Overly broad permissions can turn one compromised account into a much larger security problem. Learn how to reduce unnecessary access, review privileges, and apply least privilege across modern Linux systems. Review Linux Privileges×

Alerts This Week
Warning Icon 1 524
Alerts This Week
Warning Icon 1 524

SUSE: 2022:2910-1 Important: Critical Kernel Flaws Resolved

suse
Calendar Grey August 26, 2022
Scroller Suse
SUSE Security Patch resolves urgent kernel vulnerabilities, offering solutions for various security weaknesses impacting the infrastructure.
An update that solves 10 vulnerabilities and has 26 fixes is now available

Summary

The SUSE Linux Enterprise 12 SP5 RT kernel was updated to receive various security bugfixes. The following security bugs were fixed: - CVE-2022-2639: Fixed integer underflow that could lead to out-of-bounds write in reserve_sfa_size() (bsc#1202154). - CVE-2020-36516: Fixed TCP session data injection vulnerability via the mixed IPID assignment method (bnc#1196616). - CVE-2022-36946: Fixed an incorrect packet trucation operation which could lead to denial of service (bnc#1201940). - CVE-2022-29581: Fixed improper update of Reference Count in net/sched that could cause root privilege escalation (bnc#1199665). - CVE-2022-20166: Fixed several possible memory safety issues due to unsafe operations (bsc#1200598). - CVE-2020-36558: Fixed a race condition involving VT_RESIZEX which could

References

#1065729 #1103269 #1114648 #1190812 #1195775

#1195926 #1196616 #1196867 #1198484 #1198829

#1199665 #1199695 #1200442 #1200598 #1200644

#1200651 #1200910 #1201019 #1201196 #1201381

#1201429 #1201635 #1201636 #1201644 #1201651

#1201705 #1201742 #1201752 #1201930 #1201940

#1201941 #1201954 #1201958 #1202087 #1202154

#1202312

Cross- CVE-2020-36516 CVE-2020-36557 CVE-2020-36558

CVE-2021-33655 CVE-2021-33656 CVE-2022-1462

CVE-2022-20166 CVE-2022-2639 CVE-2022-29581

CVE-2022-36946

CVSS scores:

CVE-2020-36516 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L

CVE-2020-36516 (SUSE): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

CVE-2020-36557 (NVD) : 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2022:2910-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.