Alerts This Week
Warning Icon 1 537
Alerts This Week
Warning Icon 1 537

openSUSE 15.3: 2022:0131-1 Important: Linux Kernel DoS Risks Fixed

opensuse
Calendar Grey January 19, 2022
Dist Opensuse Esm H88
Crucial security patch for openSUSE addresses multiple kernel vulnerabilities and improves overall system reliability. A restart is recommended.
An update that solves 13 vulnerabilities, contains one feature and has 61 fixes is now available

Description

The SUSE Linux Enterprise 15 SP3 kernel was updated

- Unprivileged BPF has been disabled by default to reduce attack surface

as too many security issues have happened in the past (jsc#SLE-22573)

You can reenable via systemctl setting

/proc/sys/kernel/unprivileged_bpf_disabled to 0.

(kernel.unprivileged_bpf_disabled = 0)

The following security bugs were fixed:

- CVE-2021-45485: Fixed an information leak because of certain use of a

hash table which use IPv6 source addresses. (bsc#1194094)

- CVE-2021-45486: Fixed an information leak because the hash table is very

small in net/ipv4/route.c. (bnc#1194087).

- CVE-2021-4001: Fixed a race condition when the EBPF map is frozen.

(bsc#1192990)

- CVE-2021-28715: Fixed an issue where a guest could force Linux netback

driver to hog large amounts of kernel memory by do not queueing

unlimited number of packages. (bsc#1193442)

- CVE-2021-28714: Fixed an issue where a guest...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2022-131=1

Package List

- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):

cluster-md-kmp-default-5.3.18-59.40.1

cluster-md-kmp-default-debuginfo-5.3.18-59.40.1

dlm-kmp-default-5.3.18-59.40.1

dlm-kmp-default-debuginfo-5.3.18-59.40.1

gfs2-kmp-default-5.3.18-59.40.1

gfs2-kmp-default-debuginfo-5.3.18-59.40.1

kernel-default-5.3.18-59.40.1

kernel-default-base-5.3.18-59.40.1.18.25.1

kernel-default-base-rebuild-5.3.18-59.40.1.18.25.1

kernel-default-debuginfo-5.3.18-59.40.1

kernel-default-debugsource-5.3.18-59.40.1

kernel-default-devel-5.3.18-59.40.1

kernel-default-devel-debuginfo-5.3.18-59.40.1

kernel-default-extra-5.3.18-59.40.1

kernel-default-extra-debuginfo-5.3.18-59.40.1

kernel-default-livepatch-5.3.18-59.40.1

kernel-default-livepatch-devel-5.3.18-59.40.1

kernel-default-optional-5.3.18-59.40.1

kernel-default-optional-debuginfo-5.3.18-59.40.1

kernel-obs-build-5.3.18-59.40.1

kernel-obs-build-debugsource-5.3.18-59.40.1

kernel-obs-qa-5.3.18-59.40.1

kernel-syms-5.3.18-59.40.1

kselftests-kmp-default-5.3.18-59.40.1

kselftests-kmp-default-deb...

Read the Full Advisory

References

- swiotlb: avoid double free (git-fixes).

- swiotlb: Fix the type of index (git-fixes).

- TCON Reconnect during STATUS_NETWORK_NAME_DELETED (bsc#1192606).

- tlb: mmu_gather: add tlb_flush_*_range APIs

- tracing: Add length protection to histogram string copies (git-fixes).

- tracing: Change STR_VAR_MAX_LEN (git-fixes).

- tracing: Check pid filtering when creating events (git-fixes).

- tracing: Fix pid filtering when triggers are attached (git-fixes).

- tracing: use %ps format string to print symbols (git-fixes).

- tracing/histogram: Do not copy the fixed-size char array field over the

field size (git-fixes).

- tty: hvc: replace BUG_ON() with negative return value (git-fixes).

- tty: serial: msm_serial: Deactivate RX DMA for polling support

(git-fixes).

- tty: tty_buffer: Fix the softlockup issue in flush_to_ldisc (git-fixes).

- usb-storage: Add compatibility quirk flags for iODD 2531/2541

(git-fixes).

- usb: chipidea: ci_hdrc_imx: fix potential error pointer dereference in

probe (git-fixes).

- usb:...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2022:0131-1
Rating: important
Affected Products: openSUSE Leap 15.3 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here