The SUSE Linux Enterprise 12 SP4 LTSS kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2022-36946: Fixed a denial of service (panic) inside nfqnl_mangle in net/netfilter/nfnetlink_queue.c (bnc#1201940). - CVE-2022-36879: Fixed an issue in xfrm_expand_policies in net/xfrm/xfrm_policy.c where a refcount could be dropped twice (bnc#1201948). - CVE-2022-3028: Fixed race condition that was found in the IP framework for transforming packets (XFRM subsystem) (bnc#1202898). - CVE-2022-2977: Fixed reference counting for struct tpm_chip (bsc#1202672). - CVE-2022-2639: Fixed an integer coercion error that was found in the openvswitch kernel module (bnc#1202154). - CVE-2022-26373: Fixed non-transparent sharing of return predictor
#1172145 #1177440 #1188944 #1191881 #1194535
#1196616 #1200598 #1200770 #1200910 #1201019
#1201420 #1201429 #1201705 #1201726 #1201940
#1201948 #1202096 #1202154 #1202346 #1202347
#1202393 #1202396 #1202672 #1202897 #1202898
#1203098
Cross- CVE-2020-36516 CVE-2020-36557 CVE-2020-36558
CVE-2021-4203 CVE-2022-20166 CVE-2022-20368
CVE-2022-20369 CVE-2022-21385 CVE-2022-2588
CVE-2022-26373 CVE-2022-2639 CVE-2022-2977
CVE-2022-3028 CVE-2022-36879 CVE-2022-36946
CVSS scores:
CVE-2020-36516 (NVD) : 5.9 CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:L
CVE-2020-36516 (SUSE): 8.1 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
CVE-2020-36557 (NVD) : 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
CVE-2020-36557 (SUSE): 7.8...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.