The SUSE Linux Enterprise 12 SP5 Azure kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-15437: Fixed a null pointer dereference which could have allowed local users to cause a denial of service(bsc#1179140). - CVE-2020-27777: Restrict RTAS requests from userspace (bsc#1179107). - CVE-2020-28974: Fixed a slab-out-of-bounds read in fbcon which could have been used by local attackers to read privileged information or potentially crash the kernel (bsc#1178589). - CVE-2020-28915: Fixed a buffer over-read in the fbcon code which could have been used by local attackers to read kernel memory (bsc#1178886). - CVE-2020-8694: Insufficient access control for some Intel(R) Processors may have allowed an authenticated user to potentially enable information
#1050549 #1058115 #1067665 #1111666 #1112178
#1167030 #1170139 #1170415 #1170446 #1170630
#1172542 #1172873 #1174726 #1175306 #1175916
#1176109 #1176855 #1176907 #1176983 #1177304
#1177397 #1177703 #1177805 #1177808 #1177809
#1177819 #1177820 #1178123 #1178182 #1178393
#1178589 #1178591 #1178607 #1178635 #1178669
#1178686 #1178700 #1178765 #1178838 #1178853
#1178854 #1178878 #1178886 #1178897 #1178940
#1178962 #1179107 #1179140 #1179211 #1179213
#1179259 #1179424 #1179426 #1179427 #927455
Cross- CVE-2020-15437 CVE-2020-25668 CVE-2020-25669
CVE-2020-25704 CVE-2020-27777 CVE-2020-28915
CVE-2020-28974 CVE-2020-8694
Affected Products:
SUSE Linux Enterprise Server 12-SP5
https://www.suse.com/security/cve...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.