The SUSE Linux Enterprise 15 SP1 LTSS kernel was updated to receive
various security and bugfixes.
The following security bugs were fixed:
- Unprivileged BPF has been disabled by default to reduce attack surface
as too many security issues have happened in the past (jsc#SLE-22573)
You can reenable via systemctl setting
/proc/sys/kernel/unprivileged_bpf_disabled to 0.
(kernel.unprivileged_bpf_disabled = 0)
- CVE-2021-0941: In bpf_skb_change_head of filter.c, there is a possible
out of bounds read due to a use after free. This could lead to local
escalation of privilege with System execution privileges needed. User
interaction is not needed for exploitation (bnc#1192045).
- CVE-2021-31916: An out-of-bounds (OOB) memory write flaw was found in
list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module
in the Linux kernel A bound check failure allowed an attacker with
special user (CAP_SYS_ADMIN) privilege...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.3:
zypper in -t patch openSUSE-SLE-15.3-2021-3876=1
- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):
kernel-default-base-debuginfo-4.12.14-197.102.2
kernel-vanilla-4.12.14-197.102.2
kernel-vanilla-base-4.12.14-197.102.2
kernel-vanilla-base-debuginfo-4.12.14-197.102.2
kernel-vanilla-debuginfo-4.12.14-197.102.2
kernel-vanilla-debugsource-4.12.14-197.102.2
kernel-vanilla-devel-4.12.14-197.102.2
kernel-vanilla-devel-debuginfo-4.12.14-197.102.2
kernel-vanilla-livepatch-devel-4.12.14-197.102.2
- openSUSE Leap 15.3 (ppc64le x86_64):
kernel-debug-base-4.12.14-197.102.2
kernel-debug-base-debuginfo-4.12.14-197.102.2
- openSUSE Leap 15.3 (x86_64):
kernel-kvmsmall-base-4.12.14-197.102.2
kernel-kvmsmall-base-debuginfo-4.12.14-197.102.2
- openSUSE Leap 15.3 (s390x):
kernel-default-man-4.12.14-197.102.2
kernel-zfcpdump-man-4.12.14-197.102.2
https://www.suse.com/security/cve/CVE-2018-13405.html
https://www.suse.com/security/cve/CVE-2018-9517.html
https://www.suse.com/security/cve/CVE-2019-3874.html
https://www.suse.com/security/cve/CVE-2019-3900.html
https://www.suse.com/security/cve/CVE-2020-0429.html
https://www.suse.com/security/cve/CVE-2020-12770.html
https://www.suse.com/security/cve/CVE-2020-3702.html
https://www.suse.com/security/cve/CVE-2020-4788.html
https://www.suse.com/security/cve/CVE-2021-0941.html
https://www.suse.com/security/cve/CVE-2021-20322.html
https://www.suse.com/security/cve/CVE-2021-22543.html
https://www.suse.com/security/cve/CVE-2021-31916.html
https://www.suse.com/security/cve/CVE-2021-33033.html
https://www.suse.com/security/cve/CVE-2021-33909.html
https://www.suse.com/security/cve/CVE-2021-34556.html
https://www.suse.com/security/cve/CVE-2021-34981.html
https://www.suse.com/security/cve/CVE-2021-3542.html
https://www.suse.com/security/cve/CVE-2021-35477.html
https://www.suse.com/security/cve/CVE-2021-3640.html
ht...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.