Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The SUSE Linux Enterprise 15 SP3 azure kernel was updated to receive
various security and bugfixes.
The following security bugs were fixed:
- CVE-2020-26558: Bluetooth LE and BR/EDR secure pairing in Bluetooth Core
Specification 2.1 may permit a nearby man-in-the-middle attacker to
identify the Passkey used during pairing by reflection of the public key
and the authentication evidence of the initiating device, potentially
permitting this attacker to complete authenticated pairing with the
responding device using the correct Passkey for the pairing session.
(bnc#1179610 bnc#1186463)
- CVE-2021-0129: Improper access control in BlueZ may have allowed an
authenticated user to potentially enable information disclosure via
adjacent access (bnc#1186463).
- CVE-2020-36385: Fixed a use-after-free in drivers/infiniband/core/ucma.c
which could be triggered if the ctx is reached via the ctx_list in some
ucma_migrate_id...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.3:
zypper in -t patch openSUSE-SLE-15.3-2021-2202=1
- openSUSE Leap 15.3 (x86_64):
cluster-md-kmp-azure-5.3.18-38.8.1
cluster-md-kmp-azure-debuginfo-5.3.18-38.8.1
dlm-kmp-azure-5.3.18-38.8.1
dlm-kmp-azure-debuginfo-5.3.18-38.8.1
gfs2-kmp-azure-5.3.18-38.8.1
gfs2-kmp-azure-debuginfo-5.3.18-38.8.1
kernel-azure-5.3.18-38.8.1
kernel-azure-debuginfo-5.3.18-38.8.1
kernel-azure-debugsource-5.3.18-38.8.1
kernel-azure-devel-5.3.18-38.8.1
kernel-azure-devel-debuginfo-5.3.18-38.8.1
kernel-azure-extra-5.3.18-38.8.1
kernel-azure-extra-debuginfo-5.3.18-38.8.1
kernel-azure-livepatch-devel-5.3.18-38.8.1
kernel-azure-optional-5.3.18-38.8.1
kernel-azure-optional-debuginfo-5.3.18-38.8.1
kernel-syms-azure-5.3.18-38.8.1
kselftests-kmp-azure-5.3.18-38.8.1
kselftests-kmp-azure-debuginfo-5.3.18-38.8.1
ocfs2-kmp-azure-5.3.18-38.8.1
ocfs2-kmp-azure-debuginfo-5.3.18-38.8.1
reiserfs-kmp-azure-5.3.18-38.8.1
reiserfs-kmp-azure-debuginfo-5.3.18-38.8.1
- openSUSE Leap 15.3 (noarch):
kernel-devel-azure-5.3.18-38.8.1
kernel-source-azure-5.3.18-38.8.1
https://www.suse.com/security/cve/CVE-2020-26558.html
https://www.suse.com/security/cve/CVE-2020-36385.html
https://www.suse.com/security/cve/CVE-2020-36386.html
https://www.suse.com/security/cve/CVE-2021-0129.html
https://bugzilla.suse.com/1152489
https://bugzilla.suse.com/1154353
https://bugzilla.suse.com/1174978
https://bugzilla.suse.com/1176447
https://bugzilla.suse.com/1176771
https://bugzilla.suse.com/1178134
https://bugzilla.suse.com/1178612
https://bugzilla.suse.com/1179610
https://bugzilla.suse.com/1183712
https://bugzilla.suse.com/1184259
https://bugzilla.suse.com/1184436
https://bugzilla.suse.com/1184631
https://bugzilla.suse.com/1185195
https://bugzilla.suse.com/1185570
https://bugzilla.suse.com/1185589
https://bugzilla.suse.com/1185675
https://bugzilla.suse.com/1185701
https://bugzilla.suse.com/1186155
https://bugzilla.suse.com/1186286
https://bugzilla.suse.com/1186463
https://bugzilla.suse.com/1186472
https://bugzilla.suse.com/1186672
https://bugzilla.suse.com/1186677
https://bugzilla.suse.com/1186...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.