The SUSE Linux Enterprise 15 SP3 kernel was updated to receive various security and bugfixes. NOTE: This update was retracted due to a NFS regression. The following security bugs were fixed: - CVE-2021-3772: Fixed sctp vtag check in sctp_sf_ootb (bsc#1190351). - CVE-2021-3655: Fixed a missing size validations on inbound SCTP packets, which may have allowed the kernel to read uninitialized memory (bsc#1188563). - CVE-2021-43056: Fixed possible KVM host crash via malicious KVM guest on Power8 (bnc#1192107). - CVE-2021-3896: Fixed a array-index-out-bounds in detach_capi_ctr in drivers/isdn/capi/kcapi.c (bsc#1191958). - CVE-2021-3760: Fixed a use-after-free vulnerability with the ndev->rf_conn_info object (bsc#1190067). - CVE-2021-42739: The firewire subsystem had a buffer overflow related to
#1065729 #1085030 #1152472 #1152489 #1156395
#1172073 #1173604 #1176447 #1176774 #1176914
#1178134 #1180100 #1181147 #1184673 #1185762
#1186063 #1186109 #1187167 #1188563 #1189841
#1190006 #1190067 #1190349 #1190351 #1190479
#1190620 #1190642 #1190795 #1190801 #1190941
#1191229 #1191240 #1191241 #1191315 #1191317
#1191349 #1191384 #1191449 #1191450 #1191451
#1191452 #1191455 #1191456 #1191628 #1191645
#1191663 #1191731 #1191800 #1191867 #1191934
#1191958 #1192040 #1192041 #1192074 #1192107
#1192145
Cross- CVE-2021-33033 CVE-2021-34866 CVE-2021-3542
CVE-2021-3655 CVE-2021-3715 CVE-2021-3760
CVE-2021-3772 CVE-2021-3896 CVE-2021-41864
CVE-2021-42008 CVE-2021-42252 CVE-2021-42739
CVE-2...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.