Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various
security and bugfixes.
The following security bugs were fixed:
- CVE-2021-3640: Fixed a Use-After-Free vulnerability in function
sco_sock_sendmsg() in the bluetooth stack (bsc#1188172).
- CVE-2021-3653: Missing validation of the `int_ctl` VMCB field and allows
a malicious L1 guest to enable AVIC support for the L2 guest.
(bsc#1189399).
- CVE-2021-3656: Missing validation of the the `virt_ext` VMCB field and
allows a malicious L1 guest to disable both VMLOAD/VMSAVE intercepts and
VLS for the L2 guest (bsc#1189400).
- CVE-2021-3679: A lack of CPU resource in tracing module functionality
was found in the way user uses trace ring buffer in a specific way. Only
privileged local users (with CAP_SYS_ADMIN capability) could use this
flaw to starve the resources causing denial of service (bnc#1189057).
- CVE-2021-3732: Mounting overlayfs inside an...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.3:
zypper in -t patch openSUSE-SLE-15.3-2021-3205=1
- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):
cluster-md-kmp-default-5.3.18-59.24.1
cluster-md-kmp-default-debuginfo-5.3.18-59.24.1
dlm-kmp-default-5.3.18-59.24.1
dlm-kmp-default-debuginfo-5.3.18-59.24.1
gfs2-kmp-default-5.3.18-59.24.1
gfs2-kmp-default-debuginfo-5.3.18-59.24.1
kernel-default-5.3.18-59.24.1
kernel-default-base-5.3.18-59.24.1.18.12.1
kernel-default-base-rebuild-5.3.18-59.24.1.18.12.1
kernel-default-debuginfo-5.3.18-59.24.1
kernel-default-debugsource-5.3.18-59.24.1
kernel-default-devel-5.3.18-59.24.1
kernel-default-devel-debuginfo-5.3.18-59.24.1
kernel-default-extra-5.3.18-59.24.1
kernel-default-extra-debuginfo-5.3.18-59.24.1
kernel-default-livepatch-5.3.18-59.24.1
kernel-default-livepatch-devel-5.3.18-59.24.1
kernel-default-optional-5.3.18-59.24.1
kernel-default-optional-debuginfo-5.3.18-59.24.1
kernel-obs-build-5.3.18-59.24.1
kernel-obs-build-debugsource-5.3.18-59.24.1
kernel-obs-qa-5.3.18-59.24.1
kernel-syms-5.3.18-59.24.1
kselftests-kmp-default-5.3.18-59.24.1
kselftests-kmp-default-deb...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2020-12770.html
https://www.suse.com/security/cve/CVE-2021-34556.html
https://www.suse.com/security/cve/CVE-2021-35477.html
https://www.suse.com/security/cve/CVE-2021-3640.html
https://www.suse.com/security/cve/CVE-2021-3653.html
https://www.suse.com/security/cve/CVE-2021-3656.html
https://www.suse.com/security/cve/CVE-2021-3679.html
https://www.suse.com/security/cve/CVE-2021-3732.html
https://www.suse.com/security/cve/CVE-2021-3739.html
https://www.suse.com/security/cve/CVE-2021-3743.html
https://www.suse.com/security/cve/CVE-2021-3753.html
https://www.suse.com/security/cve/CVE-2021-3759.html
https://www.suse.com/security/cve/CVE-2021-38160.html
https://www.suse.com/security/cve/CVE-2021-38166.html
https://www.suse.com/security/cve/CVE-2021-38198.html
https://www.suse.com/security/cve/CVE-2021-38204.html
https://www.suse.com/security/cve/CVE-2021-38205.html
https://www.suse.com/security/cve/CVE-2021-38206.html
https://www.suse.com/security/cve/CVE-2021-38207.html
ht...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.