Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

openSUSE Leap 15.2: Security Update for Linux Kernel - Important Fixes

opensuse
Calendar Grey October 19, 2020
Dist Opensuse Esm H88
The latest Ubuntu Security Patch introduces vital enhancements for the Linux Kernel, boosting protection and correcting vulnerabilities.
An update that solves 7 vulnerabilities and has 39 fixes is now available.

Description

The openSUSE Leap 15.2 kernel was updated to receive various security and

bugfixes.

The following security bugs were fixed:

- CVE-2020-12351: Fixed a type confusion while processing AMP packets aka

"BleedingTooth" aka "BadKarma" (bsc#1177724).

- CVE-2020-24490: Fixed a heap buffer overflow when processing extended

advertising report events aka "BleedingTooth" aka "BadVibes"

(bsc#1177726).

- CVE-2020-12352: Fixed an information leak when processing certain AMP

packets aka "BleedingTooth" aka "BadChoice" (bsc#1177725).

- CVE-2020-25212: A TOCTOU mismatch in the NFS client code in the Linux

kernel could be used by local attackers to corrupt memory or possibly

have unspecified other impact because a size check is in

fs/nfs/nfs4proc.c instead of fs/nfs/nfs4xdr.c, aka CID-b4487b935452

(bnc#1176381).

- CVE-2020-25645: Traffic between two Geneve endpoints may be unencrypted

when IPsec is configured to encrypt traffic...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2020-1698=1

Package List

- openSUSE Leap 15.2 (x86_64):

kernel-debug-5.3.18-lp152.47.2

kernel-debug-debuginfo-5.3.18-lp152.47.2

kernel-debug-debugsource-5.3.18-lp152.47.2

kernel-debug-devel-5.3.18-lp152.47.2

kernel-debug-devel-debuginfo-5.3.18-lp152.47.2

kernel-default-5.3.18-lp152.47.2

kernel-default-debuginfo-5.3.18-lp152.47.2

kernel-default-debugsource-5.3.18-lp152.47.2

kernel-default-devel-5.3.18-lp152.47.2

kernel-default-devel-debuginfo-5.3.18-lp152.47.2

kernel-kvmsmall-5.3.18-lp152.47.2

kernel-kvmsmall-debuginfo-5.3.18-lp152.47.2

kernel-kvmsmall-debugsource-5.3.18-lp152.47.2

kernel-kvmsmall-devel-5.3.18-lp152.47.2

kernel-kvmsmall-devel-debuginfo-5.3.18-lp152.47.2

kernel-obs-build-5.3.18-lp152.47.2

kernel-obs-build-debugsource-5.3.18-lp152.47.2

kernel-obs-qa-5.3.18-lp152.47.1

kernel-preempt-5.3.18-lp152.47.2

kernel-preempt-debuginfo-5.3.18-lp152.47.2

kernel-preempt-debugsource-5.3.18-lp152.47.2

kernel-preempt-devel-5.3.18-lp152.47.2

kernel-preempt-devel-debuginfo-5.3.18-lp152.47.2

kernel-syms-5.3.18-lp152.47.1

- openSUSE Leap...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2020-12351.html

https://www.suse.com/security/cve/CVE-2020-12352.html

https://www.suse.com/security/cve/CVE-2020-24490.html

https://www.suse.com/security/cve/CVE-2020-25212.html

https://www.suse.com/security/cve/CVE-2020-25641.html

https://www.suse.com/security/cve/CVE-2020-25643.html

https://www.suse.com/security/cve/CVE-2020-25645.html

https://bugzilla.suse.com/1065600

https://bugzilla.suse.com/1065729

https://bugzilla.suse.com/1155798

https://bugzilla.suse.com/1165692

https://bugzilla.suse.com/1168468

https://bugzilla.suse.com/1171675

https://bugzilla.suse.com/1171688

https://bugzilla.suse.com/1174003

https://bugzilla.suse.com/1174098

https://bugzilla.suse.com/1175599

https://bugzilla.suse.com/1175621

https://bugzilla.suse.com/1175718

https://bugzilla.suse.com/1175807

https://bugzilla.suse.com/1176019

https://bugzilla.suse.com/1176381

https://bugzilla.suse.com/1176400

https://bugzilla.suse.com/1176588

https://bugzilla.suse.com/1176907

https://bugzilla.suse.com/1176979

ht...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2020:1698-1
Rating: important
Affected Products: openSUSE Leap 15.2 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here