The SUSE Linux Enterprise 15 SP1 RT kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-10135: Legacy pairing and secure-connections pairing authentication in Bluetooth BR/EDR Core Specification v5.2 and earlier may have allowed an unauthenticated user to complete authentication without pairing credentials via adjacent access. An unauthenticated, adjacent attacker could impersonate a Bluetooth BR/EDR master or slave to pair with a previously paired remote device to successfully complete the authentication procedure without knowing the link key (bnc#1171988). - CVE-2020-0305: In cdev_get of char_dev.c, there is a possible use-after-free due to a race condition. This could lead to local
#1051510 #1058115 #1065600 #1065729 #1071995
#1082555 #1083647 #1085030 #1089895 #1090036
#1103990 #1103991 #1103992 #1104745 #1109837
#1111666 #1112178 #1112374 #1113956 #1114279
#1124278 #1127354 #1127355 #1127371 #1133021
#1137325 #1142685 #1144333 #1145929 #1148868
#1150660 #1151794 #1151927 #1152489 #1152624
#1154824 #1157169 #1158265 #1158983 #1159037
#1159058 #1159199 #1160388 #1160947 #1161016
#1162002 #1162063 #1163309 #1163403 #1163897
#1164284 #1164780 #1164871 #1165183 #1165478
#1165741 #1166780 #1166860 #1166861 #1166862
#1166864 #1166866 #1166867 #1166868 #1166870
#1166940 #1166969 #1166978 #1166985 #1167104
#1167288 #1167574 #1167851 #1167867 #1168081
#1168202 #116...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.