Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

openSUSE: 2021:0060-1 Important Security Advisory for Kernel

opensuse
Calendar Grey January 14, 2021
Dist Opensuse Esm H88
A significant announcement for Ubuntu addresses 20 security issues and implements 88 essential patches for the Linux Core.
An update that solves 17 vulnerabilities and has 99 fixes is now available

Description

The openSUSE Leap 15.2 kernel was updated to receive various security and

bugfixes.

The following security bugs were fixed:

- CVE-2020-27835: A use after free in the Linux kernel infiniband hfi1

driver was found in the way user calls Ioctl after open dev file and

fork. A local user could use this flaw to crash the system (bnc#1179878).

- CVE-2020-25639: Fixed a NULL pointer dereference via nouveau ioctl

(bnc#1176846).

- CVE-2020-28374: In drivers/target/target_core_xcopy.c insufficient

identifier checking in the LIO SCSI target code can be used by remote

attackers to read or write files via directory traversal in an XCOPY

request, aka CID-2896c93811e3. For example, an attack can occur over a

network if the attacker has access to one iSCSI LUN. The attacker gains

control over file access because I/O operations are proxied via an

attacker-selected backstore (bnc#1178372).

- CVE-2020-36158:...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-60=1

Package List

- openSUSE Leap 15.2 (noarch):

kernel-devel-5.3.18-lp152.60.1

kernel-docs-5.3.18-lp152.60.1

kernel-docs-html-5.3.18-lp152.60.1

kernel-macros-5.3.18-lp152.60.1

kernel-source-5.3.18-lp152.60.1

kernel-source-vanilla-5.3.18-lp152.60.1

- openSUSE Leap 15.2 (x86_64):

kernel-debug-5.3.18-lp152.60.1

kernel-debug-debuginfo-5.3.18-lp152.60.1

kernel-debug-debugsource-5.3.18-lp152.60.1

kernel-debug-devel-5.3.18-lp152.60.1

kernel-debug-devel-debuginfo-5.3.18-lp152.60.1

kernel-default-5.3.18-lp152.60.1

kernel-default-debuginfo-5.3.18-lp152.60.1

kernel-default-debugsource-5.3.18-lp152.60.1

kernel-default-devel-5.3.18-lp152.60.1

kernel-default-devel-debuginfo-5.3.18-lp152.60.1

kernel-kvmsmall-5.3.18-lp152.60.1

kernel-kvmsmall-debuginfo-5.3.18-lp152.60.1

kernel-kvmsmall-debugsource-5.3.18-lp152.60.1

kernel-kvmsmall-devel-5.3.18-lp152.60.1

kernel-kvmsmall-devel-debuginfo-5.3.18-lp152.60.1

kernel-obs-build-5.3.18-lp152.60.1

kernel-obs-build-debugsource-5.3.18-lp152.60.1

kernel-obs-qa-5.3.18-lp152.60.1

kernel-preempt-5.3.18-lp152....

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2020-0444.html

https://www.suse.com/security/cve/CVE-2020-0465.html

https://www.suse.com/security/cve/CVE-2020-0466.html

https://www.suse.com/security/cve/CVE-2020-11668.html

https://www.suse.com/security/cve/CVE-2020-25639.html

https://www.suse.com/security/cve/CVE-2020-27068.html

https://www.suse.com/security/cve/CVE-2020-27777.html

https://www.suse.com/security/cve/CVE-2020-27786.html

https://www.suse.com/security/cve/CVE-2020-27825.html

https://www.suse.com/security/cve/CVE-2020-27830.html

https://www.suse.com/security/cve/CVE-2020-27835.html

https://www.suse.com/security/cve/CVE-2020-28374.html

https://www.suse.com/security/cve/CVE-2020-29370.html

https://www.suse.com/security/cve/CVE-2020-29373.html

https://www.suse.com/security/cve/CVE-2020-29660.html

https://www.suse.com/security/cve/CVE-2020-29661.html

https://www.suse.com/security/cve/CVE-2020-36158.html

https://bugzilla.suse.com/1040855

https://bugzilla.suse.com/1044120

https://bugzilla.suse.com/1044767

htt...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:0060-1
Rating: important
Affected Products: openSUSE Leap 15.2 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here