Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

openSUSE Leap 15.3: 2305-1 Important Fixes For Kernel Security

opensuse
Calendar Grey July 13, 2021
Dist Opensuse Esm H88
The most recent Fedora release tackles critical Python vulnerabilities, improving application security and overall performance.
An update that solves 5 vulnerabilities and has 40 fixes is now available

Description

The SUSE Linux Enterprise 15 SP3 Azure kernel was updated to receive

various security and bugfixes.

The following security bugs were fixed:

- CVE-2021-3573: Fixed an UAF vulnerability in function that can allow

attackers to corrupt kernel heaps and adopt further exploitations.

(bsc#1186666)

- CVE-2021-0605: Fixed an out-of-bounds read which could lead to local

information disclosure in the kernel with System execution privileges

needed. (bsc#1187601)

- CVE-2021-0512: Fixed a possible out-of-bounds write which could lead to

local escalation of privilege with no additional execution privileges

needed. (bsc#1187595)

- CVE-2021-33624: Fixed a bug which allows unprivileged BPF program to

leak the contents of arbitrary kernel memory (and therefore, of all

physical memory) via a side-channel. (bsc#1187554)

- CVE-2021-34693: Fixed a bug in net/can/bcm.c which could allow local

users to obtain sensitive information from...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2021-2305=1

Package List

- openSUSE Leap 15.3 (noarch):

kernel-devel-azure-5.3.18-38.11.1

kernel-source-azure-5.3.18-38.11.1

- openSUSE Leap 15.3 (x86_64):

cluster-md-kmp-azure-5.3.18-38.11.1

cluster-md-kmp-azure-debuginfo-5.3.18-38.11.1

dlm-kmp-azure-5.3.18-38.11.1

dlm-kmp-azure-debuginfo-5.3.18-38.11.1

gfs2-kmp-azure-5.3.18-38.11.1

gfs2-kmp-azure-debuginfo-5.3.18-38.11.1

kernel-azure-5.3.18-38.11.1

kernel-azure-debuginfo-5.3.18-38.11.1

kernel-azure-debugsource-5.3.18-38.11.1

kernel-azure-devel-5.3.18-38.11.1

kernel-azure-devel-debuginfo-5.3.18-38.11.1

kernel-azure-extra-5.3.18-38.11.1

kernel-azure-extra-debuginfo-5.3.18-38.11.1

kernel-azure-livepatch-devel-5.3.18-38.11.1

kernel-azure-optional-5.3.18-38.11.1

kernel-azure-optional-debuginfo-5.3.18-38.11.1

kernel-syms-azure-5.3.18-38.11.1

kselftests-kmp-azure-5.3.18-38.11.1

kselftests-kmp-azure-debuginfo-5.3.18-38.11.1

ocfs2-kmp-azure-5.3.18-38.11.1

ocfs2-kmp-azure-debuginfo-5.3.18-38.11.1

reiserfs-kmp-azure-5.3.18-38.11.1

reiserfs-kmp-azure-debuginfo-5.3.18-38.11.1

References

https://www.suse.com/security/cve/CVE-2021-0512.html

https://www.suse.com/security/cve/CVE-2021-0605.html

https://www.suse.com/security/cve/CVE-2021-33624.html

https://www.suse.com/security/cve/CVE-2021-34693.html

https://www.suse.com/security/cve/CVE-2021-3573.html

https://bugzilla.suse.com/1152489

https://bugzilla.suse.com/1153274

https://bugzilla.suse.com/1154353

https://bugzilla.suse.com/1155518

https://bugzilla.suse.com/1164648

https://bugzilla.suse.com/1176447

https://bugzilla.suse.com/1176774

https://bugzilla.suse.com/1176919

https://bugzilla.suse.com/1177028

https://bugzilla.suse.com/1178134

https://bugzilla.suse.com/1182470

https://bugzilla.suse.com/1183682

https://bugzilla.suse.com/1184212

https://bugzilla.suse.com/1184685

https://bugzilla.suse.com/1185486

https://bugzilla.suse.com/1185675

https://bugzilla.suse.com/1185677

https://bugzilla.suse.com/1186071

https://bugzilla.suse.com/1186206

https://bugzilla.suse.com/1186666

https://bugzilla.suse.com/1186949

https://bugzilla.suse.com/1187171

https://bugz...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:2305-1
Rating: important
Affected Products: openSUSE Leap 15.3 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here