Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 461
Alerts This Week
Warning Icon 1 461

SUSE: 2021:3388-1 Important: Linux Kernel Security Update

suse
Calendar Grey October 12, 2021
Scroller Suse
SUSE security update addresses 5 kernel vulnerabilities, improving system security and stability for users.
An update that solves 5 vulnerabilities and has 34 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP5 kernel was updated. The following security bugs were fixed: - CVE-2020-3702: Fixed a bug which could be triggered with specifically timed and handcrafted traffic and cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure. (bnc#1191193) - CVE-2021-3752: Fixed a use after free vulnerability in the Linux kernel's bluetooth module. (bsc#1190023) - CVE-2021-40490: Fixed a race condition discovered in the ext4 subsystem that could leat to local priviledge escalation. (bnc#1190159) - CVE-2021-3744: Fixed a bug which could allows attackers to cause a denial of service. (bsc#1189884) - CVE-2021-3764: Fixed a bug which could allows attackers to cause a denial of service. (bsc#1190534)

References

#1050244 #1056653 #1056657 #1056787 #1065729

#1104745 #1109837 #1111981 #1114648 #1118661

#1129770 #1148868 #1158533 #1173746 #1176940

#1181193 #1184439 #1185677 #1185727 #1186785

#1189297 #1189407 #1189884 #1190023 #1190115

#1190159 #1190432 #1190523 #1190534 #1190543

#1190576 #1190601 #1190620 #1190626 #1190717

#1190914 #1191051 #1191136 #1191193

Cross- CVE-2020-3702 CVE-2021-3744 CVE-2021-3752

CVE-2021-3764 CVE-2021-40490

CVSS scores:

CVE-2020-3702 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2020-3702 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2021-3744 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

CVE-2021-3752 (SUSE): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:3388-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.