Alerts This Week
Warning Icon 1 916
Alerts This Week
Warning Icon 1 916

SUSE: 2020:0183-1 Important: Kernel Live Patch Buffer Overflow Fix

suse
Calendar Grey January 22, 2020
Dist Suse Esm H88
SUSE has released a security patch addressing multiple kernel vulnerabilities, such as severe buffer overflows and denial of service threats.
An update that solves 5 vulnerabilities and has three fixes is now available

Summary

This update for the Linux Kernel 4.12.14-120 fixes several issues. The following security issues were fixed: - CVE-2019-14896: A heap-based buffer overflow vulnerability was found in the Marvell WiFi chip driver. A remote attacker could cause a denial of service (system crash) or, possibly execute arbitrary code, when the lbs_ibss_join_existing function is called after a STA connects to an AP (bsc#1157157). - CVE-2019-14897: A stack-based buffer overflow was found in the Marvell WiFi chip driver. An attacker was able to cause a denial of service (system crash) or, possibly execute arbitrary code, when a STA works in IBSS mode (allows connecting stations together without the use of an AP) and connects to another STA (bsc#1157155). - CVE-2019-10220: The CIFS implementation was vulnerable to a relative

References

#1103203 #1149841 #1151021 #1153108 #1153161

#1157770 #1160467 #1160468

Cross- CVE-2019-10220 CVE-2019-14835 CVE-2019-14896

CVE-2019-14897 CVE-2019-17133

Affected Products:

SUSE Linux Enterprise Live Patching 12-SP5

https://www.suse.com/security/cve/CVE-2019-10220.html

https://www.suse.com/security/cve/CVE-2019-14835.html

https://www.suse.com/security/cve/CVE-2019-14896.html

https://www.suse.com/security/cve/CVE-2019-14897.html

https://www.suse.com/security/cve/CVE-2019-17133.html

https://bugzilla.suse.com/1103203

https://bugzilla.suse.com/1149841

https://bugzilla.suse.com/1151021

https://bugzilla.suse.com/1153108

https://bugzilla.suse.com/1153161

https://bugzilla.suse.com/1157770

https://bugzilla.suse.com/1160467

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:0183-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here