Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 508
Alerts This Week
Warning Icon 1 508

SUSE 15 SP2: 2021:3658-1 Important Addressing Kernel Security Issues

suse
Calendar Grey November 11, 2021
Scroller Suse
SUSE has issued a significant update fixing major vulnerabilities in the Linux kernel, addressing 11 security flaws that may lead to attacks or unauthorized access
An update that solves 11 vulnerabilities and has 35 fixes is now available

Summary

The SUSE Linux Enterprise 15 SP2 Real Time kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2021-3772: Fixed sctp vtag check in sctp_sf_ootb (bsc#1190351). - CVE-2021-3655: Fixed a missing size validations on inbound SCTP packets, which may have allowed the kernel to read uninitialized memory (bsc#1188563). - CVE-2021-43056: Fixed possible KVM host crash via malicious KVM guest on Power8 (bnc#1192107). - CVE-2021-3896: Fixed a array-index-out-bounds in detach_capi_ctr in drivers/isdn/capi/kcapi.c (bsc#1191958). - CVE-2021-3760: Fixed a use-after-free vulnerability with the ndev->rf_conn_info object (bsc#1190067). - CVE-2021-42739: The firewire subsystem had a buffer overflow related to drivers/media/firewire/firedtv-avc.c and

References

#1065729 #1085030 #1152489 #1154353 #1156395

#1157177 #1167773 #1172073 #1173604 #1176940

#1184673 #1185762 #1186063 #1187167 #1188563

#1189841 #1190006 #1190067 #1190349 #1190351

#1190479 #1190620 #1190642 #1190795 #1190941

#1191229 #1191241 #1191315 #1191317 #1191349

#1191384 #1191449 #1191450 #1191451 #1191452

#1191455 #1191456 #1191628 #1191731 #1191800

#1191934 #1191958 #1192040 #1192041 #1192107

#1192145

Cross- CVE-2021-3542 CVE-2021-3655 CVE-2021-3715

CVE-2021-3760 CVE-2021-3772 CVE-2021-3896

CVE-2021-41864 CVE-2021-42008 CVE-2021-42252

CVE-2021-42739 CVE-2021-43056

CVSS scores:

CVE-2021-3542 (SUSE): 6.4 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H

CVE-2021-3655 (SUSE): 4 CVSS:3.1/AV:L/AC:L/PR:N/...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:3658-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.