The openSUSE Leap 15.2 kernel was updated to receive various security and
bugfixes.
The following security bugs were fixed:
- CVE-2019-19462: relay_open in kernel/relay.c allowed local users to
cause a denial of service (such as relay blockage) by triggering a NULL
alloc_percpu result (bnc#1158265).
- CVE-2019-20810: go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c
did not call snd_card_free for a failure path, which causes a memory
leak, aka CID-9453264ef586 (bnc#1172458).
- CVE-2019-20812: The prb_calc_retire_blk_tmo() function in
net/packet/af_packet.c can result in a denial of service (CPU
consumption and soft lockup) in a certain failure case involving
TPACKET_V3, aka CID-b43d1f9f7067 (bnc#1172453).
- CVE-2020-10711: A NULL pointer dereference flaw was found in the Linux
kernel's SELinux subsystem. This flaw occurs while importing the
Commercial IP Security Option (CIPSO) protocol's category bitmap...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2020-935=1
- openSUSE Leap 15.2 (noarch):
kernel-devel-5.3.18-lp152.20.7.1
kernel-docs-5.3.18-lp152.20.7.1
kernel-docs-html-5.3.18-lp152.20.7.1
kernel-macros-5.3.18-lp152.20.7.1
kernel-source-5.3.18-lp152.20.7.1
kernel-source-vanilla-5.3.18-lp152.20.7.1
- openSUSE Leap 15.2 (x86_64):
kernel-debug-5.3.18-lp152.20.7.1
kernel-debug-debuginfo-5.3.18-lp152.20.7.1
kernel-debug-debugsource-5.3.18-lp152.20.7.1
kernel-debug-devel-5.3.18-lp152.20.7.1
kernel-debug-devel-debuginfo-5.3.18-lp152.20.7.1
kernel-default-5.3.18-lp152.20.7.1
kernel-default-debuginfo-5.3.18-lp152.20.7.1
kernel-default-debugsource-5.3.18-lp152.20.7.1
kernel-default-devel-5.3.18-lp152.20.7.1
kernel-default-devel-debuginfo-5.3.18-lp152.20.7.1
kernel-kvmsmall-5.3.18-lp152.20.7.1
kernel-kvmsmall-debuginfo-5.3.18-lp152.20.7.1
kernel-kvmsmall-debugsource-5.3.18-lp152.20.7.1
kernel-kvmsmall-devel-5.3.18-lp152.20.7.1
kernel-kvmsmall-devel-debuginfo-5.3.18-lp152.20.7.1
kernel-obs-build-5.3.18-lp152.20.7.1
kernel-obs-build-debugsource-5.3.18-lp152.20.7.1
kernel-obs-qa...
Read the Full Advisorybsc#1172739
- coredump: fix crash when umh is disabled (git-fixes).
- coredump: fix null pointer dereference on coredump (git-fixes).
- crypto: algapi - Avoid spurious modprobe on LOADED (git-fixes).
- crypto: algboss - do not wait during notifier callback (git-fixes).
- crypto: cavium/nitrox - Fix 'nitrox_get_first_device()' when ndevlist is
fully iterated (git-fixes).
- crypto: ccp -- do not "select" CONFIG_DMADEVICES (git-fixes).
- crypto: chelsio/chtls: properly set tp->lsndtime (git-fixes).
- crypto: drbg - fix error return code in drbg_alloc_state() (git-fixes).
- crypto: stm32/crc32 - fix ext4 chksum BUG_ON() (git-fixes).
- crypto: stm32/crc32 - fix multi-instance (git-fixes).
- crypto: stm32/crc32 - fix run-time self test issue (git-fixes).
- cxgb4: fix adapter crash due to wrong MC size
(networking-stable-20_04_27).
- cxgb4: fix large delays in PTP synchronization
(networking-stable-20_04_27).
- Delete
patches.suse/seltests-powerpc-Add-a-selftest-for-memcpy_mcsafe.patch
(bsc#1171699).
-...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.