The SUSE Linux Enterprise 12 SP5 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-8834: KVM on Power8 processors had a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entry plus in kvmppc_{save,restore}_tm, leading to a stack corruption. Because of this, an attacker with the ability to run code in kernel space of a guest VM can cause the host kernel to panic (bnc#1168276). - CVE-2020-11494: An issue was discovered in slc_bump in drivers/net/can/slcan.c, which allowed attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration lacks CONFIG_INIT_STACK_ALL (bnc#1168424). - CVE-2020-10942: In get_raw_socket in drivers/vhost/net.c lacks
#1044231 #1050549 #1051510 #1051858 #1056686
#1060463 #1065600 #1065729 #1083647 #1085030
#1088810 #1103990 #1103992 #1104353 #1104745
#1104967 #1109837 #1109911 #1111666 #1111974
#1112178 #1112374 #1112504 #1113956 #1114279
#1114685 #1118338 #1119680 #1120386 #1123328
#1127611 #1133021 #1134090 #1134395 #1136157
#1136333 #1137325 #1141895 #1142685 #1144162
#1144333 #1145051 #1145929 #1146539 #1148868
#1154385 #1156510 #1157424 #1158187 #1158552
#1158983 #1159037 #1159142 #1159198 #1159199
#1159285 #1160659 #1161561 #1161702 #1161951
#1162171 #1162929 #1162931 #1163403 #1163508
#1163762 #1163897 #1163971 #1164051 #1164078
#1164115 #1164284 #1164388 #1164471 #1164507
#1164598 #116...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.