Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

openSUSE Leap 15.3: 2021:3641-1 Important: Kernel Security Fix

opensuse
Calendar Grey November 9, 2021
Dist Opensuse Esm H88
Significant Debian upgrade addresses 10 vulnerabilities in the Linux Kernel, featuring vital patches and improved security measures.
An update that solves 13 vulnerabilities and has 43 fixes is now available

Description

The SUSE Linux Enterprise 15 SP3 Azure kernel was updated to receive

various security and bugfixes.

The following security bugs were fixed:

- CVE-2021-3772: Fixed sctp vtag check in sctp_sf_ootb (bsc#1190351).

- CVE-2021-3655: Fixed a missing size validations on inbound SCTP packets,

which may have allowed the kernel to read uninitialized memory

(bsc#1188563).

- CVE-2021-43056: Fixed possible KVM host crash via malicious KVM guest on

Power8 (bnc#1192107).

- CVE-2021-3896: Fixed a array-index-out-bounds in detach_capi_ctr in

drivers/isdn/capi/kcapi.c (bsc#1191958).

- CVE-2021-3760: Fixed a use-after-free vulnerability with the

ndev->rf_conn_info object (bsc#1190067).

- CVE-2021-42739: The firewire subsystem had a buffer overflow related to

drivers/media/firewire/firedtv-avc.c and

drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandled

bounds checking (bsc#1184673).

- CVE-2021-3542: Fixed heap buffer...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2021-3641=1

Package List

- openSUSE Leap 15.3 (x86_64):

cluster-md-kmp-azure-5.3.18-38.28.2

cluster-md-kmp-azure-debuginfo-5.3.18-38.28.2

dlm-kmp-azure-5.3.18-38.28.2

dlm-kmp-azure-debuginfo-5.3.18-38.28.2

gfs2-kmp-azure-5.3.18-38.28.2

gfs2-kmp-azure-debuginfo-5.3.18-38.28.2

kernel-azure-5.3.18-38.28.2

kernel-azure-debuginfo-5.3.18-38.28.2

kernel-azure-debugsource-5.3.18-38.28.2

kernel-azure-devel-5.3.18-38.28.2

kernel-azure-devel-debuginfo-5.3.18-38.28.2

kernel-azure-extra-5.3.18-38.28.2

kernel-azure-extra-debuginfo-5.3.18-38.28.2

kernel-azure-livepatch-devel-5.3.18-38.28.2

kernel-azure-optional-5.3.18-38.28.2

kernel-azure-optional-debuginfo-5.3.18-38.28.2

kernel-syms-azure-5.3.18-38.28.1

kselftests-kmp-azure-5.3.18-38.28.2

kselftests-kmp-azure-debuginfo-5.3.18-38.28.2

ocfs2-kmp-azure-5.3.18-38.28.2

ocfs2-kmp-azure-debuginfo-5.3.18-38.28.2

reiserfs-kmp-azure-5.3.18-38.28.2

reiserfs-kmp-azure-debuginfo-5.3.18-38.28.2

- openSUSE Leap 15.3 (noarch):

kernel-devel-azure-5.3.18-38.28.2

kernel-source-azure-5.3.18-38.28.2

References

https://www.suse.com/security/cve/CVE-2021-33033.html

https://www.suse.com/security/cve/CVE-2021-34866.html

https://www.suse.com/security/cve/CVE-2021-3542.html

https://www.suse.com/security/cve/CVE-2021-3655.html

https://www.suse.com/security/cve/CVE-2021-3715.html

https://www.suse.com/security/cve/CVE-2021-3760.html

https://www.suse.com/security/cve/CVE-2021-3772.html

https://www.suse.com/security/cve/CVE-2021-3896.html

https://www.suse.com/security/cve/CVE-2021-41864.html

https://www.suse.com/security/cve/CVE-2021-42008.html

https://www.suse.com/security/cve/CVE-2021-42252.html

https://www.suse.com/security/cve/CVE-2021-42739.html

https://www.suse.com/security/cve/CVE-2021-43056.html

https://bugzilla.suse.com/1065729

https://bugzilla.suse.com/1085030

https://bugzilla.suse.com/1152472

https://bugzilla.suse.com/1152489

https://bugzilla.suse.com/1156395

https://bugzilla.suse.com/1172073

https://bugzilla.suse.com/1173604

https://bugzilla.suse.com/1176447

https://bugzilla.suse.com/1176774

https://bugzilla.sus...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:3641-1
Rating: important
Affected Products: openSUSE Leap 15.3 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here