The SUSE Linux Enterprise 11 SP4 LTSS kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2021-37159: hso_free_net_device in drivers/net/usb/hso.c called unregister_netdev without checking for the NETREG_REGISTERED state, leading to a use-after-free and a double free (bnc#1188601). - CVE-2021-3772: Fixed sctp vtag check in sctp_sf_ootb (bsc#1190351). - CVE-2021-3655: Missing size validations on inbound SCTP packets may have allowed the kernel to read uninitialized memory (bnc#1188563 bnc#1192267). - CVE-2014-7841: The sctp_process_param function in net/sctp/sm_make_chunk.c in the SCTP implementation, when ASCONF is used, allowed remote attackers to cause a denial of service (NULL
#1183089 #1184673 #1186109 #1187050 #1187215
#1188172 #1188563 #1188601 #1188876 #1189057
#1189262 #1189399 #1190117 #1190351 #1191315
#1191660 #1191958 #1192036 #1192267 #904899
#905100
Cross- CVE-2014-7841 CVE-2020-36385 CVE-2021-20265
CVE-2021-33033 CVE-2021-3542 CVE-2021-3609
CVE-2021-3640 CVE-2021-3653 CVE-2021-3655
CVE-2021-3679 CVE-2021-37159 CVE-2021-3772
CVE-2021-38160 CVE-2021-38198 CVE-2021-42008
CVE-2021-42739 CVE-2021-43389
CVSS scores:
CVE-2020-36385 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2020-36385 (SUSE): 8.4 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2021-20265 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVE-2021-20265 (SUSE): 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.