Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges
The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various
security and bugfixes.
The following security bugs were fixed:
- CVE-2022-0435: Fixed remote stack overflow in net/tipc module that
validate domain record count on input (bsc#1195254).
- CVE-2022-0330: Fixed flush TLBs before releasing backing store
(bsc#1194880).
- CVE-2022-0286: Fixed null pointer dereference in bond_ipsec_add_sa()
that may have lead to local denial of service (bnc#1195371).
- CVE-2022-22942: Fixed stale file descriptors on failed usercopy
(bsc#1195065).
- CVE-2021-45095: Fixed refcount leak in pep_sock_accept in
net/phonet/pep.c (bnc#1193867).
- CVE-2021-44733: Fixed a use-after-free exists in drivers/tee/tee_shm.c
in the TEE subsystem, that could have occured because of a race
condition in tee_shm_get_from_id during an attempt to free a shared
memory object (bnc#1193767).
- CVE-2021-39685: Fixed USB gadget buffer...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 15.4:
zypper in -t patch openSUSE-SLE-15.4-2022-370=1
- openSUSE Leap 15.3:
zypper in -t patch openSUSE-SLE-15.3-2022-370=1
- openSUSE Leap 15.4 (aarch64 x86_64):
cluster-md-kmp-preempt-5.3.18-150300.59.49.1
cluster-md-kmp-preempt-debuginfo-5.3.18-150300.59.49.1
dlm-kmp-preempt-5.3.18-150300.59.49.1
dlm-kmp-preempt-debuginfo-5.3.18-150300.59.49.1
gfs2-kmp-preempt-5.3.18-150300.59.49.1
gfs2-kmp-preempt-debuginfo-5.3.18-150300.59.49.1
kernel-preempt-5.3.18-150300.59.49.1
kernel-preempt-debuginfo-5.3.18-150300.59.49.1
kernel-preempt-debugsource-5.3.18-150300.59.49.1
kernel-preempt-devel-5.3.18-150300.59.49.1
kernel-preempt-devel-debuginfo-5.3.18-150300.59.49.1
kernel-preempt-extra-5.3.18-150300.59.49.1
kernel-preempt-extra-debuginfo-5.3.18-150300.59.49.1
kernel-preempt-livepatch-devel-5.3.18-150300.59.49.1
kernel-preempt-optional-5.3.18-150300.59.49.1
kernel-preempt-optional-debuginfo-5.3.18-150300.59.49.1
kselftests-kmp-preempt-5.3.18-150300.59.49.1
kselftests-kmp-preempt-debuginfo-5.3.18-150300.59.49.1
ocfs2-kmp-preempt-5.3.18-150300.59.49.1
ocfs2-kmp-preempt-debuginfo-5.3.18-150300.59.49.1
reiserfs-kmp-preempt-5.3.18-150300.59....
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2020-28097.html
https://www.suse.com/security/cve/CVE-2021-22600.html
https://www.suse.com/security/cve/CVE-2021-39648.html
https://www.suse.com/security/cve/CVE-2021-39657.html
https://www.suse.com/security/cve/CVE-2021-39685.html
https://www.suse.com/security/cve/CVE-2021-44733.html
https://www.suse.com/security/cve/CVE-2021-45095.html
https://www.suse.com/security/cve/CVE-2022-0286.html
https://www.suse.com/security/cve/CVE-2022-0330.html
https://www.suse.com/security/cve/CVE-2022-0435.html
https://www.suse.com/security/cve/CVE-2022-22942.html
https://bugzilla.suse.com/1154353
https://bugzilla.suse.com/1154488
https://bugzilla.suse.com/1156395
https://bugzilla.suse.com/1160634
https://bugzilla.suse.com/1176447
https://bugzilla.suse.com/1177599
https://bugzilla.suse.com/1183405
https://bugzilla.suse.com/1185377
https://bugzilla.suse.com/1187428
https://bugzilla.suse.com/1187723
https://bugzilla.suse.com/1188605
https://bugzilla.suse.com/1191881
https://bugzilla.suse.co...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.