Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

SUSE: 2020:1255-1 Important: Linux Kernel Denial Of Service Fix

suse
Calendar Grey May 12, 2020
Dist Suse Esm H88
Ubuntu's latest Security Patch addresses 47 vulnerabilities in the Linux Kernel, enhancing overall system protection.
An update that solves 53 vulnerabilities and has 32 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP2 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-11494: An issue was discovered in slc_bump in drivers/net/can/slcan.c, which allowed attackers to read uninitialized can_frame data, potentially containing sensitive information from kernel stack memory, if the configuration lacks CONFIG_INIT_STACK_ALL (bnc#1168424). - CVE-2020-10942: In get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls (bnc#1167629). - CVE-2020-8647: Fixed a use-after-free vulnerability in the vc_do_resize function in drivers/tty/vt/vt.c (bnc#1162929). - CVE-2020-8649: Fixed a use-after-free vulnerability in the

References

#1037216 #1075091 #1075994 #1087082 #1087813

#1091041 #1099279 #1120386 #1131107 #1133147

#1136449 #1137325 #1146519 #1146544 #1146612

#1149591 #1153811 #1154844 #1155311 #1155897

#1156060 #1157038 #1157042 #1157070 #1157143

#1157155 #1157157 #1157158 #1157303 #1157324

#1157333 #1157464 #1157804 #1157923 #1158021

#1158132 #1158381 #1158394 #1158398 #1158410

#1158413 #1158417 #1158427 #1158445 #1158819

#1158823 #1158824 #1158827 #1158834 #1158900

#1158903 #1158904 #1159199 #1159285 #1159297

#1159841 #1159908 #1159910 #1159911 #1159912

#1160195 #1162227 #1162298 #1162928 #1162929

#1162931 #1163971 #1164069 #1164078 #1164846

#1165111 #1165311 #1165873 #1165881 #1165984

#1165985 #116...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:1255-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here