Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

openSUSE Leap 15.3 Security Advisory 2021:3338-1 Important Kernel Issues

opensuse
Calendar Grey October 12, 2021
Dist Opensuse Esm H88
The recent Linux Kernel patch for openSUSE addresses significant vulnerabilities and strengthens the overall security posture against potential attacks.
An update that solves 6 vulnerabilities and has 54 fixes is now available

Description

The SUSE Linux Enterprise 15 SP3 kernel was updated.

The following security bugs were fixed:

- CVE-2020-3702: Fixed a bug which could be triggered with specifically

timed and handcrafted traffic and cause internal errors in a WLAN device

that lead to improper layer 2 Wi-Fi encryption with a consequent

possibility of information disclosure. (bnc#1191193)

- CVE-2021-3752: Fixed a use after free vulnerability in the Linux

kernel's bluetooth module. (bsc#1190023)

- CVE-2021-40490: Fixed a race condition discovered in the ext4 subsystem

that could leat to local priviledge escalation. (bnc#1190159)

- CVE-2021-3744: Fixed a bug which could allows attackers to cause a

denial of service. (bsc#1189884)

- CVE-2021-3764: Fixed a bug which could allows attackers to cause a

denial of service. (bsc#1190534)

- CVE-2021-3669: Fixed a bug that doesn't allow /proc/sysvipc/shm to scale

with large shared memory segment counts which could...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2021-3338=1

Package List

- openSUSE Leap 15.3 (noarch):

kernel-devel-azure-5.3.18-38.25.2

kernel-source-azure-5.3.18-38.25.2

- openSUSE Leap 15.3 (x86_64):

cluster-md-kmp-azure-5.3.18-38.25.2

cluster-md-kmp-azure-debuginfo-5.3.18-38.25.2

dlm-kmp-azure-5.3.18-38.25.2

dlm-kmp-azure-debuginfo-5.3.18-38.25.2

gfs2-kmp-azure-5.3.18-38.25.2

gfs2-kmp-azure-debuginfo-5.3.18-38.25.2

kernel-azure-5.3.18-38.25.2

kernel-azure-debuginfo-5.3.18-38.25.2

kernel-azure-debugsource-5.3.18-38.25.2

kernel-azure-devel-5.3.18-38.25.2

kernel-azure-devel-debuginfo-5.3.18-38.25.2

kernel-azure-extra-5.3.18-38.25.2

kernel-azure-extra-debuginfo-5.3.18-38.25.2

kernel-azure-livepatch-devel-5.3.18-38.25.2

kernel-azure-optional-5.3.18-38.25.2

kernel-azure-optional-debuginfo-5.3.18-38.25.2

kernel-syms-azure-5.3.18-38.25.1

kselftests-kmp-azure-5.3.18-38.25.2

kselftests-kmp-azure-debuginfo-5.3.18-38.25.2

ocfs2-kmp-azure-5.3.18-38.25.2

ocfs2-kmp-azure-debuginfo-5.3.18-38.25.2

reiserfs-kmp-azure-5.3.18-38.25.2

reiserfs-kmp-azure-debuginfo-5.3.18-38.25.2

References

https://www.suse.com/security/cve/CVE-2020-3702.html

https://www.suse.com/security/cve/CVE-2021-3669.html

https://www.suse.com/security/cve/CVE-2021-3744.html

https://www.suse.com/security/cve/CVE-2021-3752.html

https://www.suse.com/security/cve/CVE-2021-3764.html

https://www.suse.com/security/cve/CVE-2021-40490.html

https://bugzilla.suse.com/1065729

https://bugzilla.suse.com/1148868

https://bugzilla.suse.com/1152489

https://bugzilla.suse.com/1154353

https://bugzilla.suse.com/1159886

https://bugzilla.suse.com/1167773

https://bugzilla.suse.com/1170774

https://bugzilla.suse.com/1171688

https://bugzilla.suse.com/1173746

https://bugzilla.suse.com/1174003

https://bugzilla.suse.com/1176447

https://bugzilla.suse.com/1176940

https://bugzilla.suse.com/1177028

https://bugzilla.suse.com/1178134

https://bugzilla.suse.com/1184439

https://bugzilla.suse.com/1184804

https://bugzilla.suse.com/1185302

https://bugzilla.suse.com/1185550

https://bugzilla.suse.com/1185677

https://bugzilla.suse.com/1185726

https://bugzilla.suse.com/1...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:3338-1
Rating: important
Affected Products: openSUSE Leap 15.3 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here