July 24th, 2021
The system could crash or be made to run programs as an administrator.
Package(s) : linux-image-ql-generic,
qlustar-module-core-bionic-amd64-11.0.1,
qlustar-module-core-centos7-amd64-11.0.1,
qlustar-module-core-centos8-amd64-11.0.1,
qlustar-module-core-focal-amd64-12.0.0,
qlustar-module-core-centos7-amd64-12.0.0,
qlustar-module-core-centos8-amd64-12.0.0
Qlustar releases : 11.0, 12.0
Affected versions: All versions prior to this update
Vulnerability : privilege escalation/denial of service
Problem type : local
Qlustar-specific : no
CVE Id(s) : Not documented
A number of vulnerabilities and bugs have been discovered in the 5.4.x Linux kernel series since the last Qlustar 12.0 release based on 5.4.128. They may lead to a denial of service or privilege escalation. Please check the following web pages that contain details of the fixes in each release after 5.4.128 up to the current Qlustar kernel 5.4.134:
Linux kernel 5.4.134 Linux kernel 5.4.133 Linux kernel 5.4.132 Linux kernel 5.4.131 Linux kernel 5.4.130 Linux kernel 5.4.129
A number of vulnerabilities and bugs have been discovered in the 4.19.x Linux kernel series since the last Qlustar 11.0 release based on 4.19.195. They may lead to a denial of service or privilege escalation. Please check the following web pages that contain details of the fixes in each release after 4.19.195 up to the current Qlustar kernel 4.19.198:
Linux kernel 4.19.198 Linux kernel 4.19.197 Linux kernel 4.19.196
In particular, there is a local root exploit bug in the linux kernels prior to these updates.
The problem can be corrected by updating your system to the following or more recent package versions:
linux-image-ql-generic 5.4.134-ql-generic-12.0-10
qlustar-module-core-focal-amd64-12.0.0 12.0.0.5-b542f1391
qlustar-module-core-centos7-amd64-12.0.0 12.0.0.5-b542f1391
qlustar-module-core-centos8-amd64-12.0.0 12.0.0.5-b542f1391
linux-image-ql-generic 4.19.198-ql-generic-11.0-25
qlustar-module-core-bionic-amd64-11.0.1 11.0.1.9-b543f1392
qlustar-module-core-centos7-amd64-11.0.1 11.0.1.9-b543f1392
qlustar-module-core-centos8-amd64-11.0.1 11.0.1.9-b543f1392
In addition to the steps described in the general Qlustar Update Instructions these updates require the following: