Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

openSUSE Leap 15.1: 2020:1682-1 Important: Kernel Security Update

opensuse
Calendar Grey October 17, 2020
Dist Opensuse Esm H88
This Fedora security upgrade addresses five severe kernel vulnerabilities and incorporates numerous vital updates. Discover more today.
An update that solves four vulnerabilities and has 9 fixes is now available.

Description

The openSUSE Leap 15.1 kernel was updated to receive various security and

bugfixes.

The following security bugs were fixed:

- CVE-2020-12351: A type confusion while processing AMP packets could be

used by physical close attackers to crash the kernel or potentially

execute code was fixed (bsc#1177724).

- CVE-2020-12352: A stack information leak when handling certain AMP

packets could be used by physical close attackers to leak information

from the kernel was fixed (bsc#1177725).

- CVE-2020-25212: A TOCTOU mismatch in the NFS client code could be used

by local attackers to corrupt memory or possibly have unspecified other

impact because a size check is in fs/nfs/nfs4proc.c instead of

fs/nfs/nfs4xdr.c, aka CID-b4487b935452 (bnc#1176381).

- CVE-2020-25645: Traffic between two Geneve endpoints may be unencrypted

when IPsec is configured to encrypt traffic for the specific UDP port

used by the GENEVE tunnel allowing...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-1682=1

Package List

- openSUSE Leap 15.1 (x86_64):

kernel-debug-4.12.14-lp151.28.75.1

kernel-debug-base-4.12.14-lp151.28.75.1

kernel-debug-base-debuginfo-4.12.14-lp151.28.75.1

kernel-debug-debuginfo-4.12.14-lp151.28.75.1

kernel-debug-debugsource-4.12.14-lp151.28.75.1

kernel-debug-devel-4.12.14-lp151.28.75.1

kernel-debug-devel-debuginfo-4.12.14-lp151.28.75.1

kernel-default-4.12.14-lp151.28.75.1

kernel-default-base-4.12.14-lp151.28.75.1

kernel-default-base-debuginfo-4.12.14-lp151.28.75.1

kernel-default-debuginfo-4.12.14-lp151.28.75.1

kernel-default-debugsource-4.12.14-lp151.28.75.1

kernel-default-devel-4.12.14-lp151.28.75.1

kernel-default-devel-debuginfo-4.12.14-lp151.28.75.1

kernel-kvmsmall-4.12.14-lp151.28.75.1

kernel-kvmsmall-base-4.12.14-lp151.28.75.1

kernel-kvmsmall-base-debuginfo-4.12.14-lp151.28.75.1

kernel-kvmsmall-debuginfo-4.12.14-lp151.28.75.1

kernel-kvmsmall-debugsource-4.12.14-lp151.28.75.1

kernel-kvmsmall-devel-4.12.14-lp151.28.75.1

kernel-kvmsmall-devel-debuginfo-4.12.14-lp151.28.75.1

kernel-obs-build-4.12.14-lp15...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2020-12351.html

https://www.suse.com/security/cve/CVE-2020-12352.html

https://www.suse.com/security/cve/CVE-2020-25212.html

https://www.suse.com/security/cve/CVE-2020-25645.html

https://bugzilla.suse.com/1065729

https://bugzilla.suse.com/1140683

https://bugzilla.suse.com/1172538

https://bugzilla.suse.com/1174748

https://bugzilla.suse.com/1175520

https://bugzilla.suse.com/1176381

https://bugzilla.suse.com/1176400

https://bugzilla.suse.com/1176946

https://bugzilla.suse.com/1177340

https://bugzilla.suse.com/1177511

https://bugzilla.suse.com/1177685

https://bugzilla.suse.com/1177724

https://bugzilla.suse.com/1177725

--

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2020:1682-1
Rating: important
Affected Products: openSUSE Leap 15.1 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here