The SUSE Linux Enterprise 15 SP3 RT kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2021-4083: Fixed race condition in Unix domain socket garbage collection that could lead to read memory after free (bsc#1193727). - CVE-2021-4135: Fixed an information leak in the nsim_bpf_map_alloc function (bsc#1193927). - CVE-2021-4149: Fixed improper lock operation in btrfs that allowed users to crash the kernel or deadlock the system (bsc#1194001). - CVE-2021-4197: Fixed a cgroup issue where lower privileged processes could write to fds of lower privileged ones that could lead to privilege escalation (bsc#1194302). - CVE-2021-4202: Fixed race condition in nci_request() that could cause use-after-free (bsc#1194529).
#1065729 #1071995 #1154353 #1154492 #1156395
#1167773 #1176447 #1176774 #1177437 #1190256
#1191271 #1192931 #1193255 #1193328 #1193669
#1193727 #1193767 #1193901 #1193927 #1194001
#1194027 #1194302 #1194493 #1194516 #1194517
#1194518 #1194529 #1194580 #1194584 #1194586
#1194587 #1194589 #1194590 #1194591 #1194592
#1194888 #1194953 #1194985 #1195062 SLE-13294
SLE-13533 SLE-14777 SLE-15172 SLE-16683 SLE-23432
SLE-8464
Cross- CVE-2021-4083 CVE-2021-4135 CVE-2021-4149
CVE-2021-4197 CVE-2021-4202 CVE-2021-44733
CVE-2021-46283 CVE-2022-0185 CVE-2022-0322
CVSS scores:
CVE-2021-4083 (SUSE): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
CVE-2021-4135 (SUSE): 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Get the latest Linux and open source security news straight to your inbox.