Alerts This Week
Warning Icon 1 764
Alerts This Week
Warning Icon 1 764

SUSE Linux Kernel 12 SP4: 2021:0434-1 Important: DoS, Local Escalation

suse
Calendar Grey February 11, 2021
Dist Suse Esm H88
Essential security patch for SUSE Kernel tackling 30 vulnerabilities and enhancing overall system robustness and reliability.
An update that solves 26 vulnerabilities and has 27 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP4 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2021-3348: Fixed a use-after-free in nbd_add_socket() that could be triggered by local attackers (with access to the nbd device) via an I/O request (bnc#1181504). - CVE-2021-3347: A use-after-free was discovered in the PI futexes during fault handling, allowing local users to execute code in the kernel (bnc#1181349). - CVE-2020-27835: A use-after-free in the infiniband hfi1 driver was found, specifically in the way user calls Ioctl after open dev file and fork. A local user could use this flaw to crash the system (bnc#1179878). - CVE-2020-25211: Fixed a buffer overflow in ctnetlink_parse_tuple_filter() which could be triggered by a local

References

#1144912 #1149032 #1158775 #1163727 #1171979

#1176395 #1176846 #1176962 #1177304 #1177666

#1178036 #1178182 #1178198 #1178372 #1178589

#1178590 #1178684 #1178886 #1179107 #1179140

#1179141 #1179419 #1179429 #1179508 #1179509

#1179601 #1179616 #1179663 #1179666 #1179745

#1179877 #1179878 #1179895 #1179960 #1179961

#1180008 #1180027 #1180028 #1180029 #1180030

#1180031 #1180032 #1180052 #1180086 #1180559

#1180562 #1180676 #1181001 #1181158 #1181349

#1181504 #1181553 #1181645

Cross- CVE-2019-20934 CVE-2020-0444 CVE-2020-0465

CVE-2020-0466 CVE-2020-15436 CVE-2020-15437

CVE-2020-25211 CVE-2020-25639 CVE-2020-25669

CVE-2020-27068 CVE-2020-27777 CVE-2020-27786

CVE-2020-27825 CVE-2020-27835 CVE-2020-28374

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:0434-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here