Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The SUSE Linux Enterprise 12 SP5 Real Time kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2021-3655: Fixed a missing size validations on inbound SCTP packets, which may have allowed the kernel to read uninitialized memory (bsc#1188563). - CVE-2021-3715: Fixed a use-after-free in route4_change() in net/sched/cls_route.c (bsc#1190349). - CVE-2021-33033: Fixed a use-after-free in cipso_v4_genopt in net/ipv4/cipso_ipv4.c because the CIPSO and CALIPSO refcounting for the DOI definitions is mishandled (bsc#1186109). - CVE-2021-3760: Fixed a use-after-free vulnerability with the ndev->rf_conn_info object (bsc#1190067). - CVE-2021-42739: The firewire subsystem had a buffer overflow related to drivers/media/firewire/firedtv-avc.c and
#1050549 #1065729 #1085030 #1094840 #1114648
#1180624 #1184673 #1186063 #1186109 #1188563
#1188601 #1188983 #1188985 #1190006 #1190067
#1190317 #1190349 #1190351 #1190479 #1190620
#1190795 #1190941 #1191241 #1191315 #1191317
#1191349 #1191450 #1191452 #1191455 #1191500
#1191579 #1191628 #1191662 #1191667 #1191713
#1191801 #1192145 #1192379
Cross- CVE-2018-13405 CVE-2021-33033 CVE-2021-34556
CVE-2021-3542 CVE-2021-35477 CVE-2021-3655
CVE-2021-3715 CVE-2021-37159 CVE-2021-3760
CVE-2021-3772 CVE-2021-41864 CVE-2021-42008
CVE-2021-42252 CVE-2021-42739
CVSS scores:
CVE-2018-13405 (NVD) : 7.8 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2018-13405 (SUSE): 4.4 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Get the latest Linux and open source security news straight to your inbox.