The openSUSE Leap 15.1 kernel was updated to receive various security and
bugfixes.
The following security bugs were fixed:
- CVE-2020-25212: Fixed nfs getxattr kernel panic and memory overflow that
could lead to crashes or privilege escalations (bsc#1176381).
- CVE-2020-14381: Fixed inode life-time issue in futex handling
(bsc#1176011).
- CVE-2020-25643: Memory corruption and a read overflow is caused by
improper input validation in the ppp_cp_parse_cr function which can
cause the system to crash or cause a denial of service. The highest
threat from this vulnerability is to data confidentiality and integrity
as well as system availability (bnc#1177206).
- CVE-2020-25641: A zero-length biovec request issued by the block
subsystem could cause the kernel to enter an infinite loop, causing a
denial of service. This flaw allowed a local attacker with basic
privileges to issue requests to a block device, resulting in a...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.1:
zypper in -t patch openSUSE-2020-1655=1
- openSUSE Leap 15.1 (noarch):
kernel-devel-4.12.14-lp151.28.71.1
kernel-docs-4.12.14-lp151.28.71.1
kernel-docs-html-4.12.14-lp151.28.71.1
kernel-macros-4.12.14-lp151.28.71.1
kernel-source-4.12.14-lp151.28.71.1
kernel-source-vanilla-4.12.14-lp151.28.71.1
- openSUSE Leap 15.1 (x86_64):
kernel-debug-4.12.14-lp151.28.71.2
kernel-debug-base-4.12.14-lp151.28.71.2
kernel-debug-base-debuginfo-4.12.14-lp151.28.71.2
kernel-debug-debuginfo-4.12.14-lp151.28.71.2
kernel-debug-debugsource-4.12.14-lp151.28.71.2
kernel-debug-devel-4.12.14-lp151.28.71.2
kernel-debug-devel-debuginfo-4.12.14-lp151.28.71.2
kernel-default-4.12.14-lp151.28.71.2
kernel-default-base-4.12.14-lp151.28.71.2
kernel-default-base-debuginfo-4.12.14-lp151.28.71.2
kernel-default-debuginfo-4.12.14-lp151.28.71.2
kernel-default-debugsource-4.12.14-lp151.28.71.2
kernel-default-devel-4.12.14-lp151.28.71.2
kernel-default-devel-debuginfo-4.12.14-lp151.28.71.2
kernel-kvmsmall-4.12.14-lp151.28.71.2
kernel-kvmsmall-base-4.12.14-lp151.28.71.2
kernel-kvmsmall-base-debu...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2020-0404.html
https://www.suse.com/security/cve/CVE-2020-0427.html
https://www.suse.com/security/cve/CVE-2020-0431.html
https://www.suse.com/security/cve/CVE-2020-0432.html
https://www.suse.com/security/cve/CVE-2020-14381.html
https://www.suse.com/security/cve/CVE-2020-14386.html
https://www.suse.com/security/cve/CVE-2020-14390.html
https://www.suse.com/security/cve/CVE-2020-25212.html
https://www.suse.com/security/cve/CVE-2020-25284.html
https://www.suse.com/security/cve/CVE-2020-25641.html
https://www.suse.com/security/cve/CVE-2020-25643.html
https://www.suse.com/security/cve/CVE-2020-26088.html
https://bugzilla.suse.com/1055186
https://bugzilla.suse.com/1065600
https://bugzilla.suse.com/1065729
https://bugzilla.suse.com/1094244
https://bugzilla.suse.com/1112178
https://bugzilla.suse.com/1113956
https://bugzilla.suse.com/1154366
https://bugzilla.suse.com/1167527
https://bugzilla.suse.com/1168468
https://bugzilla.suse.com/1169972
https://bugzilla.suse.com/1171675
https...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.