Alerts This Week
Warning Icon 1 714
Alerts This Week
Warning Icon 1 714

SUSE Linux 11 SP4: Important Security Update on Kernel DoS and Escalation

suse
Calendar Grey January 17, 2024
Dist Suse Esm H88
Significant update deployed for the Linux Kernel addressing multiple security flaws in Red Hat Enterprise Linux.
* bsc#1179610 * bsc#1205762 * bsc#1210778 * bsc#1212051 * bsc#1212703

Summary

## The SUSE Linux Enterprise 11 SP4 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: * CVE-2020-26555: Fixed Bluetooth legacy BR/EDR PIN code pairing in Bluetooth Core Specification 1.0B that may permit an unauthenticated nearby device to spoof the BD_ADDR of the peer device to complete pairing without knowledge of the PIN (bsc#1179610 bsc#1215237). * CVE-2022-45887: Fixed a memory leak in ttusb_dec.c caused by the lack of a dvb_frontend_detach call (bsc#1205762). * CVE-2023-1206: Fixed a hash collision flaw in the IPv6 connection lookup table which could be exploited by network adjacent attackers, increasing CPU usage by 95% (bsc#1212703). * CVE-2023-31085: Fixed a divide-by-zero error in do_div(sz,mtd->erasesize)

References

* bsc#1179610

* bsc#1205762

* bsc#1210778

* bsc#1212051

* bsc#1212703

* bsc#1215237

* bsc#1215858

* bsc#1215860

* bsc#1216046

* bsc#1216058

* bsc#1216976

* bsc#1217947

* bsc#1218253

* bsc#1218559

Cross-

* CVE-2020-26555

* CVE-2022-45887

* CVE-2023-1206

* CVE-2023-31085

* CVE-2023-3111

* CVE-2023-39189

* CVE-2023-39192

* CVE-2023-39193

* CVE-2023-39197

* CVE-2023-45863

* CVE-2023-51779

* CVE-2023-6606

* CVE-2023-6932

CVSS scores:

* CVE-2020-26555 ( SUSE ): 5.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

* CVE-2020-26555 ( NVD ): 5.4 CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

* CVE-2022-45887 ( SUSE ): 4.1 CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:U/C:N/I:N/A:H

* CVE-2022-45887 ( NVD ): 4.7 CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2024:0112-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Your message here