Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

SUSE: 2020:2576-1 Important: Kernel Security Update Fixes Bugs

suse
Calendar Grey September 9, 2020
Dist Suse Esm H88
Significant SUSE Security Patch for Kernel Tackles Various Flaws, Provides Resolutions and Guidelines to Mitigate Threats.
An update that solves 5 vulnerabilities and has one errata is now available

Summary

The SUSE Linux Enterprise 12 SP2 kernel was updated to to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-14314: Fixed a potential negative array index in do_split() (bsc#1173798). - CVE-2020-14331: Fixed a missing check in vgacon scrollback handling (bsc#1174205). - CVE-2020-16166: Fixed a potential issue which could have allowed remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG (bsc#1174757). - CVE-2019-16746: Fixed an improper check of the length of variable elements in a beacon head, leading to a buffer overflow (bsc#1152107). - CVE-2020-14386: Fixed a potential local privilege escalation via memory corruption (bsc#1176069). The following non-security bug was fixed:

References

#1152107 #1173798 #1174205 #1174757 #1175691

#1176069

Cross- CVE-2019-16746 CVE-2020-14314 CVE-2020-14331

CVE-2020-14386 CVE-2020-16166

Affected Products:

SUSE OpenStack Cloud 7

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server 12-SP2-LTSS

SUSE Linux Enterprise Server 12-SP2-BCL

SUSE Linux Enterprise High Availability 12-SP2

https://www.suse.com/security/cve/CVE-2019-16746.html

https://www.suse.com/security/cve/CVE-2020-14314.html

https://www.suse.com/security/cve/CVE-2020-14331.html

https://www.suse.com/security/cve/CVE-2020-14386.html

https://www.suse.com/security/cve/CVE-2020-16166.html

https://bugzilla.suse.com/1152107

https://bugzilla.suse.com/1173798

https://bugzilla.suse.com/1174205

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:2576-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here