The SUSE Linux Enterprise 15 SP4 kernel was updated. The following security bugs were fixed: - CVE-2022-29900, CVE-2022-29901: Fixed the RETBLEED attack, a new Spectre like Branch Target Buffer attack, that can leak arbitrary kernel information (bsc#1199657). - CVE-2022-34918: Fixed a buffer overflow with nft_set_elem_init() that could be used by a local attacker to escalate privileges (bnc#1201171). - CVE-2021-26341: Some AMD CPUs may transiently execute beyond unconditional direct branches, which may potentially result in data leakage (bsc#1201050). - CVE-2022-20154: Fixed a use after free due to a race condition in lock_sock_nested of sock.c. This could lead to local escalation of privilege with System execution privileges needed (bsc#1200599).
#1055117 #1061840 #1065729 #1071995 #1089644
#1103269 #1118212 #1121726 #1137728 #1156395
#1157038 #1157923 #1175667 #1179439 #1179639
#1180814 #1183682 #1183872 #1184318 #1184924
#1187716 #1188885 #1189998 #1190137 #1190208
#1190336 #1190497 #1190768 #1190786 #1190812
#1191271 #1191663 #1192483 #1193064 #1193277
#1193289 #1193431 #1193556 #1193629 #1193640
#1193787 #1193823 #1193852 #1194086 #1194111
#1194191 #1194409 #1194501 #1194523 #1194526
#1194583 #1194585 #1194586 #1194625 #1194765
#1194826 #1194869 #1195099 #1195287 #1195478
#1195482 #1195504 #1195651 #1195668 #1195669
#1195775 #1195823 #1195826 #1195913 #1195915
#1195926 #1195944 #1195957 #1195987 #1196079
#1196114 #119...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.