Alerts This Week
Warning Icon 1 566
Alerts This Week
Warning Icon 1 566

openSUSE Leap 15.2: 2020:2161-1 Important Security Fixes

opensuse
Calendar Grey December 4, 2020
Dist Opensuse Esm H88
Major Fedora patch addresses 9 vulnerabilities and includes 45 corrections for the Linux Kernel. System restart mandated.
An update that solves 11 vulnerabilities and has 57 fixes is now available

Description

The openSUSE Leap 15.2 kernel was updated to receive various security and

bugfixes.

The following security bugs were fixed:

- CVE-2020-29369: There was a race condition between certain expand

functions (expand_downwards and expand_upwards) and page-table free

operations from an munmap call, aka CID-246c320a8cfe (bnc#1173504

bnc#1179432).

- CVE-2020-29371: An issue was discovered in romfs_dev_read in

fs/romfs/storage.c, where uninitialized memory could leak to userspace,

aka CID-bcf85fcedfdd (bnc#1179429).

- CVE-2020-15436: Use-after-free vulnerability in fs/block_dev.c allowed

local users to gain privileges or cause a denial of service by

leveraging improper access to a certain error field (bnc#1179141).

- CVE-2020-25705: A flaw in the way reply ICMP packets are limited was

found that allowed to quickly scan open UDP ports. This flaw allowed an

off-path remote user to effectively bypassing...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2020-2161=1

Package List

- openSUSE Leap 15.2 (x86_64):

kernel-debug-5.3.18-lp152.54.1

kernel-debug-debuginfo-5.3.18-lp152.54.1

kernel-debug-debugsource-5.3.18-lp152.54.1

kernel-debug-devel-5.3.18-lp152.54.1

kernel-debug-devel-debuginfo-5.3.18-lp152.54.1

kernel-default-5.3.18-lp152.54.1

kernel-default-base-5.3.18-lp152.54.1.lp152.8.12.1

kernel-default-base-rebuild-5.3.18-lp152.54.1.lp152.8.12.1

kernel-default-debuginfo-5.3.18-lp152.54.1

kernel-default-debugsource-5.3.18-lp152.54.1

kernel-default-devel-5.3.18-lp152.54.1

kernel-default-devel-debuginfo-5.3.18-lp152.54.1

kernel-kvmsmall-5.3.18-lp152.54.1

kernel-kvmsmall-debuginfo-5.3.18-lp152.54.1

kernel-kvmsmall-debugsource-5.3.18-lp152.54.1

kernel-kvmsmall-devel-5.3.18-lp152.54.1

kernel-kvmsmall-devel-debuginfo-5.3.18-lp152.54.1

kernel-obs-build-5.3.18-lp152.54.1

kernel-obs-build-debugsource-5.3.18-lp152.54.1

kernel-obs-qa-5.3.18-lp152.54.1

kernel-preempt-5.3.18-lp152.54.1

kernel-preempt-debuginfo-5.3.18-lp152.54.1

kernel-preempt-debugsource-5.3.18-lp152.54.1

kernel-preempt-devel-5.3.1...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2020-15436.html

https://www.suse.com/security/cve/CVE-2020-15437.html

https://www.suse.com/security/cve/CVE-2020-25669.html

https://www.suse.com/security/cve/CVE-2020-25705.html

https://www.suse.com/security/cve/CVE-2020-27777.html

https://www.suse.com/security/cve/CVE-2020-28915.html

https://www.suse.com/security/cve/CVE-2020-28941.html

https://www.suse.com/security/cve/CVE-2020-28974.html

https://www.suse.com/security/cve/CVE-2020-29369.html

https://www.suse.com/security/cve/CVE-2020-29371.html

https://www.suse.com/security/cve/CVE-2020-4788.html

https://bugzilla.suse.com/1149032

https://bugzilla.suse.com/1152489

https://bugzilla.suse.com/1153274

https://bugzilla.suse.com/1154353

https://bugzilla.suse.com/1155518

https://bugzilla.suse.com/1160634

https://bugzilla.suse.com/1167773

https://bugzilla.suse.com/1170139

https://bugzilla.suse.com/1171073

https://bugzilla.suse.com/1171558

https://bugzilla.suse.com/1172873

https://bugzilla.suse.com/1173504

https://bugzilla.suse....

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2020:2161-1
Rating: important
Affected Products: openSUSE Leap 15.2 able.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here