The SUSE Linux Enterprise 12 SP5 Azure kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-26088: Fixed an improper CAP_NET_RAW check in NFC socket creation could have been used by local attackers to create raw sockets, bypassing security mechanisms (bsc#1176990). - CVE-2020-14390: Fixed an out-of-bounds memory write leading to memory corruption or a denial of service when changing screen size (bnc#1176235). - CVE-2020-0432: Fixed an out of bounds write due to an integer overflow (bsc#1176721). - CVE-2020-0427: Fixed an out of bounds read due to a use after free (bsc#1176725). - CVE-2020-0431: Fixed an out of bounds write due to a missing bounds check (bsc#1176722). - CVE-2020-0404: Fixed a linked list corruption due to an unusual root cause (bsc#1176423).
#1055186 #1065600 #1065729 #1094244 #1112178
#1113956 #1154366 #1163524 #1167527 #1169972
#1171688 #1171742 #1173115 #1174354 #1174899
#1175228 #1175528 #1175749 #1175882 #1176011
#1176022 #1176038 #1176235 #1176242 #1176278
#1176316 #1176317 #1176318 #1176319 #1176320
#1176321 #1176381 #1176395 #1176410 #1176423
#1176482 #1176507 #1176536 #1176544 #1176545
#1176546 #1176548 #1176659 #1176698 #1176699
#1176700 #1176721 #1176722 #1176725 #1176732
#1176788 #1176789 #1176869 #1176877 #1176935
#1176950 #1176962 #1176966 #1176990 #1177027
#1177030 #1177041 #1177042 #1177043 #1177044
#1177121 #1177206 #1177291 #1177293 #1177294
#1177295 #1177296
Cross- CVE-2020-0404 CVE-2020-0427 CVE-2020-0431
...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.