Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE: 2020:1596-1 Important: Kernel Denial Of Service Fixes

suse
Calendar Grey June 10, 2020
Dist Suse Esm H88
The recent update to the SUSE kernel addresses multiple security flaws impacting various applications.
An update that solves 7 vulnerabilities and has 11 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP3 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-0543: Fixed a side channel attack against special registers which could have resulted in leaking of read values to cores other than the one which called it. This attack is known as Special Register Buffer Data Sampling (SRBDS) or "CrossTalk" (bsc#1154824). - CVE-2020-12652: Fixed an issue which could have allowed local users to hold an incorrect lock during the ioctl operation and trigger a race condition (bsc#1171218). - CVE-2020-12653: Fixed an issue in the wifi driver which could have allowed local users to gain privileges or cause a denial of service (bsc#1171195). - CVE-2020-12654: Fixed an issue in he wifi driver which could have

References

#1154824 #1161951 #1164871 #1169025 #1169625

#1170383 #1170618 #1170620 #1171098 #1171195

#1171202 #1171218 #1171219 #1171689 #1171698

#1172032 #1172221 #1172317

Cross- CVE-2020-0543 CVE-2020-10757 CVE-2020-12114

CVE-2020-12652 CVE-2020-12653 CVE-2020-12654

CVE-2020-12656

Affected Products:

SUSE OpenStack Cloud Crowbar 8

SUSE OpenStack Cloud 8

SUSE Linux Enterprise Server for SAP 12-SP3

SUSE Linux Enterprise Server 12-SP3-LTSS

SUSE Linux Enterprise Server 12-SP3-BCL

SUSE Linux Enterprise High Availability 12-SP3

SUSE Enterprise Storage 5

HPE Helion Openstack 8

https://www.suse.com/security/cve/CVE-2020-0543.html

https://www.suse.com/security/cve/CVE-2020-10757.html

https://www.suse.com/security/cve/CVE-2020-12114.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:1596-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here