Alerts This Week
Warning Icon 1 540
Alerts This Week
Warning Icon 1 540

SUSE: 2020:3272-1 Important: Kernel Denial of Service Fixes

suse
Calendar Grey November 10, 2020
Dist Suse Esm H88
SUSE releases a critical update to address security issues in the Linux Kernel, providing several key fixes for vulnerabilities.
An update that solves 8 vulnerabilities and has 38 fixes is now available

Summary

The SUSE Linux Enterprise 15 SP1 kernel was updated to receive various security and bug fixes. The following security bugs were fixed: - CVE-2020-25656: Fixed a concurrency use-after-free in vt_do_kdgkb_ioctl (bnc#1177766). - CVE-2020-25285: Fixed a race condition between hugetlb sysctl handlers in mm/hugetlb.c (bnc#1176485). - CVE-2020-0430: Fixed an OOB read in skb_headlen of /include/linux/skbuff.h (bnc#1176723). - CVE-2020-14351: Fixed a race in the perf_mmap_close() function (bsc#1177086). - CVE-2020-16120: Fixed a permissions issue in ovl_path_open() (bsc#1177470). - CVE-2020-8694: Restricted energy meter to root access (bsc#1170415). - CVE-2020-27673: Fixed an issue where rogue guests could have caused denial of service of Dom0 via high frequency events (XSA-332 bsc#1177411)

References

#1055014 #1061843 #1065600 #1065729 #1066382

#1077428 #1112178 #1131277 #1134760 #1170415

#1171558 #1173432 #1174748 #1176354 #1176485

#1176560 #1176713 #1176723 #1177086 #1177101

#1177271 #1177281 #1177410 #1177411 #1177470

#1177687 #1177719 #1177740 #1177749 #1177750

#1177753 #1177754 #1177755 #1177766 #1177855

#1177856 #1177861 #1178003 #1178027 #1178166

#1178185 #1178187 #1178188 #1178202 #1178234

#1178330

Cross- CVE-2020-0430 CVE-2020-14351 CVE-2020-16120

CVE-2020-25285 CVE-2020-25656 CVE-2020-27673

CVE-2020-27675 CVE-2020-8694

Affected Products:

SUSE Linux Enterprise Workstation Extension 15-SP1

SUSE Linux Enterprise Module for Legacy Software 15-SP1

SUSE Linux Enterprise Module for Development To...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:3272-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here