Alerts This Week
Warning Icon 1 677
Alerts This Week
Warning Icon 1 677

SUSE Linux 15: SUSE-SU-2022:1255-1 Important Kernel Update

suse
Calendar Grey April 19, 2022
Dist Suse Esm H88
Crucial announcement for SUSE Linux Kernel addresses 20 vulnerabilities, enhancing both security and reliability.
An update that solves 20 vulnerabilities, contains one feature and has three fixes is now available

Summary

The SUSE Linux Enterprise 15 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2022-28356: Fixed a refcount leak bug in net/llc/af_llc.c (bnc#1197391). - CVE-2022-1016: Fixed a vulnerability in the nf_tables component of the netfilter subsystem. This vulnerability gives an attacker a powerful primitive that can be used to both read from and write to relative stack data, which can lead to arbitrary code execution (bsc#1197227). - CVE-2022-28389: Fixed a double free in drivers/net/can/usb/mcba_usb.c vulnerability in the Linux kernel (bnc#1198033). - CVE-2022-28388: Fixed a double free in drivers/net/can/usb/usb_8dev.c vulnerability in the Linux kernel (bnc#1198032). - CVE-2022-28390: Fixed a double free in drivers/net/can/usb/ems_usb.c

References

#1189562 #1194943 #1195051 #1195353 #1196018

#1196114 #1196468 #1196488 #1196514 #1196639

#1196761 #1196830 #1196836 #1196942 #1196973

#1197131 #1197227 #1197331 #1197366 #1197391

#1198031 #1198032 #1198033 SLE-18234

Cross- CVE-2021-39713 CVE-2021-45868 CVE-2022-0812

CVE-2022-0850 CVE-2022-0886 CVE-2022-1016

CVE-2022-1048 CVE-2022-23036 CVE-2022-23037

CVE-2022-23038 CVE-2022-23039 CVE-2022-23040

CVE-2022-23041 CVE-2022-23042 CVE-2022-26490

CVE-2022-26966 CVE-2022-28356 CVE-2022-28388

CVE-2022-28389 CVE-2022-28390

CVSS scores:

CVE-2021-39713 (NVD) : 9.8 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2021-39713 (SUSE): 7.4 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CVE-2021-45868 (NVD) : 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:1255-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here