The SUSE Linux Enterprise 12 SP2 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-11494: An issue was discovered in slc_bump in drivers/net/can/slcan.c, which allowed attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration lacks CONFIG_INIT_STACK_ALL (bnc#1168424). - CVE-2020-10942: In get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls (bnc#1167629). - CVE-2020-8647: Fixed a use-after-free vulnerability in the vc_do_resize function in drivers/tty/vt/vt.c (bnc#1162929). - CVE-2020-8649: Fixed a use-after-free vulnerability in the
#1037216 #1075091 #1075994 #1087082 #1087813
#1091041 #1099279 #1120386 #1131107 #1133147
#1136449 #1137325 #1146519 #1146544 #1146612
#1149591 #1153811 #1154844 #1155311 #1155897
#1156060 #1157038 #1157042 #1157070 #1157143
#1157155 #1157157 #1157158 #1157303 #1157324
#1157333 #1157464 #1157804 #1157923 #1158021
#1158132 #1158381 #1158394 #1158398 #1158410
#1158413 #1158417 #1158427 #1158445 #1158819
#1158823 #1158824 #1158827 #1158834 #1158900
#1158903 #1158904 #1159199 #1159285 #1159297
#1159841 #1159908 #1159910 #1159911 #1159912
#1160195 #1162227 #1162298 #1162928 #1162929
#1162931 #1163971 #1164069 #1164078 #1164846
#1165111 #1165311 #1165873 #1165881 #1165984
#1165985 #116...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.