Alerts This Week
Warning Icon 1 700
Alerts This Week
Warning Icon 1 700

SUSE: 2020:3748-1 Important: Linux Kernel Critical Fixes

suse
Calendar Grey December 10, 2020
Dist Suse Esm H88
Important SUSE Linux Kernel update resolves 12 issues including local privilege escalation risks and denial of service.
An update that solves 12 vulnerabilities and has 72 fixes is now available

Summary

The SUSE Linux Enterprise 15 SP2 kernel was updated to 3.12.31 to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-15436: Fixed a use after free vulnerability in fs/block_dev.c which could have allowed local users to gain privileges or cause a denial of service (bsc#1179141). - CVE-2020-15437: Fixed a null pointer dereference which could have allowed local users to cause a denial of service(bsc#1179140). - CVE-2020-25668: Fixed a concurrency use-after-free in con_font_op (bsc#1178123). - CVE-2020-25669: Fixed a use-after-free read in sunkbd_reinit() (bsc#1178182). - CVE-2020-25704: Fixed a leak in perf_event_parse_addr_filter() (bsc#1178393). - CVE-2020-27777: Restrict RTAS requests from userspace (bsc#1179107)

References

#1149032 #1152489 #1153274 #1154353 #1155518

#1160634 #1166146 #1166166 #1167030 #1167773

#1170139 #1171073 #1171558 #1172873 #1173504

#1174852 #1175306 #1175918 #1176109 #1176180

#1176200 #1176481 #1176586 #1176855 #1176983

#1177066 #1177070 #1177353 #1177397 #1177577

#1177666 #1177703 #1177820 #1178123 #1178182

#1178227 #1178286 #1178304 #1178330 #1178393

#1178401 #1178426 #1178461 #1178579 #1178581

#1178584 #1178585 #1178589 #1178635 #1178653

#1178659 #1178661 #1178669 #1178686 #1178740

#1178755 #1178762 #1178838 #1178853 #1178886

#1179001 #1179012 #1179014 #1179015 #1179045

#1179076 #1179082 #1179107 #1179140 #1179141

#1179160 #1179201 #1179211 #1179217 #1179225

#1179419 #117...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2020:3748-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here