{
  "schema_version": "1.7.0",
  "id": "MGASA-2021-0347",
  "published": "2021-07-12T20:26:21Z",
  "modified": "2022-02-17T18:21:47Z",
  "summary": "Updated kernel packages fix security vulnerabilities",
  "details": "This kernel update is based on upstream 5.10.48 and fixes at least the\nfollowing security issues:\n\nThe Linux kernel through 5.8.13 does not properly enforce the Secure Boot\nForbidden Signature Database (aka dbx) protection mechanism. This affects\ncerts/blacklist.c and certs/system_keyring.c (CVE-2020-26541).\n\nAn issue was discovered in Linux: KVM through Improper handling of VM_IO|\nVM_PFNMAP vmas in KVM can bypass RO checks and can lead to pages being\nfreed while still accessible by the VMM and guest. This allows users with\nthe ability to start and control a VM to read/write random pages of memory\nand can result in local privilege escalation (CVE-2021-22543).\n\nkernel/module.c in the Linux kernel before 5.12.14 mishandles Signature\nVerification. Without CONFIG_MODULE_SIG, verification that a kernel module\nis signed, for loading via init_module, does not occur for a\nmodule.sig_enforce=1 command-line argument (CVE-2021-35039).\n\nOther fixes in this update:\n- ahci: Add support for Dell S140 and later controllers\n- ALSA: hda/realtek: fix mute/micmute LEDs for HP EliteBook 830 G8\n- ALSA: hda/realtek: fix mute/micmute LEDs for HP ProBook 445/450/630 G8\n- drm/amdgpu: fix bad address translation for sienna_cichlid\n- drm/sched: Avoid data corruptions\n- net: ip: avoid OOM kills with large UDP sends over loopback\n- iwlwifi: Add support for ax201 in Samsung Galaxy Book Flex2 Alpha\n- virtio_net: Remove BUG() to avoid machine dead\n\nFor other upstream fixes, see the referenced changelogs.\n",
  "upstream": [
    "CVE-2020-26541",
    "CVE-2021-22543",
    "CVE-2021-35039"
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://advisories.mageia.org/MGASA-2021-0347.html"
    },
    {
      "type": "REPORT",
      "url": "https://bugs.mageia.org/show_bug.cgi?id=29235"
    },
    {
      "type": "WEB",
      "url": "https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.47"
    },
    {
      "type": "WEB",
      "url": "https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.10.48"
    }
  ],
  "affected": [
    {
      "package": {
        "ecosystem": "Mageia:8",
        "name": "kernel",
        "purl": "pkg:rpm/mageia/kernel?arch=source&distro=mageia-8"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "5.10.48-1.mga8"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:8",
        "name": "kmod-virtualbox",
        "purl": "pkg:rpm/mageia/kmod-virtualbox?arch=source&distro=mageia-8"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "6.1.22-1.10.mga8"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    },
    {
      "package": {
        "ecosystem": "Mageia:8",
        "name": "kmod-xtables-addons",
        "purl": "pkg:rpm/mageia/kmod-xtables-addons?arch=source&distro=mageia-8"
      },
      "ranges": [
        {
          "type": "ECOSYSTEM",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "3.18-1.10.mga8"
            }
          ]
        }
      ],
      "ecosystem_specific": {
        "section": "core"
      }
    }
  ],
  "credits": [
    {
      "name": "Mageia",
      "type": "COORDINATOR",
      "contact": [
        "https://wiki.mageia.org/en/Packages_Security_Team"
      ]
    }
  ]
}
