Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×
The SUSE Linux Enterprise 12 SP3 LTSS kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - Unprivileged BPF has been disabled by default to reduce attack surface as too many security issues have happened in the past (jsc#SLE-22573) You can reenable via systemctl setting /proc/sys/kernel/unprivileged_bpf_disabled to 0. (kernel.unprivileged_bpf_disabled = 0) - CVE-2021-31916: An out-of-bounds (OOB) memory write flaw was found in list_devices in drivers/md/dm-ioctl.c in the Multi-device driver module in the Linux kernel A bound check failure allowed an attacker with special user (CAP_SYS_ADMIN) privilege to gain access to out-of-bounds memory leading to a system crash or a leak of internal kernel
#1073928 #1098425 #1100416 #1119934 #1129735
#1171217 #1171420 #1173346 #1176724 #1177666
#1181158 #1181854 #1181855 #1183089 #1184673
#1185726 #1185727 #1185758 #1185973 #1186109
#1186390 #1188172 #1188563 #1188601 #1188838
#1188876 #1188983 #1188985 #1189057 #1189262
#1189278 #1189291 #1189399 #1189420 #1189706
#1190022 #1190023 #1190025 #1190067 #1190117
#1190159 #1190194 #1190349 #1190351 #1190601
#1190717 #1191193 #1191315 #1191790 #1191801
#1191958 #1191961 #1192267 #1192400 #1192775
#1192781
Cross- CVE-2017-17862 CVE-2017-17864 CVE-2018-13405
CVE-2018-16882 CVE-2020-0429 CVE-2020-12655
CVE-2020-14305 CVE-2020-3702 CVE-2020-4788
CVE-2021-20265 CVE-2021-20322 CVE-2021-31916
CV...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.