Alerts This Week
Warning Icon 1 923
Alerts This Week
Warning Icon 1 923

SUSE: 2020:3670-1 Important: Linux Kernel Security Update

suse
Calendar Grey December 7, 2020
Dist Suse Esm H88
A critical SUSE update has been released, targeting three key vulnerabilities within the Linux Kernel for SLE 12 SP5. This patch aims to enhance security and system stability.
An update that solves three vulnerabilities and has one errata is now available

Summary

This update for the Linux Kernel 4.12.14-122_29 fixes several issues. The following security issues were fixed: - CVE-2020-25668: Fixed a concurrency use-after-free in con_font_op (bsc#1178622). - CVE-2020-8694: Fixed an insufficient access control in the Linux kernel driver for some Intel(R) Processors which might have allowed an authenticated user to potentially enable information disclosure via local access (bsc#1178700). - CVE-2020-25705: Fixed a flaw which could have allowed an off-path remote user to effectively bypass source port UDP randomization (bsc#1178783). - Fixed an issue where system was hanging due to a massive amount of soft lockups in btrfs_drop_and_free_fs_root() (bsc#1178046). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods

References

#1178046 #1178622 #1178700 #1178783

Cross- CVE-2020-25668 CVE-2020-25705 CVE-2020-8694

Affected Products:

SUSE Linux Enterprise Module for Live Patching 15-SP1

SUSE Linux Enterprise Live Patching 12-SP5

SUSE Linux Enterprise Live Patching 12-SP4

https://www.suse.com/security/cve/CVE-2020-25668.html

https://www.suse.com/security/cve/CVE-2020-25705.html

https://www.suse.com/security/cve/CVE-2020-8694.html

https://bugzilla.suse.com/show_bug.cgi?id=1178046

https://bugzilla.suse.com/show_bug.cgi?id=1178622

https://bugzilla.suse.com/show_bug.cgi?id=1178700

https://bugzilla.suse.com/show_bug.cgi?id=1178783

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:3670-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here