Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

SUSE: 2020:0559-1 Important Update: Kernel Security Issues Resolved

suse
Calendar Grey March 2, 2020
Dist Suse Esm H88
A crucial update for SUSE addressing 23 issues in the Linux kernel is now available for users.
An update that solves 23 vulnerabilities and has 136 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP4 Azure kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-2732: Fixed an issue affecting Intel CPUs where an L2 guest may trick the L0 hypervisor into accessing sensitive L1 resources (bsc#1163971). - CVE-2020-8992: An issue was discovered in ext4_protect_reserved_inode in fs/ext4/block_validity.c that allowed attackers to cause a soft lockup via a crafted journal size (bnc#1164069). - CVE-2020-8648: There was a use-after-free vulnerability in the n_tty_receive_buf_common function in drivers/tty/n_tty.c (bnc#1162928). - CVE-2020-8428: There was a use-after-free bug in fs/namei.c, which allowed local users to cause a denial of service or possibly obtain sensitive information from kernel memory (bnc#1162109).

References

#1046303 #1050244 #1051510 #1051858 #1061840

#1065600 #1065729 #1071995 #1085030 #1086301

#1086313 #1086314 #1088810 #1104427 #1105392

#1111666 #1112178 #1112504 #1114279 #1118338

#1123328 #1127371 #1133021 #1133147 #1134973

#1140025 #1143959 #1144333 #1151910 #1151927

#1153917 #1154243 #1155331 #1155334 #1156259

#1156286 #1156462 #1157155 #1157157 #1157303

#1157424 #1157692 #1157853 #1157966 #1158013

#1158021 #1158026 #1158533 #1158819 #1159028

#1159271 #1159297 #1159394 #1159483 #1159484

#1159569 #1159588 #1159841 #1159908 #1159909

#1159910 #1159911 #1159955 #1160195 #1160210

#1160211 #1160218 #1160433 #1160442 #1160476

#1160560 #1160755 #1160756 #1160784 #1160787

#1160802 #116...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:0559-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here