Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 544
Alerts This Week
Warning Icon 1 544

openSUSE Leap 15.3: 2021:3806-1 Important Security Fixes

opensuse
Calendar Grey November 25, 2021
Scroller Opensuse
Important release for openSUSE aimed at resolving various vulnerabilities in the Linux Kernel, while enhancing overall system reliability.
An update that solves 6 vulnerabilities, contains one feature and has 35 fixes is now available

Description

The SUSE Linux Enterprise 15 SP3 kernel for Azure was updated to receive

various security and bugfixes.

The following security bugs were fixed:

- Unprivileged BPF has been disabled by default to reduce attack surface

as too many security issues have happened in the past (jsc#SLE-22573)

You can reenable via systemctl setting

/proc/sys/kernel/unprivileged_bpf_disabled to 0.

(kernel.unprivileged_bpf_disabled = 0)

- CVE-2021-0941: In bpf_skb_change_head of filter.c, there is a possible

out of bounds read due to a use after free. This could lead to local

escalation of privilege with System execution privileges needed. User

interaction is not needed for exploitation (bnc#1192045).

- CVE-2021-31916: An out-of-bounds (OOB) memory write flaw was found in

list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module

in the Linux kernel A bound check failure allowed an attacker with

special user (CAP_SYS_ADMIN)...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2021-3806=1

Package List

- openSUSE Leap 15.3 (x86_64):

cluster-md-kmp-azure-5.3.18-38.31.1

cluster-md-kmp-azure-debuginfo-5.3.18-38.31.1

dlm-kmp-azure-5.3.18-38.31.1

dlm-kmp-azure-debuginfo-5.3.18-38.31.1

gfs2-kmp-azure-5.3.18-38.31.1

gfs2-kmp-azure-debuginfo-5.3.18-38.31.1

kernel-azure-5.3.18-38.31.1

kernel-azure-debuginfo-5.3.18-38.31.1

kernel-azure-debugsource-5.3.18-38.31.1

kernel-azure-devel-5.3.18-38.31.1

kernel-azure-devel-debuginfo-5.3.18-38.31.1

kernel-azure-extra-5.3.18-38.31.1

kernel-azure-extra-debuginfo-5.3.18-38.31.1

kernel-azure-livepatch-devel-5.3.18-38.31.1

kernel-azure-optional-5.3.18-38.31.1

kernel-azure-optional-debuginfo-5.3.18-38.31.1

kernel-syms-azure-5.3.18-38.31.1

kselftests-kmp-azure-5.3.18-38.31.1

kselftests-kmp-azure-debuginfo-5.3.18-38.31.1

ocfs2-kmp-azure-5.3.18-38.31.1

ocfs2-kmp-azure-debuginfo-5.3.18-38.31.1

reiserfs-kmp-azure-5.3.18-38.31.1

reiserfs-kmp-azure-debuginfo-5.3.18-38.31.1

- openSUSE Leap 15.3 (noarch):

kernel-devel-azure-5.3.18-38.31.1

kernel-source-azure-5.3.18-38.31.1

References

https://www.suse.com/security/cve/CVE-2021-0941.html

https://www.suse.com/security/cve/CVE-2021-20322.html

https://www.suse.com/security/cve/CVE-2021-31916.html

https://www.suse.com/security/cve/CVE-2021-34981.html

https://www.suse.com/security/cve/CVE-2021-37159.html

https://www.suse.com/security/cve/CVE-2021-43389.html

https://bugzilla.suse.com/1094840

https://bugzilla.suse.com/1133021

https://bugzilla.suse.com/1152489

https://bugzilla.suse.com/1154353

https://bugzilla.suse.com/1157177

https://bugzilla.suse.com/1167773

https://bugzilla.suse.com/1169263

https://bugzilla.suse.com/1170269

https://bugzilla.suse.com/1176940

https://bugzilla.suse.com/1180749

https://bugzilla.suse.com/1184924

https://bugzilla.suse.com/1188601

https://bugzilla.suse.com/1190523

https://bugzilla.suse.com/1190795

https://bugzilla.suse.com/1191628

https://bugzilla.suse.com/1191790

https://bugzilla.suse.com/1191851

https://bugzilla.suse.com/1191958

https://bugzilla.suse.com/1191961

https://bugzilla.suse.com/1191980

https://bugzilla.suse.c...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2021:3806-1
Rating: important
Affected Products: openSUSE Leap 15.3 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.