The SUSE Linux Enterprise 12 SP4 azure kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-8834: KVM on Power8 processors had a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entry plus in kvmppc_{save,restore}_tm, leading to a stack corruption. Because of this, an attacker with the ability to run code in kernel space of a guest VM can cause the host kernel to panic (bnc#1168276). - CVE-2020-11494: An issue was discovered in slc_bump in drivers/net/can/slcan.c, which allowed attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration lacks CONFIG_INIT_STACK_ALL (bnc#1168424). - CVE-2020-10942: In get_raw_socket in drivers/vhost/net.c lacks
#1044231 #1050549 #1051510 #1051858 #1056686
#1060463 #1065600 #1065729 #1071995 #1083647
#1085030 #1104967 #1109911 #1111666 #1114279
#1118338 #1120386 #1133021 #1136157 #1137325
#1144333 #1145051 #1145929 #1146539 #1148868
#1154385 #1157424 #1158552 #1158983 #1159037
#1159142 #1159198 #1159199 #1159285 #1160659
#1161951 #1162929 #1162931 #1163403 #1163508
#1163897 #1164078 #1164284 #1164507 #1164893
#1165019 #1165111 #1165182 #1165404 #1165488
#1165527 #1165741 #1165813 #1165873 #1165949
#1165984 #1165985 #1166003 #1166101 #1166102
#1166103 #1166104 #1166632 #1166730 #1166731
#1166732 #1166733 #1166734 #1166735 #1166780
#1166860 #1166861 #1166862 #1166864 #1166866
#1166867 #116...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.