Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2021:1865-1 Important Kernel Patch for SLE 12 SP3 Critical Issues

suse
Calendar Grey June 4, 2021
Scroller Suse
New update released for SUSE Linux Kernel Live Patch, addressing two major vulnerabilities and one notable erratum for SLE 12 SP3.
An update that solves two vulnerabilities and has one errata is now available

Summary

This update for the Linux Kernel 4.4.180-94_130 fixes several issues. The following security issues were fixed: - Fix a kernel warning during sysfs read (bsc#1186235) - CVE-2020-36322: An issue was discovered in the FUSE filesystem implementation in the Linux kernel aka CID-5d069dbe8aaf. fuse_do_getattr() calls make_bad_inode() in inappropriate situations, causing a system crash. NOTE: the original fix for this vulnerability was incomplete, and its incompleteness is tracked as CVE-2021-28950 (bsc#1184952). - CVE-2021-29154: BPF JIT compilers in the Linux kernel have incorrect computation of branch displacements, allowing them to execute arbitrary code within the kernel context. This affects arch/x86/net/bpf_jit_comp.c and arch/x86/net/bpf_jit_comp32.c (bsc#1184710) Patch Instructions:

References

#1184710 #1184952 #1186235

Cross- CVE-2020-36322 CVE-2021-29154

CVSS scores:

CVE-2020-36322 (SUSE): 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CVE-2021-29154 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVE-2021-29154 (SUSE): 7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected Products:

SUSE Linux Enterprise Server for SAP 12-SP3

SUSE Linux Enterprise Server 12-SP3-LTSS

https://www.suse.com/security/cve/CVE-2020-36322.html

https://www.suse.com/security/cve/CVE-2021-29154.html

https://bugzilla.suse.com/1184710

https://bugzilla.suse.com/1184952

https://bugzilla.suse.com/1186235

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:1865-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.