The SUSE Linux Enterprise 12 SP4 RT kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-10135: Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may have allowed an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key (bnc#1171988). - CVE-2020-0305: In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could lead to local
#1051510 #1058115 #1065729 #1071995 #1082555
#1085030 #1089895 #1104967 #1111666 #1114279
#1133021 #1144333 #1148868 #1150660 #1151794
#1152107 #1152489 #1152624 #1154824 #1157169
#1158265 #1158983 #1159058 #1159199 #1160388
#1160947 #1161016 #1162002 #1162063 #1165183
#1165741 #1166969 #1167574 #1167851 #1168081
#1168503 #1168670 #1169020 #1169194 #1169514
#1169525 #1169625 #1169795 #1170011 #1170056
#1170125 #1170145 #1170345 #1170457 #1170522
#1170592 #1170618 #1170620 #1170770 #1170778
#1170791 #1170901 #1171078 #1171098 #1171118
#1171124 #1171189 #1171191 #1171195 #1171202
#1171205 #1171217 #1171218 #1171219 #1171220
#1171293 #1171417 #1171424 #1171527 #1171558
#1171599 #117...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.