Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE: 2021:3447-1 Important Kernel Security Threats Addressed

suse
Calendar Grey October 15, 2021
Scroller Suse
SUSE Security Patch 2021-3447-2 tackles significant kernel vulnerabilities, implementing crucial repairs and bolstering system security.
An update that solves 6 vulnerabilities and has 44 fixes is now available

Summary

The SUSE Linux Enterprise 15 SP2 kernel was updated. The following security bugs were fixed: - CVE-2020-3702: Fixed a bug which could be triggered with specifically timed and handcrafted traffic and cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure. (bnc#1191193) - CVE-2021-3752: Fixed a use after free vulnerability in the Linux kernel's bluetooth module. (bsc#1190023) - CVE-2021-40490: Fixed a race condition discovered in the ext4 subsystem that could leat to local priviledge escalation. (bnc#1190159) - CVE-2021-3744: Fixed a bug which could allows attackers to cause a denial of service. (bsc#1189884) - CVE-2021-3764: Fixed a bug which could allows attackers to cause a denial of service. (bsc#1190534)

References

#1065729 #1148868 #1152489 #1154353 #1159886

#1167773 #1170774 #1173746 #1176940 #1184439

#1184804 #1185302 #1185677 #1185726 #1185762

#1187167 #1188067 #1188651 #1188986 #1189297

#1189841 #1189884 #1190023 #1190062 #1190115

#1190159 #1190358 #1190406 #1190432 #1190467

#1190523 #1190534 #1190543 #1190576 #1190595

#1190596 #1190598 #1190620 #1190626 #1190679

#1190705 #1190717 #1190746 #1190758 #1190784

#1190785 #1191172 #1191193 #1191240 #1191292

Cross- CVE-2020-3702 CVE-2021-3669 CVE-2021-3744

CVE-2021-3752 CVE-2021-3764 CVE-2021-40490

CVSS scores:

CVE-2020-3702 (NVD) : 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CVE-2020-3702 (SUSE): 7.5 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:3447-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.