The SUSE Linux Enterprise 12 SP4 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-8834: KVM on Power8 processors had a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entry plus in kvmppc_{save,restore}_tm, leading to a stack corruption. Because of this, an attacker with the ability to run code in kernel space of a guest VM can cause the host kernel to panic (bnc#1168276). - CVE-2020-11494: An issue was discovered in slc_bump in drivers/net/can/slcan.c, which allowed attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration lacks CONFIG_INIT_STACK_ALL (bnc#1168424). - CVE-2020-10942: In get_raw_socket in drivers/vhost/net.c lacks
#1044231 #1050549 #1051510 #1051858 #1056686
#1060463 #1065600 #1065729 #1083647 #1085030
#1104967 #1109911 #1114279 #1118338 #1120386
#1133021 #1136157 #1137325 #1144333 #1145051
#1145929 #1146539 #1148868 #1154385 #1157424
#1158552 #1158983 #1159037 #1159142 #1159198
#1159199 #1159285 #1160659 #1161951 #1162929
#1162931 #1163403 #1163508 #1163897 #1164078
#1164284 #1164507 #1164893 #1165019 #1165111
#1165182 #1165404 #1165488 #1165527 #1165741
#1165813 #1165873 #1165949 #1165984 #1165985
#1166003 #1166101 #1166102 #1166103 #1166104
#1166632 #1166730 #1166731 #1166732 #1166733
#1166734 #1166735 #1166780 #1166860 #1166861
#1166862 #1166864 #1166866 #1166867 #1166868
#1166870 #116...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.