Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

openSUSE Leap 15.1: 2020:2034-1 Important Kernel Security Fixes

opensuse
Calendar Grey November 26, 2020
Dist Opensuse Esm H88
A critical security notice highlighting several kernel vulnerabilities, including their resolutions and guidelines for software updates on openSUSE platforms.
An update that solves four vulnerabilities and has 20 fixes is now available.

Description

The openSUSE Leap 15.1 kernel was updated to receive various security and

bugfixes.

The following security bugs were fixed:

- CVE-2020-28915: A buffer over-read (at the framebuffer layer) in the

fbcon code could be used by local attackers to read kernel memory, aka

CID-6735b4632def (bnc#1178886).

- CVE-2020-25669: A use-after-free in teardown paths of sunkbd was fixed

(bsc#1178182).

- CVE-2020-25705: A flaw in the way reply ICMP packets are limited in the

Linux kernel functionality was found that allowed to quickly scan open

UDP ports. This flaw allowed an off-path remote user to effectively

bypassing source port UDP randomization. The highest threat from this

vulnerability is to confidentiality and possibly integrity, because

software that relies on UDP source port randomization are indirectly

affected as well. Kernel versions may be vulnerable to this issue

(bnc#1175721 bnc#1178782).

-...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-2034=1

Package List

- openSUSE Leap 15.1 (noarch):

kernel-devel-4.12.14-lp151.28.83.1

kernel-docs-4.12.14-lp151.28.83.1

kernel-docs-html-4.12.14-lp151.28.83.1

kernel-macros-4.12.14-lp151.28.83.1

kernel-source-4.12.14-lp151.28.83.1

kernel-source-vanilla-4.12.14-lp151.28.83.1

- openSUSE Leap 15.1 (x86_64):

kernel-debug-4.12.14-lp151.28.83.1

kernel-debug-base-4.12.14-lp151.28.83.1

kernel-debug-base-debuginfo-4.12.14-lp151.28.83.1

kernel-debug-debuginfo-4.12.14-lp151.28.83.1

kernel-debug-debugsource-4.12.14-lp151.28.83.1

kernel-debug-devel-4.12.14-lp151.28.83.1

kernel-debug-devel-debuginfo-4.12.14-lp151.28.83.1

kernel-default-4.12.14-lp151.28.83.1

kernel-default-base-4.12.14-lp151.28.83.1

kernel-default-base-debuginfo-4.12.14-lp151.28.83.1

kernel-default-debuginfo-4.12.14-lp151.28.83.1

kernel-default-debugsource-4.12.14-lp151.28.83.1

kernel-default-devel-4.12.14-lp151.28.83.1

kernel-default-devel-debuginfo-4.12.14-lp151.28.83.1

kernel-kvmsmall-4.12.14-lp151.28.83.1

kernel-kvmsmall-base-4.12.14-lp151.28.83.1

kernel-kvmsmall-base-debu...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2020-25669.html

https://www.suse.com/security/cve/CVE-2020-25704.html

https://www.suse.com/security/cve/CVE-2020-25705.html

https://www.suse.com/security/cve/CVE-2020-28915.html

https://bugzilla.suse.com/1050549

https://bugzilla.suse.com/1067665

https://bugzilla.suse.com/1170630

https://bugzilla.suse.com/1172873

https://bugzilla.suse.com/1175306

https://bugzilla.suse.com/1175721

https://bugzilla.suse.com/1176855

https://bugzilla.suse.com/1176983

https://bugzilla.suse.com/1177397

https://bugzilla.suse.com/1177703

https://bugzilla.suse.com/1177819

https://bugzilla.suse.com/1177820

https://bugzilla.suse.com/1178182

https://bugzilla.suse.com/1178393

https://bugzilla.suse.com/1178589

https://bugzilla.suse.com/1178686

https://bugzilla.suse.com/1178765

https://bugzilla.suse.com/1178782

https://bugzilla.suse.com/1178838

https://bugzilla.suse.com/1178853

https://bugzilla.suse.com/1178854

https://bugzilla.suse.com/1178878

https://bugzilla.suse.com/1178886

https://bugzilla.suse.com/927...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2020:2034-1
Rating: important
Affected Products: openSUSE Leap 15.1

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here