Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

openSUSE: 2021:0241-1 Critical: Kernel Security Issues Fixed

opensuse
Calendar Grey February 5, 2021
Dist Opensuse Esm H88
Important openSUSE patch for Linux Kernel addresses several security issues. A prompt system restart is necessary following the installation.
An update that solves 7 vulnerabilities and has 49 fixes is now available

Description

The openSUSE Leap 15.2 kernel was updated to receive various security and

bugfixes.

The following security bugs were fixed:

- CVE-2021-3347: A use-after-free was discovered in the PI futexes during

fault handling, allowing local users to execute code in the kernel

(bnc#1181349).

- CVE-2021-3348: Fixed a use-after-free in nbd_add_socket that could be

triggered by local attackers (with access to the nbd device) via an I/O

request at a certain point during device setup (bnc#1181504).

- CVE-2021-20177: Fixed a kernel panic related to iptables string matching

rules. A privileged user could insert a rule which could lead to denial

of service (bnc#1180765).

- CVE-2021-0342: In tun_get_user of tun.c, there is possible memory

corruption due to a use after free. This could lead to local escalation

of privilege with System execution privileges required. (bnc#1180812)

- CVE-2020-29569: Fixed a potential privilege escalation and...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-241=1

Package List

- openSUSE Leap 15.2 (noarch):

kernel-devel-5.3.18-lp152.63.1

kernel-docs-5.3.18-lp152.63.1

kernel-docs-html-5.3.18-lp152.63.1

kernel-macros-5.3.18-lp152.63.1

kernel-source-5.3.18-lp152.63.1

kernel-source-vanilla-5.3.18-lp152.63.1

- openSUSE Leap 15.2 (x86_64):

kernel-debug-5.3.18-lp152.63.1

kernel-debug-debuginfo-5.3.18-lp152.63.1

kernel-debug-debugsource-5.3.18-lp152.63.1

kernel-debug-devel-5.3.18-lp152.63.1

kernel-debug-devel-debuginfo-5.3.18-lp152.63.1

kernel-default-5.3.18-lp152.63.1

kernel-default-base-5.3.18-lp152.63.1.lp152.8.21.1

kernel-default-base-rebuild-5.3.18-lp152.63.1.lp152.8.21.1

kernel-default-debuginfo-5.3.18-lp152.63.1

kernel-default-debugsource-5.3.18-lp152.63.1

kernel-default-devel-5.3.18-lp152.63.1

kernel-default-devel-debuginfo-5.3.18-lp152.63.1

kernel-kvmsmall-5.3.18-lp152.63.1

kernel-kvmsmall-debuginfo-5.3.18-lp152.63.1

kernel-kvmsmall-debugsource-5.3.18-lp152.63.1

kernel-kvmsmall-devel-5.3.18-lp152.63.1

kernel-kvmsmall-devel-debuginfo-5.3.18-lp152.63.1

kernel-obs-build-5.3.18-lp152.6...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2020-25211.html

https://www.suse.com/security/cve/CVE-2020-29568.html

https://www.suse.com/security/cve/CVE-2020-29569.html

https://www.suse.com/security/cve/CVE-2021-0342.html

https://www.suse.com/security/cve/CVE-2021-20177.html

https://www.suse.com/security/cve/CVE-2021-3347.html

https://www.suse.com/security/cve/CVE-2021-3348.html

https://bugzilla.suse.com/1065600

https://bugzilla.suse.com/1149032

https://bugzilla.suse.com/1152472

https://bugzilla.suse.com/1152489

https://bugzilla.suse.com/1153274

https://bugzilla.suse.com/1154353

https://bugzilla.suse.com/1155518

https://bugzilla.suse.com/1163930

https://bugzilla.suse.com/1165545

https://bugzilla.suse.com/1167773

https://bugzilla.suse.com/1172355

https://bugzilla.suse.com/1176395

https://bugzilla.suse.com/1176831

https://bugzilla.suse.com/1178142

https://bugzilla.suse.com/1178631

https://bugzilla.suse.com/1179142

https://bugzilla.suse.com/1179396

https://bugzilla.suse.com/1179508

https://bugzilla.suse.com/1179509

https...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:0241-1
Rating: important
Affected Products: openSUSE Leap 15.2 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here