Alerts This Week
Warning Icon 1 664
Alerts This Week
Warning Icon 1 664

openSUSE: 2020:2193-1 Important: Critical Kernel Security Update

opensuse
Calendar Grey December 7, 2020
Dist Opensuse Esm H88
Address 7 problems with the openSUSE Kernel upgrade: enhancements and security patches have been released.
An update that solves 7 vulnerabilities and has 45 fixes is now available

Description

The openSUSE Leap 15.2 kernel was updated to receive various security and

bugfixes.

The following security bugs were fixed:

- CVE-2020-29371: An issue was discovered in romfs_dev_read in

fs/romfs/storage.c where uninitialized memory leaks to userspace, aka

CID-bcf85fcedfdd (bnc#1179429).

- CVE-2020-15436: Use-after-free vulnerability in fs/block_dev.c allowed

local users to gain privileges or cause a denial of service by

leveraging improper access to a certain error field (bnc#1179141).

- CVE-2020-4788: IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could

allow a local user to obtain sensitive information from the data in the

L1 cache under extenuating circumstances. IBM X-Force ID: 189296

(bnc#1177666).

- CVE-2018-20669: An issue where a provided address with access_ok() is

not checked was discovered in i915_gem_execbuffer2_ioctl in

drivers/gpu/drm/i915/i915_gem_execbuffer.c, where a local...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2020-2193=1

Package List

- openSUSE Leap 15.1 (x86_64):

kernel-debug-4.12.14-lp151.28.87.2

kernel-debug-base-4.12.14-lp151.28.87.2

kernel-debug-base-debuginfo-4.12.14-lp151.28.87.2

kernel-debug-debuginfo-4.12.14-lp151.28.87.2

kernel-debug-debugsource-4.12.14-lp151.28.87.2

kernel-debug-devel-4.12.14-lp151.28.87.2

kernel-debug-devel-debuginfo-4.12.14-lp151.28.87.2

kernel-default-4.12.14-lp151.28.87.2

kernel-default-base-4.12.14-lp151.28.87.2

kernel-default-base-debuginfo-4.12.14-lp151.28.87.2

kernel-default-debuginfo-4.12.14-lp151.28.87.2

kernel-default-debugsource-4.12.14-lp151.28.87.2

kernel-default-devel-4.12.14-lp151.28.87.2

kernel-default-devel-debuginfo-4.12.14-lp151.28.87.2

kernel-kvmsmall-4.12.14-lp151.28.87.2

kernel-kvmsmall-base-4.12.14-lp151.28.87.2

kernel-kvmsmall-base-debuginfo-4.12.14-lp151.28.87.2

kernel-kvmsmall-debuginfo-4.12.14-lp151.28.87.2

kernel-kvmsmall-debugsource-4.12.14-lp151.28.87.2

kernel-kvmsmall-devel-4.12.14-lp151.28.87.2

kernel-kvmsmall-devel-debuginfo-4.12.14-lp151.28.87.2

kernel-obs-build-4.12.14-lp15...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2018-20669.html

https://www.suse.com/security/cve/CVE-2020-15436.html

https://www.suse.com/security/cve/CVE-2020-15437.html

https://www.suse.com/security/cve/CVE-2020-27777.html

https://www.suse.com/security/cve/CVE-2020-28974.html

https://www.suse.com/security/cve/CVE-2020-29371.html

https://www.suse.com/security/cve/CVE-2020-4788.html

https://bugzilla.suse.com/1050242

https://bugzilla.suse.com/1050536

https://bugzilla.suse.com/1050545

https://bugzilla.suse.com/1056653

https://bugzilla.suse.com/1056657

https://bugzilla.suse.com/1056787

https://bugzilla.suse.com/1064802

https://bugzilla.suse.com/1066129

https://bugzilla.suse.com/1103990

https://bugzilla.suse.com/1103992

https://bugzilla.suse.com/1104389

https://bugzilla.suse.com/1104393

https://bugzilla.suse.com/1109837

https://bugzilla.suse.com/1110096

https://bugzilla.suse.com/1111666

https://bugzilla.suse.com/1112178

https://bugzilla.suse.com/1112374

https://bugzilla.suse.com/1118657

https://bugzilla.suse.com/1122971

htt...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2020:2193-1
Rating: important
Affected Products: openSUSE Leap 15.1 able.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here