Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The SUSE Linux Enterprise 12 SP4 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2021-33200: Enforcing incorrect limits for pointer arithmetic operations by the BPF verifier could be abused to perform out-of-bounds reads and writes in kernel memory (bsc#1186484). - CVE-2021-33034: Fixed a use-after-free when destroying an hci_chan. This could lead to writing an arbitrary values. (bsc#1186111) - CVE-2020-26139: Fixed a denial-of-service when an Access Point (AP) forwards EAPOL frames to other clients even though the sender has not yet successfully authenticated to the AP. (bnc#1186062) - CVE-2021-23134: A Use After Free vulnerability in nfc sockets allowed local attackers to elevate their privileges. (bnc#1186060)
#1176081 #1180846 #1183947 #1184611 #1184675
#1185642 #1185677 #1185680 #1185724 #1185859
#1185860 #1185862 #1185863 #1185898 #1185899
#1185901 #1185938 #1185950 #1185987 #1186060
#1186061 #1186062 #1186111 #1186285 #1186390
#1186484 #1186498
Cross- CVE-2020-24586 CVE-2020-24587 CVE-2020-26139
CVE-2020-26141 CVE-2020-26145 CVE-2020-26147
CVE-2021-23133 CVE-2021-23134 CVE-2021-32399
CVE-2021-33034 CVE-2021-33200 CVE-2021-3491
CVSS scores:
CVE-2020-24586 (NVD) : 3.5 CVSS:3.1/AV:A/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVE-2020-24586 (SUSE): 4.7 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:N
CVE-2020-24587 (NVD) : 2.6 CVSS:3.1/AV:A/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
CVE-2020-24587 (SUSE): 4.2 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Get the latest Linux and open source security news straight to your inbox.