The SUSE Linux Enterprise 15 SP1 Azure kernel was updated receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-15437: Fixed a null pointer dereference which could have allowed local users to cause a denial of service(bsc#1179140). - CVE-2020-27777: Restrict RTAS requests from userspace (bsc#1179107). - CVE-2020-28974: Fixed a slab-out-of-bounds read in fbcon which could have been used by local attackers to read privileged information or potentially crash the kernel (bsc#1178589). - CVE-2020-28915: Fixed a buffer over-read in the fbcon code which could have been used by local attackers to read kernel memory (bsc#1178886). The following non-security bugs were fixed: - ACPI: GED: fix -Wformat (git-fixes).
#1050549 #1067665 #1111666 #1112178 #1170139
#1172542 #1174726 #1175916 #1176109 #1177304
#1177397 #1177805 #1177808 #1178589 #1178635
#1178669 #1178853 #1178854 #1178886 #1178897
#1178940 #1178962 #1179107 #1179140 #1179211
#1179213 #1179259 #1179424 #1179426 #1179427
Cross- CVE-2020-15437 CVE-2020-27777 CVE-2020-28915
CVE-2020-28974
Affected Products:
SUSE Linux Enterprise Module for Public Cloud 15-SP1
https://www.suse.com/security/cve/CVE-2020-15437.html
https://www.suse.com/security/cve/CVE-2020-27777.html
https://www.suse.com/security/cve/CVE-2020-28915.html
https://www.suse.com/security/cve/CVE-2020-28974.html
https://bugzilla.suse.com/1050549
https://bugzilla.suse.com/1067665
https://bugzilla.suse.com/1111666
Get the latest Linux and open source security news straight to your inbox.