Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

openSUSE Leap 15.1: 2020:0801-1 Important: Kernel Update

opensuse
Calendar Grey June 13, 2020
Dist Opensuse Esm H88
This notification provides a significant update for the openSUSE kernel, incorporating 25 CVE resolution measures and necessitating a restart of the system.
An update that solves 25 vulnerabilities and has 132 fixes is now available.

Description

The openSUSE Leap 15.1 kernel was updated to receive various security and

bugfixes.

The following security bugs were fixed:

- CVE-2020-0543: Fixed a side channel attack against special registers which could have resulted in leaking of read values to cores other than

the one which called it. This attack is known as Special Register Buffer

Data Sampling (SRBDS) or "CrossTalk" (bsc#1154824).

- CVE-2018-1000199: Fixed a potential local code execution via ptrace

(bsc#1089895).

- CVE-2019-19462: relay_open in kernel/relay.c allowed local users to

cause a denial of service (such as relay blockage) by triggering a NULL

alloc_percpu result (bnc#1158265).

- CVE-2019-20806: Fixed a null pointer dereference in

tw5864_handle_frame() which may had lead to denial of service

(bsc#1172199).

- CVE-2019-20812: The prb_calc_retire_blk_tmo() function in

net/packet/af_packet.c can result in a denial of service (CPU

consumption...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-801=1

Package List

- openSUSE Leap 15.1 (noarch):

kernel-devel-4.12.14-lp151.28.52.1

kernel-docs-4.12.14-lp151.28.52.2

kernel-docs-html-4.12.14-lp151.28.52.2

kernel-macros-4.12.14-lp151.28.52.1

kernel-source-4.12.14-lp151.28.52.1

kernel-source-vanilla-4.12.14-lp151.28.52.1

- openSUSE Leap 15.1 (x86_64):

kernel-debug-4.12.14-lp151.28.52.1

kernel-debug-base-4.12.14-lp151.28.52.1

kernel-debug-base-debuginfo-4.12.14-lp151.28.52.1

kernel-debug-debuginfo-4.12.14-lp151.28.52.1

kernel-debug-debugsource-4.12.14-lp151.28.52.1

kernel-debug-devel-4.12.14-lp151.28.52.1

kernel-debug-devel-debuginfo-4.12.14-lp151.28.52.1

kernel-default-4.12.14-lp151.28.52.1

kernel-default-base-4.12.14-lp151.28.52.1

kernel-default-base-debuginfo-4.12.14-lp151.28.52.1

kernel-default-debuginfo-4.12.14-lp151.28.52.1

kernel-default-debugsource-4.12.14-lp151.28.52.1

kernel-default-devel-4.12.14-lp151.28.52.1

kernel-default-devel-debuginfo-4.12.14-lp151.28.52.1

kernel-kvmsmall-4.12.14-lp151.28.52.1

kernel-kvmsmall-base-4.12.14-lp151.28.52.1

kernel-kvmsmall-base-debu...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2018-1000199.html

https://www.suse.com/security/cve/CVE-2019-19462.html

https://www.suse.com/security/cve/CVE-2019-20806.html

https://www.suse.com/security/cve/CVE-2019-20812.html

https://www.suse.com/security/cve/CVE-2019-9455.html

https://www.suse.com/security/cve/CVE-2020-0543.html

https://www.suse.com/security/cve/CVE-2020-10690.html

https://www.suse.com/security/cve/CVE-2020-10711.html

https://www.suse.com/security/cve/CVE-2020-10720.html

https://www.suse.com/security/cve/CVE-2020-10732.html

https://www.suse.com/security/cve/CVE-2020-10751.html

https://www.suse.com/security/cve/CVE-2020-10757.html

https://www.suse.com/security/cve/CVE-2020-11608.html

https://www.suse.com/security/cve/CVE-2020-11609.html

https://www.suse.com/security/cve/CVE-2020-12114.html

https://www.suse.com/security/cve/CVE-2020-12464.html

https://www.suse.com/security/cve/CVE-2020-12652.html

https://www.suse.com/security/cve/CVE-2020-12653.html

https://www.suse.com/security/cve/CVE-2020-126...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2020:0801-1
Rating: important
Affected Products: openSUSE Leap 15.1 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here