Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

SUSE: 2022:0131-1 Critical Update for Linux Kernel DoS Vulnerabilities

suse
Calendar Grey January 19, 2022
Dist Suse Esm H88
Swift patches rolled out addressing 13 concerns within the Linux kernel, guaranteeing enhanced system reliability and fortified security measures.
An update that solves 13 vulnerabilities, contains one feature and has 61 fixes is now available

Summary

The SUSE Linux Enterprise 15 SP3 kernel was updated - Unprivileged BPF has been disabled by default to reduce attack surface as too many security issues have happened in the past (jsc#SLE-22573) You can reenable via systemctl setting /proc/sys/kernel/unprivileged_bpf_disabled to 0. (kernel.unprivileged_bpf_disabled = 0) The following security bugs were fixed: - CVE-2021-45485: Fixed an information leak because of certain use of a hash table which use IPv6 source addresses. (bsc#1194094) - CVE-2021-45486: Fixed an information leak because the hash table is very small in net/ipv4/route.c. (bnc#1194087). - CVE-2021-4001: Fixed a race condition when the EBPF map is frozen. (bsc#1192990) - CVE-2021-28715: Fixed an issue where a guest could force Linux netback

References

#1139944 #1151927 #1152489 #1153275 #1154353

#1154355 #1161907 #1164565 #1166780 #1169514

#1176242 #1176447 #1176536 #1176544 #1176545

#1176546 #1176548 #1176558 #1176559 #1176774

#1176940 #1176956 #1177440 #1178134 #1178270

#1179211 #1179424 #1179426 #1179427 #1179599

#1181148 #1181507 #1181710 #1182404 #1183534

#1183540 #1183897 #1184318 #1185726 #1185902

#1186332 #1187541 #1189126 #1189158 #1191793

#1191876 #1192267 #1192320 #1192507 #1192511

#1192569 #1192606 #1192691 #1192845 #1192847

#1192874 #1192946 #1192969 #1192987 #1192990

#1192998 #1193002 #1193042 #1193139 #1193169

#1193306 #1193318 #1193349 #1193440 #1193442

#1193655 #1193993 #1194087 #1194094 SLE-22574

Cross- CVE...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:0131-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here