Alerts This Week
Warning Icon 1 562
Alerts This Week
Warning Icon 1 562

openSUSE Leap 15.3 and 15.4: 2022:0366-1 Critical Kernel Fixes

opensuse
Calendar Grey February 10, 2022
Dist Opensuse Esm H88
Important security patch released for the openSUSE Linux kernel rectifying 27 security flaws, with various solutions provided.
An update that solves 27 vulnerabilities and has 23 fixes is now available

Description

The SUSE Linux Enterprise 15 SP1 LTSS kernel was updated to receive

various security and bugfixes.

The following security bugs were fixed:

- CVE-2022-0435: Fixed remote stack overflow in net/tipc module that

validate domain record count on input (bsc#1195254).

- CVE-2022-0330: Fixed flush TLBs before releasing backing store

(bsc#1194880).

- CVE-2021-45486: Fixed an information leak because the hash table is very

small in net/ipv4/route.c (bnc#1194087).

- CVE-2021-45095: Fixed refcount leak in pep_sock_accept in

net/phonet/pep.c (bnc#1193867).

- CVE-2021-44733: Fixed a use-after-free exists in drivers/tee/tee_shm.c

in the TEE subsystem, that could have occured because of a race

condition in tee_shm_get_from_id during an attempt to free a shared

memory object (bnc#1193767).

- CVE-2021-43976: Fixed a flaw that could allow an attacker (who can

connect a crafted USB device) to cause a denial of service. (bnc#1192847)

...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.4:

zypper in -t patch openSUSE-SLE-15.4-2022-366=1

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2022-366=1

Package List

- openSUSE Leap 15.4 (aarch64 ppc64le s390x x86_64):

kernel-default-base-debuginfo-4.12.14-197.105.1

kernel-vanilla-4.12.14-197.105.1

kernel-vanilla-base-4.12.14-197.105.1

kernel-vanilla-base-debuginfo-4.12.14-197.105.1

kernel-vanilla-debuginfo-4.12.14-197.105.1

kernel-vanilla-debugsource-4.12.14-197.105.1

kernel-vanilla-devel-4.12.14-197.105.1

kernel-vanilla-devel-debuginfo-4.12.14-197.105.1

kernel-vanilla-livepatch-devel-4.12.14-197.105.1

- openSUSE Leap 15.4 (ppc64le x86_64):

kernel-debug-base-4.12.14-197.105.1

kernel-debug-base-debuginfo-4.12.14-197.105.1

- openSUSE Leap 15.4 (x86_64):

kernel-kvmsmall-base-4.12.14-197.105.1

kernel-kvmsmall-base-debuginfo-4.12.14-197.105.1

- openSUSE Leap 15.4 (s390x):

kernel-default-man-4.12.14-197.105.1

kernel-zfcpdump-man-4.12.14-197.105.1

- openSUSE Leap 15.3 (aarch64 ppc64le s390x x86_64):

kernel-default-base-debuginfo-4.12.14-197.105.1

kernel-vanilla-4.12.14-197.105.1

kernel-vanilla-base-4.12.14-197.105.1

kernel-vanilla-base-debuginfo-4.12.14-197.105.1

kernel-vanilla...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2018-25020.html

https://www.suse.com/security/cve/CVE-2019-15126.html

https://www.suse.com/security/cve/CVE-2020-27820.html

https://www.suse.com/security/cve/CVE-2021-0920.html

https://www.suse.com/security/cve/CVE-2021-0935.html

https://www.suse.com/security/cve/CVE-2021-28711.html

https://www.suse.com/security/cve/CVE-2021-28712.html

https://www.suse.com/security/cve/CVE-2021-28713.html

https://www.suse.com/security/cve/CVE-2021-28714.html

https://www.suse.com/security/cve/CVE-2021-28715.html

https://www.suse.com/security/cve/CVE-2021-33098.html

https://www.suse.com/security/cve/CVE-2021-3564.html

https://www.suse.com/security/cve/CVE-2021-39648.html

https://www.suse.com/security/cve/CVE-2021-39657.html

https://www.suse.com/security/cve/CVE-2021-4002.html

https://www.suse.com/security/cve/CVE-2021-4083.html

https://www.suse.com/security/cve/CVE-2021-4135.html

https://www.suse.com/security/cve/CVE-2021-4149.html

https://www.suse.com/security/cve/CVE-2021-4197.html

h...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2022:0366-1
Rating: critical
Affected Products: openSUSE Leap 15.3 openSUSE Leap 15.4 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here