Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

openSUSE Leap 15.4: 2022:1234-5 Critical Kernel Security Update

opensuse
Calendar Grey November 16, 2021
Dist Opensuse Esm H88
Essential patch for openSUSE Leap 15.3 tackles 15 security flaws with crucial remedies provided.
An update that solves 15 vulnerabilities and has 56 fixes is now available

Description

The following security bugs were fixed:

- CVE-2021-3542: Fixed heap buffer overflow in firedtv driver

(bsc#1186063).

- CVE-2021-3655: Fixed a missing size validations on inbound SCTP packets,

which may have allowed the kernel to read uninitialized memory

(bsc#1188563).

- CVE-2021-3715: Fixed a use-after-free in route4_change() in

net/sched/cls_route.c (bsc#1190349).

- CVE-2021-3760: Fixed a use-after-free vulnerability with the

ndev->rf_conn_info object (bsc#1190067).

- CVE-2021-3772: Fixed sctp vtag check in sctp_sf_ootb (bsc#1190351).

- CVE-2021-3896: Fixed a array-index-out-bounds in detach_capi_ctr in

drivers/isdn/capi/kcapi.c (bsc#1191958).

- CVE-2021-33033: Fixed a use-after-free in cipso_v4_genopt in

net/ipv4/cipso_ipv4.c because the CIPSO and CALIPSO refcounting for the

DOI definitions is mishandled (bsc#1186109).

- CVE-2021-34866: Fixed eBPF Type Confusion Privilege Escalation

Vulnerability...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2021-3675=1

Package List

- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):

cluster-md-kmp-default-5.3.18-59.34.1

cluster-md-kmp-default-debuginfo-5.3.18-59.34.1

dlm-kmp-default-5.3.18-59.34.1

dlm-kmp-default-debuginfo-5.3.18-59.34.1

gfs2-kmp-default-5.3.18-59.34.1

gfs2-kmp-default-debuginfo-5.3.18-59.34.1

kernel-default-5.3.18-59.34.1

kernel-default-base-5.3.18-59.34.1.18.21.1

kernel-default-base-rebuild-5.3.18-59.34.1.18.21.1

kernel-default-debuginfo-5.3.18-59.34.1

kernel-default-debugsource-5.3.18-59.34.1

kernel-default-devel-5.3.18-59.34.1

kernel-default-devel-debuginfo-5.3.18-59.34.1

kernel-default-extra-5.3.18-59.34.1

kernel-default-extra-debuginfo-5.3.18-59.34.1

kernel-default-livepatch-5.3.18-59.34.1

kernel-default-livepatch-devel-5.3.18-59.34.1

kernel-default-optional-5.3.18-59.34.1

kernel-default-optional-debuginfo-5.3.18-59.34.1

kernel-obs-build-5.3.18-59.34.1

kernel-obs-build-debugsource-5.3.18-59.34.1

kernel-obs-qa-5.3.18-59.34.1

kernel-syms-5.3.18-59.34.1

kselftests-kmp-default-5.3.18-59.34.1

kselftests-kmp-default-deb...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2021-33033.html

https://www.suse.com/security/cve/CVE-2021-34866.html

https://www.suse.com/security/cve/CVE-2021-3542.html

https://www.suse.com/security/cve/CVE-2021-3655.html

https://www.suse.com/security/cve/CVE-2021-3715.html

https://www.suse.com/security/cve/CVE-2021-37159.html

https://www.suse.com/security/cve/CVE-2021-3760.html

https://www.suse.com/security/cve/CVE-2021-3772.html

https://www.suse.com/security/cve/CVE-2021-3896.html

https://www.suse.com/security/cve/CVE-2021-41864.html

https://www.suse.com/security/cve/CVE-2021-42008.html

https://www.suse.com/security/cve/CVE-2021-42252.html

https://www.suse.com/security/cve/CVE-2021-42739.html

https://www.suse.com/security/cve/CVE-2021-43056.html

https://www.suse.com/security/cve/CVE-2021-43389.html

https://bugzilla.suse.com/1065729

https://bugzilla.suse.com/1085030

https://bugzilla.suse.com/1089118

https://bugzilla.suse.com/1094840

https://bugzilla.suse.com/1133021

https://bugzilla.suse.com/1152472

https://bugzi...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:3675-1
Rating: important
Affected Products: openSUSE Leap 15.3 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here