The openSUSE Leap 15.2 kernel was updated to receive various security and
bugfixes.
The following security bugs were fixed:
- CVE-2021-3347: A use-after-free was discovered in the PI futexes during
fault handling, allowing local users to execute code in the kernel
(bnc#1181349).
- CVE-2021-3348: Fixed a use-after-free in nbd_add_socket that could be
triggered by local attackers (with access to the nbd device) via an I/O
request at a certain point during device setup (bnc#1181504).
- CVE-2021-20177: Fixed a kernel panic related to iptables string matching
rules. A privileged user could insert a rule which could lead to denial
of service (bnc#1180765).
- CVE-2021-0342: In tun_get_user of tun.c, there is possible memory
corruption due to a use after free. This could lead to local escalation
of privilege with System execution privileges required. (bnc#1180812)
- CVE-2020-29569: Fixed a potential privilege escalation and...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.2:
zypper in -t patch openSUSE-2021-241=1
- openSUSE Leap 15.2 (noarch):
kernel-devel-5.3.18-lp152.63.1
kernel-docs-5.3.18-lp152.63.1
kernel-docs-html-5.3.18-lp152.63.1
kernel-macros-5.3.18-lp152.63.1
kernel-source-5.3.18-lp152.63.1
kernel-source-vanilla-5.3.18-lp152.63.1
- openSUSE Leap 15.2 (x86_64):
kernel-debug-5.3.18-lp152.63.1
kernel-debug-debuginfo-5.3.18-lp152.63.1
kernel-debug-debugsource-5.3.18-lp152.63.1
kernel-debug-devel-5.3.18-lp152.63.1
kernel-debug-devel-debuginfo-5.3.18-lp152.63.1
kernel-default-5.3.18-lp152.63.1
kernel-default-base-5.3.18-lp152.63.1.lp152.8.21.1
kernel-default-base-rebuild-5.3.18-lp152.63.1.lp152.8.21.1
kernel-default-debuginfo-5.3.18-lp152.63.1
kernel-default-debugsource-5.3.18-lp152.63.1
kernel-default-devel-5.3.18-lp152.63.1
kernel-default-devel-debuginfo-5.3.18-lp152.63.1
kernel-kvmsmall-5.3.18-lp152.63.1
kernel-kvmsmall-debuginfo-5.3.18-lp152.63.1
kernel-kvmsmall-debugsource-5.3.18-lp152.63.1
kernel-kvmsmall-devel-5.3.18-lp152.63.1
kernel-kvmsmall-devel-debuginfo-5.3.18-lp152.63.1
kernel-obs-build-5.3.18-lp152.6...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2020-25211.html
https://www.suse.com/security/cve/CVE-2020-29568.html
https://www.suse.com/security/cve/CVE-2020-29569.html
https://www.suse.com/security/cve/CVE-2021-0342.html
https://www.suse.com/security/cve/CVE-2021-20177.html
https://www.suse.com/security/cve/CVE-2021-3347.html
https://www.suse.com/security/cve/CVE-2021-3348.html
https://bugzilla.suse.com/1065600
https://bugzilla.suse.com/1149032
https://bugzilla.suse.com/1152472
https://bugzilla.suse.com/1152489
https://bugzilla.suse.com/1153274
https://bugzilla.suse.com/1154353
https://bugzilla.suse.com/1155518
https://bugzilla.suse.com/1163930
https://bugzilla.suse.com/1165545
https://bugzilla.suse.com/1167773
https://bugzilla.suse.com/1172355
https://bugzilla.suse.com/1176395
https://bugzilla.suse.com/1176831
https://bugzilla.suse.com/1178142
https://bugzilla.suse.com/1178631
https://bugzilla.suse.com/1179142
https://bugzilla.suse.com/1179396
https://bugzilla.suse.com/1179508
https://bugzilla.suse.com/1179509
https...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.