Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 514
Alerts This Week
Warning Icon 1 514

openSUSE Leap 15.3: 2022:0755-1 Critical: Kernel Update Mitigation

opensuse
Calendar Grey March 8, 2022
Scroller Opensuse
A significant update has been issued for the Linux Kernel in openSUSE, tackling critical vulnerabilities and enhancing system reliability. For details and guidance, check the documentation
An update that solves 6 vulnerabilities, contains three features and has 56 fixes is now available

Description

The SUSE Linux Enterprise 15 SP3 Azure kernel was updated to receive

various security and bugfixes.

Transient execution side-channel attacks attacking the Branch History

Buffer (BHB), named "Branch Target Injection" and "Intra-Mode Branch

History Injection" are now mitigated.

The following security bugs were fixed:

- CVE-2022-0847: Fixed a vulnerability were a local attackers could

overwrite data in arbitrary (read-only) files (bsc#1196584).

- CVE-2022-0001: Fixed Branch History Injection vulnerability

(bsc#1191580).

- CVE-2022-0002: Fixed Intra-Mode Branch Target Injection vulnerability

(bsc#1191580).

- CVE-2022-25375: The RNDIS USB gadget lacks validation of the size of the

RNDIS_MSG_SET command. Attackers can obtain sensitive information from

kernel memory (bsc#1196235).

- CVE-2022-0516: Fixed missing check in ioctl related to KVM in s390

allows kernel memory read/write (bsc#1195516).

- CVE-2022-0492: Fixed a...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.3:

zypper in -t patch openSUSE-SLE-15.3-2022-755=1

Package List

- openSUSE Leap 15.3 (x86_64):

cluster-md-kmp-azure-5.3.18-150300.38.47.1

cluster-md-kmp-azure-debuginfo-5.3.18-150300.38.47.1

dlm-kmp-azure-5.3.18-150300.38.47.1

dlm-kmp-azure-debuginfo-5.3.18-150300.38.47.1

gfs2-kmp-azure-5.3.18-150300.38.47.1

gfs2-kmp-azure-debuginfo-5.3.18-150300.38.47.1

kernel-azure-5.3.18-150300.38.47.1

kernel-azure-debuginfo-5.3.18-150300.38.47.1

kernel-azure-debugsource-5.3.18-150300.38.47.1

kernel-azure-devel-5.3.18-150300.38.47.1

kernel-azure-devel-debuginfo-5.3.18-150300.38.47.1

kernel-azure-extra-5.3.18-150300.38.47.1

kernel-azure-extra-debuginfo-5.3.18-150300.38.47.1

kernel-azure-livepatch-devel-5.3.18-150300.38.47.1

kernel-azure-optional-5.3.18-150300.38.47.1

kernel-azure-optional-debuginfo-5.3.18-150300.38.47.1

kernel-syms-azure-5.3.18-150300.38.47.1

kselftests-kmp-azure-5.3.18-150300.38.47.1

kselftests-kmp-azure-debuginfo-5.3.18-150300.38.47.1

ocfs2-kmp-azure-5.3.18-150300.38.47.1

ocfs2-kmp-azure-debuginfo-5.3.18-150300.38.47.1

reiserfs-kmp-azure-5.3.18-150300.38.47.1

reiserf...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2022-0001.html

https://www.suse.com/security/cve/CVE-2022-0002.html

https://www.suse.com/security/cve/CVE-2022-0492.html

https://www.suse.com/security/cve/CVE-2022-0516.html

https://www.suse.com/security/cve/CVE-2022-0847.html

https://www.suse.com/security/cve/CVE-2022-25375.html

https://bugzilla.suse.com/1089644

https://bugzilla.suse.com/1154353

https://bugzilla.suse.com/1156395

https://bugzilla.suse.com/1157038

https://bugzilla.suse.com/1157923

https://bugzilla.suse.com/1176447

https://bugzilla.suse.com/1176940

https://bugzilla.suse.com/1178134

https://bugzilla.suse.com/1181147

https://bugzilla.suse.com/1181588

https://bugzilla.suse.com/1183872

https://bugzilla.suse.com/1187716

https://bugzilla.suse.com/1188404

https://bugzilla.suse.com/1189126

https://bugzilla.suse.com/1190812

https://bugzilla.suse.com/1190972

https://bugzilla.suse.com/1191580

https://bugzilla.suse.com/1191655

https://bugzilla.suse.com/1191741

https://bugzilla.suse.com/1192210

https://bugzilla.suse.com/1...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2022:0755-1
Rating: important
Affected Products: openSUSE Leap 15.3 ble.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.