Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The SUSE Linux Enterprise 12 SP5 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2021-3655: Fixed a missing size validations on inbound SCTP packets, which may have allowed the kernel to read uninitialized memory (bsc#1188563). - CVE-2021-3715: Fixed a use-after-free in route4_change() in net/sched/cls_route.c (bsc#1190349). - CVE-2021-33033: Fixed a use-after-free in cipso_v4_genopt in net/ipv4/cipso_ipv4.c because the CIPSO and CALIPSO refcounting for the DOI definitions is mishandled (bsc#1186109). - CVE-2021-3760: Fixed a use-after-free vulnerability with the ndev->rf_conn_info object (bsc#1190067). - CVE-2021-42739: The firewire subsystem had a buffer overflow related to drivers/media/firewire/firedtv-avc.c and
#1050549 #1065729 #1085030 #1114648 #1180624
#1184673 #1186063 #1186109 #1188563 #1188601
#1188983 #1188985 #1190006 #1190067 #1190317
#1190349 #1190397 #1190479 #1190620 #1190795
#1190941 #1191241 #1191315 #1191317 #1191349
#1191450 #1191452 #1191455 #1191500 #1191579
#1191628 #1191662 #1191667 #1191713 #1191801
#1191888 #1192145 #1192267
Cross- CVE-2018-13405 CVE-2021-33033 CVE-2021-34556
CVE-2021-3542 CVE-2021-35477 CVE-2021-3655
CVE-2021-3715 CVE-2021-37159 CVE-2021-3760
CVE-2021-41864 CVE-2021-42008 CVE-2021-42252
CVE-2021-42739
CVSS scores:
CVE-2018-13405 (NVD) : 7.8 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE-2018-13405 (SUSE): 4.4 CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Get the latest Linux and open source security news straight to your inbox.