Alerts This Week
Warning Icon 1 626
Alerts This Week
Warning Icon 1 626

SUSE MicroOS 5.0: 2022:0181-1 Important: Critical Kernel Security Issues

suse
Calendar Grey January 25, 2022
Dist Suse Esm H88
Important SUSE patch resolves various kernel issues and security vulnerabilities, including risks for Denial of Service attacks. Discover further details.
An update that solves 10 vulnerabilities, contains one feature and has 42 fixes is now available

Summary

The SUSE MicroOS 5.0 RT kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2021-4001: Fixed a race condition when the EBPF map is frozen. (bsc#1192990) - CVE-2021-4002: Added a missing TLB flush that could lead to leak or corruption of data in hugetlbfs. (bsc#1192946) - CVE-2021-28711: Fixed a rogue backends that could cause DoS of guests via high frequency events by hardening blkfront against event channel storms. (bsc#1193440) - CVE-2021-28712: Fixed a rogue backends that could cause DoS of guests via high frequency events by hardening netfront against event channel storms. (bsc#1193440) - CVE-2021-28713: Fixed a rogue backends that could cause DoS of guests via high frequency events by hardening hvc_xen against event channel storms. (bsc#1193440)

References

#1139944 #1151927 #1152489 #1154353 #1154355

#1161907 #1164565 #1166780 #1176242 #1176536

#1176544 #1176545 #1176546 #1176548 #1176558

#1176559 #1176956 #1177440 #1178270 #1179211

#1179426 #1179427 #1179960 #1181148 #1181507

#1181710 #1183534 #1183540 #1183897 #1185726

#1185902 #1187541 #1189126 #1191793 #1191876

#1192267 #1192507 #1192511 #1192569 #1192606

#1192845 #1192847 #1192877 #1192946 #1192969

#1192990 #1193042 #1193169 #1193318 #1193349

#1193440 #1193442 SLE-20042

Cross- CVE-2021-28711 CVE-2021-28712 CVE-2021-28713

CVE-2021-28714 CVE-2021-28715 CVE-2021-33098

CVE-2021-4001 CVE-2021-4002 CVE-2021-43975

CVE-2021-43976

CVSS scores:

CVE-2021-28711 (NVD) : 6.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:0181-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here