Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE: 2020:1146-1 Important: Linux Kernel Security Issue Resolved

suse
Calendar Grey April 29, 2020
Dist Suse Esm H88
Explore the latest SUSE security patch that addresses various kernel vulnerabilities, bolstering system integrity and safety for its users.
An update that solves 7 vulnerabilities and has 77 fixes is now available

Summary

The SUSE Linux Enterprise 15 SP1 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-8834: KVM on Power8 processors had a conflicting use of HSTATE_HOST_R1 to store r1 state in kvmppc_hv_entry plus in kvmppc_{save,restore}_tm, leading to a stack corruption. Because of this, an attacker with the ability to run code in kernel space of a guest VM can cause the host kernel to panic (bnc#1168276). - CVE-2020-11494: An issue was discovered in slc_bump in drivers/net/can/slcan.c, which allowed attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration lacks CONFIG_INIT_STACK_ALL (bnc#1168424). - CVE-2020-10942: In get_raw_socket in drivers/vhost/net.c lacks

References

#1051510 #1065600 #1065729 #1071995 #1083647

#1085030 #1109911 #1111666 #1113956 #1114279

#1118338 #1120386 #1137325 #1142685 #1145051

#1145929 #1148868 #1157424 #1158983 #1159037

#1159198 #1159199 #1161561 #1161951 #1162171

#1163403 #1163897 #1164284 #1164777 #1164780

#1164893 #1165019 #1165182 #1165185 #1165211

#1165823 #1165949 #1166780 #1166860 #1166861

#1166862 #1166864 #1166866 #1166867 #1166868

#1166870 #1166940 #1166982 #1167005 #1167216

#1167288 #1167290 #1167316 #1167421 #1167423

#1167627 #1167629 #1168075 #1168202 #1168273

#1168276 #1168295 #1168367 #1168424 #1168443

#1168486 #1168552 #1168760 #1168762 #1168763

#1168764 #1168765 #1168829 #1168854 #1168881

#1168884 #116...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:1146-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here