The openSUSE Leap 15.1 kernel was updated to receive various security and
bugfixes.
The following security bugs were fixed:
- CVE-2019-16746: An issue was discovered in net/wireless/nl80211.c where
it did not check the length of variable elements in a beacon head,
leading to a buffer overflow (bnc#1152107 1173659).
- CVE-2019-20810: go7007_snd_init in drivers/media/usb/go7007/snd-go7007.c
did not call snd_card_free for a failure path, which causes a memory
leak, aka CID-9453264ef586 (bnc#1172458).
- CVE-2019-20908: An issue was discovered in drivers/firmware/efi/efi.c
where Incorrect access permissions for the efivar_ssdt ACPI variable
could be used by attackers to bypass lockdown or secure boot
restrictions, aka CID-1957a85b0032 (bnc#1173567).
- CVE-2020-0305: In cdev_get of char_dev.c, there is a possible
use-after-free due to a race condition. This could lead to local
escalation of privilege with System...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2020-1153=1
- openSUSE Leap 15.1 (x86_64):
kernel-debug-4.12.14-lp151.28.59.1
kernel-debug-base-4.12.14-lp151.28.59.1
kernel-debug-base-debuginfo-4.12.14-lp151.28.59.1
kernel-debug-debuginfo-4.12.14-lp151.28.59.1
kernel-debug-debugsource-4.12.14-lp151.28.59.1
kernel-debug-devel-4.12.14-lp151.28.59.1
kernel-debug-devel-debuginfo-4.12.14-lp151.28.59.1
kernel-default-4.12.14-lp151.28.59.1
kernel-default-base-4.12.14-lp151.28.59.1
kernel-default-base-debuginfo-4.12.14-lp151.28.59.1
kernel-default-debuginfo-4.12.14-lp151.28.59.1
kernel-default-debugsource-4.12.14-lp151.28.59.1
kernel-default-devel-4.12.14-lp151.28.59.1
kernel-default-devel-debuginfo-4.12.14-lp151.28.59.1
kernel-kvmsmall-4.12.14-lp151.28.59.1
kernel-kvmsmall-base-4.12.14-lp151.28.59.1
kernel-kvmsmall-base-debuginfo-4.12.14-lp151.28.59.1
kernel-kvmsmall-debuginfo-4.12.14-lp151.28.59.1
kernel-kvmsmall-debugsource-4.12.14-lp151.28.59.1
kernel-kvmsmall-devel-4.12.14-lp151.28.59.1
kernel-kvmsmall-devel-debuginfo-4.12.14-lp151.28.59.1
kernel-obs-build-4.12.14-lp15...
Read the Full Advisorybsc#1174549
- copy_{to,from}_user(): consolidate object size checks (git fixes).
- crypto: algboss - do not wait during notifier callback (bsc#1111666).
- crypto: algif_skcipher - Cap recv SG list at ctx->used (bsc#1111666).
- crypto: caam - update xts sector size for large input length
(bsc#1111666).
- crypto: cavium/nitrox - Fix 'nitrox_get_first_device()' when ndevlist is
fully iterated (bsc#1111666).
- crypto: cavium/nitrox - Fix 'nitrox_get_first_device()' when ndevlist is
fully iterated (git-fixes).
- crypto/chcr: fix for ccm(aes) failed test (bsc#1111666).
- crypto: chelsio/chtls: properly set tp->lsndtime (bsc#1111666).
- crypto: rockchip - fix scatterlist nents error (git-fixes).
- crypto: stm32/crc32 - fix ext4 chksum BUG_ON() (git-fixes).
- crypto: talitos - check AES key size (git-fixes).
- crypto: talitos - fix ablkcipher for CONFIG_VMAP_STACK (git-fixes).
- crypto: talitos - fix IPsec cipher in length (git-fixes).
- crypto: talitos - reorder code in talitos_edesc_alloc() (git-fixes).
-...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.