Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: 2020:3648-1 Important: Kernel Fix For Live Patch 38

suse
Calendar Grey December 7, 2020
Dist Suse Esm H88
Essential update addresses five major vulnerabilities in the Linux Kernel for SUSE, providing straightforward patching guidelines.
An update that fixes 5 vulnerabilities is now available

Summary

This update for the Linux Kernel 4.4.121-92_146 fixes several issues. The following security issues were fixed: - CVE-2020-25668: Fixed a concurrency use-after-free in con_font_op (bsc#1178622). - CVE-2020-25645: Fixed an issue which traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted (bsc#1177513). - CVE-2020-0429: Fixed a memory corruption due to a use after free which could have led to to local privilege escalation (bsc#1176931). - CVE-2020-11668: Fixed an issue where the Xirlink camera USB driver mishandled invalid descriptors (bsc#1173942). - CVE-2020-1749: Use ip6_dst_lookup_flow instead of ip6_dst_lookup (bsc#1165631).

References

#1165631 #1173942 #1176931 #1177513 #1178622

Cross- CVE-2020-0429 CVE-2020-11668 CVE-2020-1749

CVE-2020-25645 CVE-2020-25668

Affected Products:

SUSE Linux Enterprise Server for SAP 12-SP2

SUSE Linux Enterprise Server 12-SP2-LTSS

https://www.suse.com/security/cve/CVE-2020-0429.html

https://www.suse.com/security/cve/CVE-2020-11668.html

https://www.suse.com/security/cve/CVE-2020-1749.html

https://www.suse.com/security/cve/CVE-2020-25645.html

https://www.suse.com/security/cve/CVE-2020-25668.html

https://bugzilla.suse.com/show_bug.cgi?id=1165631

https://bugzilla.suse.com/show_bug.cgi?id=1173942

https://bugzilla.suse.com/show_bug.cgi?id=1176931

https://bugzilla.suse.com/show_bug.cgi?id=1177513

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:3648-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here