, so that it is only
    possible to cause a crash.

CVE-2019-15902

    Brad Spengler reported that a backporting error reintroduced a
    spectre-v1 vulnerability in the ptrace subsystem in the
    ptrace_get_debugreg() function.

For Debian 8 "Jessie", these problems have been fixed in version
4.9.189-3+deb9u1~deb8u1.

We recommend that you upgrade your linux-4.9 packages.

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

Ben Hutchings - Debian developer, member of kernel, installer and LTS teams

- --------------------------END INCLUDED TEXT--------------------

You have received this e-mail bulletin as a result of your organisation's
registration with AusCERT. The mailing list you are subscribed to is
maintained within your organisation, so if you do not wish to continue
receiving these bulletins you should contact your local IT manager. If
you do not know who that is, please send an email to auscert@auscert.org.au
and we will forward your request to the appropriate person.

NOTE: Third Party Rights
This security bulletin is provided as a service to AusCERT's members.  As
AusCERT did not write the document quoted above, AusCERT has had no control
over its content. The decision to follow or act on information or advice
contained in this security bulletin is the responsibility of each user or
organisation, and should be considered in accordance with your organisation's
site policies and procedures. AusCERT takes no responsibility for consequences
which may arise from following or acting on information or advice contained in
this security bulletin.

NOTE: This is only the original release of the security bulletin.  It may
not be updated when updates to the original are made.  If downloading at
a later date, it is recommended that the bulletin is retrieved directly
from the author's website to ensure that the information is still current.

Contact information for the authors of the original document is included
in the Security Bulletin above.  If you have any questions or need further
information, please contact them directly.

Previous advisories and external security bulletins can be retrieved from:

        https://www.auscert.org.au/bulletins/

===========================================================================
Australian Computer Emergency Response Team
The University of Queensland
Brisbane
Qld 4072

Internet Email: auscert@auscert.org.au
Facsimile:      (07) 3365 7031
Telephone:      (07) 3365 4417 (International: +61 7 3365 4417)
                AusCERT personnel answer during Queensland business hours
                which are GMT+10:00 (AEST).
                On call after hours for member emergencies only.
===========================================================================
-----BEGIN PGP SIGNATURE-----
Comment: http://www.auscert.org.au/render.html?it=1967

iQIVAwUBXZQEAWaOgq3Tt24GAQgN0A//bWXa5vSFBJ6IzAGQ1DF6rtMoSjHMaOJL
UKAmiK9lxG93qcrFKwolGo3vrkWg30ggNbHrH9X5QLFokccBBMThIf/tP7DGTL4T
l5/pJHOXPm+ChUr+DAyWy74Pb9FFQaKi4GvHhGmvgHg5Jv0k2PKL7jaxrZXWChDb
145nxnMX0ZMU5KI1ICaHKsixq8cq9AHw/bOeurauAnWxLZtRBXrFJP85Gw841JXU
lqlGptx0V1FDOeYSWZAAZckf4P16O2DzdShbqbmpgQsGjdukLNuek70JrSsh3yN5
ygs1VkffVy6uW8P9hwxfhM3OuTtSLi+LWrhS0trgfRVnSwFDBKYektJfvCLM4J3z
z7+g8HB4cR3GZ0ZY+uDwio+S/18MSY/aRHzWHy21Wfjb/hj3mtKkqBoM38gqWeiE
HjJLeeSs3uEhnGzKbyz71nq95MgMXB9vtvybuKTaRYoqr9htV+OoSFtEk3dpVZQi
uo8DDVbjU6oUCIIFviT5g69iAwzsG1utUbevs6zNq2Pfo3RYI4J/pAY+5NfnrEht
iIltD5ITa59wjGLHOVtzmFstEnYdtbBZ5uovEHJN8eBLZ/GVpNSrMbJXGBbHOORy
MF8VXBHhY2rJK6vDDQvtSHpsADyNr0sKKKaogV+Fw7N+UXPq0tIEn1WX4vu4/baB
eDAzsHDDTzk=
=3loD
-----END PGP SIGNATURE-----