Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE: 2020:1699-1 Important: Kernel Security Fixes and Updates

suse
Calendar Grey June 22, 2020
Dist Suse Esm H88
SUSE has released a Security Update for the Linux Kernel, resolving major vulnerabilities that enhance defenses against local attacks.
An update that solves 5 vulnerabilities and has 22 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP5 Azure kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-10768: The prctl() function could be used to enable indirect branch speculation even after it has been disabled. (bnc#1172783) - CVE-2020-10766: A bug in the logic handling could allow an attacker with a local account to disable SSBD protection. (bnc#1172781) - CVE-2020-10767: A IBPB would be disabled when STIBP was not available or when Enhanced Indirect Branch Restricted Speculation (IBRS) was available. This is unexpected behaviour could leave the system open to a spectre v2 style attack (bnc#1172782) - CVE-2020-13974: drivers/tty/vt/keyboard.c had an integer overflow if k_ascii was called several times in a row (bnc#1172775)

References

#1051510 #1065729 #1071995 #1085030 #1111666

#1113956 #1114279 #1144333 #1148868 #1158983

#1161016 #1162063 #1166985 #1168081 #1169194

#1170592 #1171904 #1172458 #1172472 #1172537

#1172538 #1172759 #1172775 #1172781 #1172782

#1172783 #1172884

Cross- CVE-2019-20810 CVE-2020-10766 CVE-2020-10767

CVE-2020-10768 CVE-2020-13974

Affected Products:

SUSE Linux Enterprise Server 12-SP5

https://www.suse.com/security/cve/CVE-2019-20810.html

https://www.suse.com/security/cve/CVE-2020-10766.html

https://www.suse.com/security/cve/CVE-2020-10767.html

https://www.suse.com/security/cve/CVE-2020-10768.html

https://www.suse.com/security/cve/CVE-2020-13974.html

https://bugzilla.suse.com/1051510

https://bugzilla.suse.com/1065729

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:1699-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here