Alerts This Week
Warning Icon 1 770
Alerts This Week
Warning Icon 1 770

openSUSE 15.2: 2021:1271-1 Important Kernel Update for DoS Fixes

opensuse
Calendar Grey September 15, 2021
Dist Opensuse Esm H88
A significant release for Ubuntu addresses 20 security flaws in the core kernel, improving reliability and safeguarding user data.
An update that solves 15 vulnerabilities and has 92 fixes is now available

Description

The openSUSE Leap 15.2 kernel was updated to receive various security and

bugfixes.

The following security bugs were fixed:

- CVE-2021-3759: Unaccounted ipc objects in Linux kernel could have lead

to breaking memcg limits and DoS attacks (bsc#1190115).

- CVE-2021-38160: Data corruption or loss could be triggered by an

untrusted device that supplies a buf->len value exceeding the buffer

size in drivers/char/virtio_console.c (bsc#1190117)

- CVE-2021-3640: Fixed a Use-After-Free vulnerability in function

sco_sock_sendmsg() in the bluetooth stack (bsc#1188172).

- CVE-2021-3753: Fixed race out-of-bounds in virtual terminal handling

(bsc#1190025).

- CVE-2021-3743: Fixed OOB Read in qrtr_endpoint_post (bsc#1189883).

- CVE-2021-3739: Fixed a NULL pointer dereference when deleting device by

invalid id (bsc#1189832 ).

- CVE-2021-3732: Mounting overlayfs inside an unprivileged user namespace

can reveal files (bsc#1189706).

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.2:

zypper in -t patch openSUSE-2021-1271=1

Package List

- openSUSE Leap 15.2 (noarch):

kernel-devel-5.3.18-lp152.92.2

kernel-docs-5.3.18-lp152.92.1

kernel-docs-html-5.3.18-lp152.92.1

kernel-macros-5.3.18-lp152.92.2

kernel-source-5.3.18-lp152.92.2

kernel-source-vanilla-5.3.18-lp152.92.2

- openSUSE Leap 15.2 (x86_64):

kernel-debug-5.3.18-lp152.92.2

kernel-debug-debuginfo-5.3.18-lp152.92.2

kernel-debug-debugsource-5.3.18-lp152.92.2

kernel-debug-devel-5.3.18-lp152.92.2

kernel-debug-devel-debuginfo-5.3.18-lp152.92.2

kernel-default-5.3.18-lp152.92.2

kernel-default-base-5.3.18-lp152.92.2.lp152.8.42.3

kernel-default-base-rebuild-5.3.18-lp152.92.2.lp152.8.42.3

kernel-default-debuginfo-5.3.18-lp152.92.2

kernel-default-debugsource-5.3.18-lp152.92.2

kernel-default-devel-5.3.18-lp152.92.2

kernel-default-devel-debuginfo-5.3.18-lp152.92.2

kernel-kvmsmall-5.3.18-lp152.92.2

kernel-kvmsmall-debuginfo-5.3.18-lp152.92.2

kernel-kvmsmall-debugsource-5.3.18-lp152.92.2

kernel-kvmsmall-devel-5.3.18-lp152.92.2

kernel-kvmsmall-devel-debuginfo-5.3.18-lp152.92.2

kernel-obs-build-5.3.18-lp152.9...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2021-34556.html

https://www.suse.com/security/cve/CVE-2021-35477.html

https://www.suse.com/security/cve/CVE-2021-3640.html

https://www.suse.com/security/cve/CVE-2021-3653.html

https://www.suse.com/security/cve/CVE-2021-3656.html

https://www.suse.com/security/cve/CVE-2021-3732.html

https://www.suse.com/security/cve/CVE-2021-3739.html

https://www.suse.com/security/cve/CVE-2021-3743.html

https://www.suse.com/security/cve/CVE-2021-3753.html

https://www.suse.com/security/cve/CVE-2021-3759.html

https://www.suse.com/security/cve/CVE-2021-38160.html

https://www.suse.com/security/cve/CVE-2021-38198.html

https://www.suse.com/security/cve/CVE-2021-38204.html

https://www.suse.com/security/cve/CVE-2021-38205.html

https://www.suse.com/security/cve/CVE-2021-38207.html

https://bugzilla.suse.com/1040364

https://bugzilla.suse.com/1124431

https://bugzilla.suse.com/1127650

https://bugzilla.suse.com/1135481

https://bugzilla.suse.com/1152489

https://bugzilla.suse.com/1160010

https://bugzill...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:1271-1
Rating: important
Affected Products: openSUSE Leap 15.2 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here