Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

SUSE: 2020:3326-1 Moderate: Linux Kernel Security Update

suse
Calendar Grey November 13, 2020
Dist Suse Esm H88
Keep informed on the most recent SUSE Linux kernel security patch release, tackling several vulnerabilities and corrective measures.
An update that solves 7 vulnerabilities, contains one feature and has 47 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP5 kernel was updated to receive various security and bug fixes. The following security bugs were fixed: - CVE-2020-25656: Fixed a concurrency use-after-free in vt_do_kdgkb_ioctl (bnc#1177766). - CVE-2020-25285: Fixed a race condition between hugetlb sysctl handlers in mm/hugetlb.c (bnc#1176485). - CVE-2020-0430: Fixed an OOB read in skb_headlen of /include/linux/skbuff.h (bnc#1176723). - CVE-2020-14351: Fixed a race in the perf_mmap_close() function (bsc#1177086). - CVE-2020-16120: Fixed a permissions issue in ovl_path_open() (bsc#1177470). - CVE-2020-8694: Restricted energy meter to root access (bsc#1170415). - CVE-2020-25705: A ICMP global rate limiting side-channel was removed which could lead to e.g. the SADDNS attack (bsc#1175721)

References

#1055014 #1058115 #1061843 #1065600 #1065729

#1066382 #1077428 #1112178 #1114648 #1131277

#1134760 #1157424 #1163592 #1167030 #1170415

#1171558 #1172538 #1173432 #1174748 #1175520

#1175721 #1176354 #1176485 #1176560 #1176723

#1176907 #1176946 #1177086 #1177101 #1177271

#1177281 #1177410 #1177411 #1177470 #1177719

#1177740 #1177749 #1177750 #1177753 #1177754

#1177755 #1177766 #1177855 #1177856 #1177861

#1178003 #1178027 #1178166 #1178185 #1178187

#1178188 #1178202 #1178234 #1178330 SLE-10886

Cross- CVE-2020-0430 CVE-2020-14351 CVE-2020-16120

CVE-2020-25285 CVE-2020-25656 CVE-2020-25705

CVE-2020-8694

Affected Products:

SUSE Linux Enterprise Workstation Extension 12-SP5

SUSE Linux Ente...

Read the Full Advisory

Announcement ID: SUSE-SU-2020:3326-1
Rating: moderate

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here