Alerts This Week
Warning Icon 1 697
Alerts This Week
Warning Icon 1 697

SUSE Linux: 2021:3969-1 Important Kernel Update and Fixes

suse
Calendar Grey December 7, 2021
Dist Suse Esm H88
SUSE Linux kernel upgrade addresses 37 vulnerabilities and includes crucial bug corrections. A system reboot is advised following the update.
An update that solves 37 vulnerabilities and has 21 fixes is now available

Summary

The SUSE Linux Enterprise 15 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: Unprivileged BPF has been disabled by default to reduce attack surface as too many security issues have happened in the past (jsc#SLE-22573) You can reenable via systemctl setting /proc/sys/kernel/unprivileged_bpf_disabled to 0. (kernel.unprivileged_bpf_disabled = 0) - CVE-2018-3639: Fixed a speculative execution that may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. (bsc#1087082) - CVE-2021-20320: Fix a bug that allows a local attacker with special user privilege can circumvent the verifier and may lead to a confidentiality problem. (bsc#1190601)

References

#1085235 #1085308 #1087078 #1087082 #1100394

#1102640 #1105412 #1108488 #1129898 #1133374

#1171420 #1173489 #1174161 #1181854 #1184804

#1185377 #1185726 #1185758 #1186109 #1186482

#1188172 #1188563 #1188601 #1188838 #1188876

#1188983 #1188985 #1189057 #1189262 #1189291

#1189399 #1189400 #1189706 #1189846 #1189884

#1190023 #1190025 #1190067 #1190117 #1190159

#1190351 #1190479 #1190534 #1190601 #1190717

#1191193 #1191315 #1191317 #1191790 #1191800

#1191961 #1192045 #1192267 #1192379 #1192400

#1192775 #1192781 #1192802

Cross- CVE-2018-3639 CVE-2018-9517 CVE-2019-3874

CVE-2019-3900 CVE-2020-12770 CVE-2020-3702

CVE-2021-0941 CVE-2021-20320 CVE-2021-20322

CVE-2021-22543 CVE-2021-31916 CVE-2021-33033

...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2021:3969-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here