Alerts This Week
Warning Icon 1 619
Alerts This Week
Warning Icon 1 619

SUSE: 2020:3474-1 Important: u-boot Security Update for Multiple Issues

suse
Calendar Grey November 21, 2020
Dist Suse Esm H88
SUSE Security Patch for u-boot: Significant updates addressing numerous vulnerabilities released. Review essential correction specifics.
An update that fixes 17 vulnerabilities is now available

Summary

This update for u-boot fixes the following issues: Work around CVE-2019-11059 by disabling 64Bit descritptor size (bsc#1134853) CVE-2019-11690 (bsc#1134157), CVE-2020-10648 (bsc#1167209), CVE-2019-13103 (bsc#1143463), CVE-2019-14197 (bsc#1143821), CVE-2019-14200 (bsc#1143825), CVE-2019-14201 (bsc#1143827), CVE-2019-14202 (bsc#1143828), CVE-2019-14203 (bsc#1143830), CVE-2019-14204 (bsc#1143831), CVE-2019-14194 (bsc#1143818), CVE-2019-14198 (bsc#1143823), CVE-2019-14195 (bsc#1143819), CVE-2019-14196 (bsc#1143820), CVE-2019-14299 (bsc#1143824), CVE-2019-14192 (bsc#1143777), CVE-2019-14193 (bsc#1143817). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch".

References

#1134157 #1134853 #1143463 #1143777 #1143817

#1143818 #1143819 #1143820 #1143821 #1143823

#1143824 #1143825 #1143827 #1143828 #1143830

#1143831 #1167209

Cross- CVE-2019-11059 CVE-2019-11690 CVE-2019-13103

CVE-2019-14192 CVE-2019-14193 CVE-2019-14194

CVE-2019-14195 CVE-2019-14196 CVE-2019-14197

CVE-2019-14198 CVE-2019-14200 CVE-2019-14201

CVE-2019-14202 CVE-2019-14203 CVE-2019-14204

CVE-2019-14299 CVE-2020-10648

Affected Products:

SUSE Linux Enterprise Server 12-SP3-LTSS

SUSE Enterprise Storage 5

https://www.suse.com/security/cve/CVE-2019-11059.html

https://www.suse.com/security/cve/CVE-2019-11690.html

https://www.suse.com/security/cve/CVE-2019-13103.html

https://www.suse.com/security/cve/CVE-2019-14192.html

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:3474-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here