The SUSE Linux Enterprise 12 SP5 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2022-29900, CVE-2022-29901: Fixed the RETBLEED attack, a new Spectre like Branch Target Buffer attack, that can leak arbitrary kernel information (bsc#1199657). - CVE-2022-1679: Fixed a use-after-free in the Atheros wireless driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages (bsc#1199487). - CVE-2022-20132: Fixed out of bounds read due to improper input validation in lg_probe and related functions of hid-lg.c (bsc#1200619). - CVE-2022-1012: Fixed information leak caused by small table perturb size in the TCP source port generation algorithm (bsc#1199482).
#1065729 #1129770 #1177282 #1194013 #1196964
#1197170 #1199482 #1199487 #1199657 #1200343
#1200571 #1200599 #1200600 #1200604 #1200605
#1200608 #1200619 #1200692 #1200762 #1200806
#1200807 #1200809 #1200810 #1200813 #1200820
#1200821 #1200822 #1200829 #1200868 #1200869
#1200870 #1200871 #1200872 #1200873 #1200925
#1201080 #1201251
Cross- CVE-2020-26541 CVE-2021-4157 CVE-2022-1012
CVE-2022-1679 CVE-2022-20132 CVE-2022-20141
CVE-2022-20154 CVE-2022-2318 CVE-2022-26365
CVE-2022-29900 CVE-2022-29901 CVE-2022-33740
CVE-2022-33741 CVE-2022-33742 CVE-2022-33981
CVSS scores:
CVE-2020-26541 (NVD) : 6.5 CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H
CVE-2020-26541 (SUSE): 6 CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:N
Get the latest Linux and open source security news straight to your inbox.