- CVE-2021-44141: Information leak via symlinks of existance of files or
directories outside of the exported share; (bso#14911); (bsc#1193690);
- CVE-2021-44142: Out-of-bounds heap read/write vulnerability in VFS
module vfs_fruit allows code execution; (bso#14914); (bsc#1194859);
- CVE-2022-0336: Samba AD users with permission to write to an account can
impersonate arbitrary services; (bso#14950); (bsc#1195048);
samba was updated to 4.15.4 (jsc#SLE-23329);
* Duplicate SMB file_ids leading to Windows client cache poisoning;
(bso#14928);
* Failed to parse NTLMv2_RESPONSE length 95 - Buffer Size Error -
NT_STATUS_BUFFER_TOO_SMALL; (bso#14932);
* kill_tcp_connections does not work; (bso#14934);
* Can't connect to Windows shares not requiring authentication using
KDE/Gnome; (bso#14935);
* smbclient -L doesn't set "client max protocol" to NT1 before calling the
"Reconnecting with SMB1 for workgroup listing" path;...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.3:
zypper in -t patch openSUSE-SLE-15.3-2022-283=1
- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):
apache2-mod_apparmor-2.13.6-150300.3.11.2
apache2-mod_apparmor-debuginfo-2.13.6-150300.3.11.2
apparmor-debugsource-2.13.6-150300.3.11.2
apparmor-parser-2.13.6-150300.3.11.2
apparmor-parser-debuginfo-2.13.6-150300.3.11.2
ctdb-4.15.4+git.324.8332acf1a63-150300.3.25.3
ctdb-debuginfo-4.15.4+git.324.8332acf1a63-150300.3.25.3
ctdb-pcp-pmda-4.15.4+git.324.8332acf1a63-150300.3.25.3
ctdb-pcp-pmda-debuginfo-4.15.4+git.324.8332acf1a63-150300.3.25.3
krb5-1.19.2-150300.8.3.2
krb5-client-1.19.2-150300.8.3.2
krb5-client-debuginfo-1.19.2-150300.8.3.2
krb5-debuginfo-1.19.2-150300.8.3.2
krb5-debugsource-1.19.2-150300.8.3.2
krb5-devel-1.19.2-150300.8.3.2
krb5-mini-1.19.2-150300.8.3.2
krb5-mini-debuginfo-1.19.2-150300.8.3.2
krb5-mini-debugsource-1.19.2-150300.8.3.2
krb5-mini-devel-1.19.2-150300.8.3.2
krb5-plugin-kdb-ldap-1.19.2-150300.8.3.2
krb5-plugin-kdb-ldap-debuginfo-1.19.2-150300.8.3.2
krb5-plugin-preauth-otp-1.19.2-150300.8.3.2
krb5-plugin-preauth-otp-debuginfo-1.19.2-1...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2020-27840.html
https://www.suse.com/security/cve/CVE-2021-20277.html
https://www.suse.com/security/cve/CVE-2021-20316.html
https://www.suse.com/security/cve/CVE-2021-36222.html
https://www.suse.com/security/cve/CVE-2021-43566.html
https://www.suse.com/security/cve/CVE-2021-44141.html
https://www.suse.com/security/cve/CVE-2021-44142.html
https://www.suse.com/security/cve/CVE-2022-0336.html
https://bugzilla.suse.com/1139519
https://bugzilla.suse.com/1183572
https://bugzilla.suse.com/1183574
https://bugzilla.suse.com/1188571
https://bugzilla.suse.com/1191227
https://bugzilla.suse.com/1191532
https://bugzilla.suse.com/1192684
https://bugzilla.suse.com/1193690
https://bugzilla.suse.com/1194859
https://bugzilla.suse.com/1195048
Get the latest Linux and open source security news straight to your inbox.