No Image

USN-4946-1: Linux kernel vulnerabilities

2021-05-12 KENNETH 0

USN-4946-1: Linux kernel vulnerabilities It was discovered that the DRM subsystem in the Linux kernel contained double-free vulnerabilities. A privileged attacker could possibly use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2021-20292) Olivier Benjamin, Norbert Manthey, Martin Mazein, and Jan H. Schönherr discovered that the Xen paravirtualization backend in the Linux kernel did not properly propagate errors to frontend drivers in some situations. An attacker in a guest VM could possibly use this to cause a denial of service (host domain crash). (CVE-2021-26930) Jan Beulich discovered that multiple Xen backends in the Linux kernel did not properly handle certain error conditions under paravirtualization. An attacker in a guest VM could possibly use this to cause a denial of service (host domain crash). (CVE-2021-26931) Jan Beulich discovered that the Xen netback backend in the [ more… ]

No Image

USN-4947-1: Linux kernel (OEM) vulnerabilities

2021-05-12 KENNETH 0

USN-4947-1: Linux kernel (OEM) vulnerabilities Kiyin (尹亮) discovered that the x25 implementation in the Linux kernel contained overflows when handling addresses from user space. A local attacker could use this to cause a denial of service (system crash) or possibly execute arbitrary code. (CVE-2020-35519) It was discovered that the fastrpc driver in the Linux kernel did not prevent user space applications from sending kernel RPC messages. A local attacker could possibly use this to gain elevated privileges. (CVE-2021-28375) It was discovered that the TIPC protocol implementation in the Linux kernel did not properly validate passed encryption key sizes. A local attacker could use this to cause a denial of service (system crash). (CVE-2021-29646) It was discovered that a race condition existed in the netfilter subsystem of the Linux kernel when replacing tables. A local attacker could use this to cause [ more… ]

No Image

USN-4945-1: Linux kernel vulnerabilities

2021-05-12 KENNETH 0

USN-4945-1: Linux kernel vulnerabilities It was discovered that the Nouveau GPU driver in the Linux kernel did not properly handle error conditions in some situations. A local attacker could use this to cause a denial of service (system crash). (CVE-2020-25639) Jan Beulich discovered that the Xen netback backend in the Linux kernel did not properly handle certain error conditions under paravirtualization. An attacker in a guest VM could possibly use this to cause a denial of service (host domain crash). (CVE-2021-28038) It was discovered that the fastrpc driver in the Linux kernel did not prevent user space applications from sending kernel RPC messages. A local attacker could possibly use this to gain elevated privileges. (CVE-2021-28375) It was discovered that the Realtek RTL8188EU Wireless device driver in the Linux kernel did not properly validate ssid lengths in some situations. An attacker [ more… ]

No Image

USN-4944-1: MariaDB vulnerabilities

2021-05-12 KENNETH 0

USN-4944-1: MariaDB vulnerabilities This update fixed multiple vulnerabilities in MariaDB. Ubuntu 18.04 LTS has been updated to MariaDB 10.1.48. Ubuntu 20.04 LTS has been updated to MariaDB 10.3.29. Ubuntu 20.10 has been updated to MariaDB 10.3.29. Ubuntu 21.04 has been updated to MariaDB 10.5.10. Source: USN-4944-1: MariaDB vulnerabilities

No Image

HP’s new ZBook G8 mobile workstations aim for collaborative hybrid work environments

2021-05-12 KENNETH 0

HP’s new ZBook G8 mobile workstations aim for collaborative hybrid work environments Anticipating that working from home – or at least, not in the office – will continue for the foreseeable future, HP has unveiled the latest ZBook Studio G8, ZBook Fury G8 and ZBook Power G8, which all run on Windows 10. The HP ZBook Studio is designed for performance workflows. Animate in seconds and render or visualize in real time with up to NVIDIA RTX A5000 or GeForce RTX 3080 laptop GPUs and 11th Gen Intel Core i9 vPro processors. HP DreamColor displays with a 120Hz refresh rate provide certainty that your design is right the first time, with 100% DCI-P3 and end-to-end color accuracy with Pantone validation. HP Sound Calibration helps make the the office anywhere you want to work with crisp audio and automatic blocking of unwanted [ more… ]