The SUSE Linux Enterprise 15 SP2 Azure kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-10781: Fixed a denial of service issue in the ZRAM implementation (bnc#1173074). - CVE-2020-0305: In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation (bnc#1174462). - CVE-2020-10135: Legacy pairing and secure-connections pairing authentication in bluetooth may have allowed an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth
#1065729 #1152472 #1152489 #1153274 #1154353
#1154488 #1155518 #1155798 #1165933 #1167773
#1168959 #1169771 #1171857 #1171988 #1172201
#1173074 #1173849 #1173941 #1174072 #1174116
#1174126 #1174127 #1174128 #1174129 #1174185
#1174205 #1174247 #1174263 #1174264 #1174331
#1174332 #1174333 #1174356 #1174362 #1174396
#1174398 #1174407 #1174409 #1174411 #1174438
#1174462 #1174513 #1174527 #1174627 #1174645
Cross- CVE-2020-0305 CVE-2020-10135 CVE-2020-10781
CVE-2020-14331
Affected Products:
SUSE Linux Enterprise Module for Public Cloud 15-SP2
https://www.suse.com/security/cve/CVE-2020-0305.html
https://www.suse.com/security/cve/CVE-2020-10135.html
https://www.suse.com/security/cve/CVE-2020-10781.html
https://www.suse.com/security/cve/CVE-2020-14331.html
Get the latest Linux and open source security news straight to your inbox.