Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 515
Alerts This Week
Warning Icon 1 515

SUSE 12-SP5: 2021:3192-1 Important: Kernel Memory Corruption Fix

suse
Calendar Grey September 22, 2021
Scroller Suse
Essential SUSE Linux kernel patch addresses multiple concerns including service denial and memory handling flaws.
An update that solves 13 vulnerabilities and has 39 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP5 Azure kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2018-9517: Fixed possible memory corruption due to a use after free in pppol2tp_connect (bsc#1108488). - CVE-2019-3874: Fixed possible denial of service attack via SCTP socket buffer used by a userspace applications (bnc#1129898). - CVE-2019-3900: Fixed an infinite loop issue while handling incoming packets in handle_rx() (bnc#1133374). - CVE-2021-3640: Fixed a Use-After-Free vulnerability in function sco_sock_sendmsg() in the bluetooth stack (bsc#1188172). - CVE-2021-3653: Missing validation of the `int_ctl` VMCB field and allows a malicious L1 guest to enable AVIC support for the L2 guest. (bsc#1189399).

References

#1040364 #1108488 #1114648 #1127650 #1129898

#1133374 #1183050 #1183983 #1185902 #1185973

#1187076 #1188000 #1188172 #1188439 #1188616

#1188885 #1188982 #1189057 #1189262 #1189268

#1189269 #1189270 #1189271 #1189272 #1189291

#1189301 #1189384 #1189385 #1189392 #1189399

#1189400 #1189505 #1189506 #1189562 #1189564

#1189565 #1189566 #1189567 #1189568 #1189569

#1189573 #1189577 #1189579 #1189581 #1189582

#1189639 #1189640 #1189706 #1189846 #1190025

#1190115 #1190117

Cross- CVE-2018-9517 CVE-2019-3874 CVE-2019-3900

CVE-2021-3640 CVE-2021-3653 CVE-2021-3656

CVE-2021-3679 CVE-2021-3732 CVE-2021-3753

CVE-2021-3759 CVE-2021-38160 CVE-2021-38198

CVE-2021-38204

CVSS scores:

CVE-2018-9517 (NVD)...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:3192-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.