Alerts This Week
Warning Icon 1 692
Alerts This Week
Warning Icon 1 692

SUSE: 2020:3656-1 Important: Memory Threat And Traffic Issue

suse
Calendar Grey December 7, 2020
Dist Suse Esm H88
Essential SUSE Security Patch corrects several kernel vulnerabilities; mitigates unencrypted communication and memory corruption threats.
An update that fixes four vulnerabilities is now available

Summary

This update for the Linux Kernel 4.4.180-94_135 fixes several issues. The following security issues were fixed: - CVE-2020-25645: Fixed an issue which traffic between two Geneve endpoints may be unencrypted when IPsec is configured to encrypt traffic for the specific UDP port used by the GENEVE tunnel allowing anyone between the two endpoints to read the traffic unencrypted (bsc#1177513). - CVE-2020-0429: Fixed a memory corruption due to a use after free which could have led to to local privilege escalation (bsc#1176931). - CVE-2020-11668: Fixed an issue where the Xirlink camera USB driver mishandled invalid descriptors (bsc#1173942). - CVE-2020-1749: Use ip6_dst_lookup_flow instead of ip6_dst_lookup (bsc#1165631). Patch Instructions:

References

#1165631 #1173942 #1176931 #1177513

Cross- CVE-2020-0429 CVE-2020-11668 CVE-2020-1749

CVE-2020-25645

Affected Products:

SUSE Linux Enterprise Server for SAP 12-SP3

SUSE Linux Enterprise Server 12-SP3-LTSS

https://www.suse.com/security/cve/CVE-2020-0429.html

https://www.suse.com/security/cve/CVE-2020-11668.html

https://www.suse.com/security/cve/CVE-2020-1749.html

https://www.suse.com/security/cve/CVE-2020-25645.html

https://bugzilla.suse.com/show_bug.cgi?id=1165631

https://bugzilla.suse.com/show_bug.cgi?id=1173942

https://bugzilla.suse.com/show_bug.cgi?id=1176931

https://bugzilla.suse.com/show_bug.cgi?id=1177513

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:3656-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here