The openSUSE Leap 15.2 kernel was updated to receive various security and
bugfixes.
The following security bugs were fixed:
- CVE-2020-27835: A use after free in the Linux kernel infiniband hfi1
driver was found in the way user calls Ioctl after open dev file and
fork. A local user could use this flaw to crash the system (bnc#1179878).
- CVE-2020-25639: Fixed a NULL pointer dereference via nouveau ioctl
(bnc#1176846).
- CVE-2020-28374: In drivers/target/target_core_xcopy.c insufficient
identifier checking in the LIO SCSI target code can be used by remote
attackers to read or write files via directory traversal in an XCOPY
request, aka CID-2896c93811e3. For example, an attack can occur over a
network if the attacker has access to one iSCSI LUN. The attacker gains
control over file access because I/O operations are proxied via an
attacker-selected backstore (bnc#1178372).
- CVE-2020-36158:...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-60=1
- openSUSE Leap 15.2 (noarch):
kernel-devel-5.3.18-lp152.60.1
kernel-docs-5.3.18-lp152.60.1
kernel-docs-html-5.3.18-lp152.60.1
kernel-macros-5.3.18-lp152.60.1
kernel-source-5.3.18-lp152.60.1
kernel-source-vanilla-5.3.18-lp152.60.1
- openSUSE Leap 15.2 (x86_64):
kernel-debug-5.3.18-lp152.60.1
kernel-debug-debuginfo-5.3.18-lp152.60.1
kernel-debug-debugsource-5.3.18-lp152.60.1
kernel-debug-devel-5.3.18-lp152.60.1
kernel-debug-devel-debuginfo-5.3.18-lp152.60.1
kernel-default-5.3.18-lp152.60.1
kernel-default-debuginfo-5.3.18-lp152.60.1
kernel-default-debugsource-5.3.18-lp152.60.1
kernel-default-devel-5.3.18-lp152.60.1
kernel-default-devel-debuginfo-5.3.18-lp152.60.1
kernel-kvmsmall-5.3.18-lp152.60.1
kernel-kvmsmall-debuginfo-5.3.18-lp152.60.1
kernel-kvmsmall-debugsource-5.3.18-lp152.60.1
kernel-kvmsmall-devel-5.3.18-lp152.60.1
kernel-kvmsmall-devel-debuginfo-5.3.18-lp152.60.1
kernel-obs-build-5.3.18-lp152.60.1
kernel-obs-build-debugsource-5.3.18-lp152.60.1
kernel-obs-qa-5.3.18-lp152.60.1
kernel-preempt-5.3.18-lp152....
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2020-0444.html
https://www.suse.com/security/cve/CVE-2020-0465.html
https://www.suse.com/security/cve/CVE-2020-0466.html
https://www.suse.com/security/cve/CVE-2020-11668.html
https://www.suse.com/security/cve/CVE-2020-25639.html
https://www.suse.com/security/cve/CVE-2020-27068.html
https://www.suse.com/security/cve/CVE-2020-27777.html
https://www.suse.com/security/cve/CVE-2020-27786.html
https://www.suse.com/security/cve/CVE-2020-27825.html
https://www.suse.com/security/cve/CVE-2020-27830.html
https://www.suse.com/security/cve/CVE-2020-27835.html
https://www.suse.com/security/cve/CVE-2020-28374.html
https://www.suse.com/security/cve/CVE-2020-29370.html
https://www.suse.com/security/cve/CVE-2020-29373.html
https://www.suse.com/security/cve/CVE-2020-29660.html
https://www.suse.com/security/cve/CVE-2020-29661.html
https://www.suse.com/security/cve/CVE-2020-36158.html
https://bugzilla.suse.com/1040855
https://bugzilla.suse.com/1044120
https://bugzilla.suse.com/1044767
htt...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.