Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

openSUSE Leap 15.3: 2021:3655-1 Important: Kernel Security Issues Fixed

opensuse
Calendar Grey November 11, 2021
Dist Opensuse Esm H88
An important openSUSE security patch addressing multiple kernel flaws is now available. A system reboot is required after the installation is completed.
An update that solves 13 vulnerabilities and has 43 fixes is now available

Description

The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various

security and bugfixes.

NOTE: This update was retracted due to a NFS regression.

The following security bugs were fixed:

- CVE-2021-3772: Fixed sctp vtag check in sctp_sf_ootb (bsc#1190351).

- CVE-2021-3655: Fixed a missing size validations on inbound SCTP packets,

which may have allowed the kernel to read uninitialized memory

(bsc#1188563).

- CVE-2021-43056: Fixed possible KVM host crash via malicious KVM guest on

Power8 (bnc#1192107).

- CVE-2021-3896: Fixed a array-index-out-bounds in detach_capi_ctr in

drivers/isdn/capi/kcapi.c (bsc#1191958).

- CVE-2021-3760: Fixed a use-after-free vulnerability with the

ndev->rf_conn_info object (bsc#1190067).

- CVE-2021-42739: The firewire subsystem had a buffer overflow related to

drivers/media/firewire/firedtv-avc.c and

drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandled

bounds checking...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2021-3655=1

Package List

- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):

cluster-md-kmp-default-5.3.18-59.30.1

cluster-md-kmp-default-debuginfo-5.3.18-59.30.1

dlm-kmp-default-5.3.18-59.30.1

dlm-kmp-default-debuginfo-5.3.18-59.30.1

gfs2-kmp-default-5.3.18-59.30.1

gfs2-kmp-default-debuginfo-5.3.18-59.30.1

kernel-default-5.3.18-59.30.1

kernel-default-base-5.3.18-59.30.1.18.17.1

kernel-default-base-rebuild-5.3.18-59.30.1.18.17.1

kernel-default-debuginfo-5.3.18-59.30.1

kernel-default-debugsource-5.3.18-59.30.1

kernel-default-devel-5.3.18-59.30.1

kernel-default-devel-debuginfo-5.3.18-59.30.1

kernel-default-extra-5.3.18-59.30.1

kernel-default-extra-debuginfo-5.3.18-59.30.1

kernel-default-livepatch-5.3.18-59.30.1

kernel-default-livepatch-devel-5.3.18-59.30.1

kernel-default-optional-5.3.18-59.30.1

kernel-default-optional-debuginfo-5.3.18-59.30.1

kernel-obs-build-5.3.18-59.30.1

kernel-obs-build-debugsource-5.3.18-59.30.1

kernel-obs-qa-5.3.18-59.30.1

kernel-syms-5.3.18-59.30.1

kselftests-kmp-default-5.3.18-59.30.1

kselftests-kmp-default-deb...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2021-33033.html

https://www.suse.com/security/cve/CVE-2021-34866.html

https://www.suse.com/security/cve/CVE-2021-3542.html

https://www.suse.com/security/cve/CVE-2021-3655.html

https://www.suse.com/security/cve/CVE-2021-3715.html

https://www.suse.com/security/cve/CVE-2021-3760.html

https://www.suse.com/security/cve/CVE-2021-3772.html

https://www.suse.com/security/cve/CVE-2021-3896.html

https://www.suse.com/security/cve/CVE-2021-41864.html

https://www.suse.com/security/cve/CVE-2021-42008.html

https://www.suse.com/security/cve/CVE-2021-42252.html

https://www.suse.com/security/cve/CVE-2021-42739.html

https://www.suse.com/security/cve/CVE-2021-43056.html

https://bugzilla.suse.com/1065729

https://bugzilla.suse.com/1085030

https://bugzilla.suse.com/1152472

https://bugzilla.suse.com/1152489

https://bugzilla.suse.com/1156395

https://bugzilla.suse.com/1172073

https://bugzilla.suse.com/1173604

https://bugzilla.suse.com/1176447

https://bugzilla.suse.com/1176774

https://bugzilla.sus...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:3655-1
Rating: important
Affected Products: openSUSE Leap 15.3 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here