Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

SUSE: 2020:2487-1 important: Kernel Security Update and Bug Fixes

suse
Calendar Grey September 4, 2020
Dist Suse Esm H88
The latest Linux Kernel version addresses 40 vulnerabilities and enhances the system's reliability.
An update that solves 40 vulnerabilities and has 227 fixes is now available

Summary

The SUSE Linux Enterprise 15 SP1 RT kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-10135: Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may have allowed an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key (bnc#1171988). - CVE-2020-0305: In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could lead to local

References

#1051510 #1058115 #1065600 #1065729 #1071995

#1082555 #1083647 #1085030 #1089895 #1090036

#1103990 #1103991 #1103992 #1104745 #1109837

#1111666 #1112178 #1112374 #1113956 #1114279

#1124278 #1127354 #1127355 #1127371 #1133021

#1137325 #1142685 #1144333 #1145929 #1148868

#1150660 #1151794 #1151927 #1152489 #1152624

#1154824 #1157169 #1158265 #1158983 #1159037

#1159058 #1159199 #1160388 #1160947 #1161016

#1162002 #1162063 #1163309 #1163403 #1163897

#1164284 #1164780 #1164871 #1165183 #1165478

#1165741 #1166780 #1166860 #1166861 #1166862

#1166864 #1166866 #1166867 #1166868 #1166870

#1166940 #1166969 #1166978 #1166985 #1167104

#1167288 #1167574 #1167851 #1167867 #1168081

#1168202 #116...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:2487-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here