The SUSE Linux Enterprise 12 SP4 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2022-29900, CVE-2022-29901: Fixed the RETBLEED attack, a new Spectre like Branch Target Buffer attack, that can leak arbitrary kernel information (bsc#1199657). - CVE-2022-1679: Fixed a use-after-free in the Atheros wireless driver in the way a user forces the ath9k_htc_wait_for_target function to fail with some input messages (bsc#1199487). - CVE-2022-20132: Fixed out of bounds read due to improper input validation in lg_probe and related functions of hid-lg.c (bsc#1200619). - CVE-2022-33981: Fixed use-after-free in floppy driver (bsc#1200692) - CVE-2022-20141: Fixed a possible use after free due to improper locking in ip_check_mc_rcu() (bsc#1200604).
#1158266 #1162338 #1162369 #1173871 #1177282
#1194013 #1196901 #1198577 #1199426 #1199487
#1199507 #1199657 #1200059 #1200143 #1200144
#1200249 #1200571 #1200599 #1200604 #1200605
#1200608 #1200619 #1200692 #1200762 #1201050
#1201080 #1201251
Cross- CVE-2019-19377 CVE-2020-26541 CVE-2021-26341
CVE-2021-4157 CVE-2022-1184 CVE-2022-1679
CVE-2022-1729 CVE-2022-1974 CVE-2022-1975
CVE-2022-20132 CVE-2022-20141 CVE-2022-20154
CVE-2022-21499 CVE-2022-2318 CVE-2022-26365
CVE-2022-29900 CVE-2022-29901 CVE-2022-33740
CVE-2022-33741 CVE-2022-33742 CVE-2022-33981
CVSS scores:
CVE-2019-19377 (NVD) : 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2019-19377 (SUSE): 7.8 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Get the latest Linux and open source security news straight to your inbox.