Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 491
Alerts This Week
Warning Icon 1 491

SUSE: 2022:0090-1 Important: Kernel Critical DoS Threats

suse
Calendar Grey January 17, 2022
Scroller Suse
Canonical reveals significant patches for the Ubuntu Kernel targeting 12 vulnerabilities, reinforcing system integrity and performance.
An update that solves 15 vulnerabilities, contains one feature and has 18 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP5 RT kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2019-15126: Fixed a vulnerability in Broadcom and Cypress Wi-Fi chips, used in RPi family of devices aka "Kr00k". (bsc#1167162) - CVE-2020-27820: Fixed a vulnerability where a use-after-frees in nouveau's postclose() handler could happen if removing device. (bsc#1179599) - CVE-2021-0920: Fixed a local privilege escalation due to an use after free bug in unix_gc. (bsc#1193731) - CVE-2021-0935: Fixed out of bounds write due to a use after free which could lead to local escalation of privilege with System execution privileges needed in ip6_xmit. (bsc#1192032) - CVE-2021-4002: Added a missing TLB flush that could lead to leak or corruption of data in hugetlbfs. (bsc#1192946)

References

#1114648 #1124431 #1167162 #1179599 #1183678

#1183897 #1184804 #1185727 #1185762 #1187167

#1189126 #1189305 #1189841 #1190358 #1191229

#1191384 #1192032 #1192145 #1192267 #1192740

#1192845 #1192847 #1192877 #1192946 #1192974

#1193231 #1193306 #1193318 #1193440 #1193442

#1193731 #1194087 #1194094 SLE-17288

Cross- CVE-2019-15126 CVE-2020-27820 CVE-2021-0920

CVE-2021-0935 CVE-2021-28711 CVE-2021-28712

CVE-2021-28713 CVE-2021-28714 CVE-2021-28715

CVE-2021-33098 CVE-2021-4002 CVE-2021-43975

CVE-2021-43976 CVE-2021-45485 CVE-2021-45486

CVSS scores:

CVE-2019-15126 (NVD) : 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CVE-2019-15126 (SUSE): 3.1 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

CVE-2020-27820 (SUSE):...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:0090-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.