Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE: 2021:1254-1 Critical: Security Update for SLE 12 SP5 Kernel

suse
Calendar Grey November 19, 2020
Dist Suse Esm H88
SUSE released a vital security update for the kernel in Live Patch 1 for SLE 15 SP2, aimed at bolstering system integrity and safeguarding against vulnerabilities.
An update that fixes three vulnerabilities is now available

Summary

This update for the Linux Kernel 5.3.18-24_9 fixes several issues. The following security issues were fixed: - CVE-2020-12351: Fixed a type confusion while processing AMP packets aka "BleedingTooth" aka "BadKarma" (bsc#1177724, bsc#1177729, bsc#1178397). - CVE-2020-24490: Fixed a heap buffer overflow when processing extended advertising report events aka "BleedingTooth" aka "BadVibes" (bsc#1177726, bsc#1177727). - CVE-2020-25645: Fixed an an issue in IPsec that caused traffic between two Geneve endpoints to be unencrypted (bnc#1177513). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Live Patching 15-SP2:

References

#1177513 #1177727 #1177729

Cross- CVE-2020-12351 CVE-2020-24490 CVE-2020-25645

Affected Products:

SUSE Linux Enterprise Module for Live Patching 15-SP2

https://www.suse.com/security/cve/CVE-2020-12351.html

https://www.suse.com/security/cve/CVE-2020-24490.html

https://www.suse.com/security/cve/CVE-2020-25645.html

https://bugzilla.suse.com/show_bug.cgi?id=1177513

https://bugzilla.suse.com/show_bug.cgi?id=1177727

https://bugzilla.suse.com/show_bug.cgi?id=1177729

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:3389-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here