Alerts This Week
Warning Icon 1 687
Alerts This Week
Warning Icon 1 687

Stay Secure with the Latest Linux Advisories

Filter Icon Refine advisories
X Clear Filters
X Clear Filters
View More

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Loading...

Explore Latest Linux Security advisories

We found -1 articles for you...
202

openSUSE Leap 15.2: 2020:1282-1 Important: grub2 Kernel Validation Issue

An update that solves one vulnerability and has one errata is now available.. openSUSE Security Update: Security update for grub2 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1282-1 Rating: important References: #1172745 #1174421 Cross-References: CVE-2020-15705 Affected Products: openSUSE Leap 15.2 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for grub2 fixes the following issue: - CVE-2020-15705: Fail kernel validation without shim protocol (bsc#1174421). - Add fibre channel device's ofpath support to grub-ofpathname and search hint to speed up root device discovery (bsc#1172745). This update was imported from the SUSE:SLE-15-SP2:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.2: zypper in -t patch openSUSE-2020-1282=1 Package List: - openSUSE Leap 15.2 (i586 x86_64): grub2-2.04-lp152.7.9.1 grub2-branding-upstream-2.04-lp152.7.9.1 grub2-debuginfo-2.04-lp152.7.9.1 grub2-debugsource-2.04-lp152.7.9.1 - openSUSE Leap 15.2 (noarch): grub2-i386-efi-2.04-lp152.7.9.1 grub2-i386-efi-debug-2.04-lp152.7.9.1 grub2-i386-pc-2.04-lp152.7.9.1 grub2-i386-pc-debug-2.04-lp152.7.9.1 grub2-i386-xen-2.04-lp152.7.9.1 grub2-snapper-plugin-2.04-lp152.7.9.1 grub2-systemd-sleep-plugin-2.04-lp152.7.9.1 grub2-x86_64-efi-2.04-lp152.7.9.1 grub2-x86_64-efi-debug-2.04-lp152.7.9.1 grub2-x86_64-xen-2.04-lp152.7.9.1 References: https://www.suse.com/security/cve/CVE-2020-15705.html https://bugzilla.suse.com/1172745 https://bugzilla.suse.com/1174421 -- . Important revision for Fedora addresses a grub2 problem, enhancing kernel verification and expanding hardware compatibility.. openSUSE Update, grub2 Security Fix, kernel validation issue. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 29, 2020 Important OpenSUSE
202

openSUSE Leap 15.1: 2020:1280-1 Important: grub2 Kernel Validation Fix

An update that solves one vulnerability and has one errata is now available.. openSUSE Security Update: Security update for grub2 ______________________________________________________________________________ Announcement ID: openSUSE-SU-2020:1280-1 Rating: important References: #1172745 #1174421 Cross-References: CVE-2020-15705 Affected Products: openSUSE Leap 15.1 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for grub2 fixes the following issues: - CVE-2020-15705: Fail kernel validation without shim protocol (bsc#1174421). - Add fibre channel device's ofpath support to grub-ofpathname and search hint to speed up root device discovery (bsc#1172745). This update was imported from the SUSE:SLE-15-SP1:Update update project. Patch Instructions: To install this openSUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - openSUSE Leap 15.1: zypper in -t patch openSUSE-2020-1280=1 Package List: - openSUSE Leap 15.1 (i586 x86_64): grub2-2.02-lp151.21.27.1 grub2-branding-upstream-2.02-lp151.21.27.1 grub2-debuginfo-2.02-lp151.21.27.1 grub2-debugsource-2.02-lp151.21.27.1 - openSUSE Leap 15.1 (noarch): grub2-i386-efi-2.02-lp151.21.27.1 grub2-i386-pc-2.02-lp151.21.27.1 grub2-i386-xen-2.02-lp151.21.27.1 grub2-snapper-plugin-2.02-lp151.21.27.1 grub2-systemd-sleep-plugin-2.02-lp151.21.27.1 grub2-x86_64-efi-2.02-lp151.21.27.1 grub2-x86_64-xen-2.02-lp151.21.27.1 References: https://www.suse.com/security/cve/CVE-2020-15705.html https://bugzilla.suse.com/1172745 https://bugzilla.suse.com/1174421 -- . openSUSE has released a security patch for grub2 addressing a severe kernelauthentication vulnerability. Detailed update procedure is provided.. openSUSE Security, grub2 Update, kernel validation fix, security advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 29, 2020 Important OpenSUSE
100

SUSE: 2020:14461-1 Important: Grub2 Kernel Validation Issue

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for grub2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:14461-1 Rating: important References: #1174421 Cross-References: CVE-2020-15705 Affected Products: SUSE Linux Enterprise Server 11-SP4-LTSS SUSE Linux Enterprise Debuginfo 11-SP4 ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for grub2 fixes the following issues: - CVE-2020-15705: Fail kernel validation without shim protocol (bsc#1174421). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server 11-SP4-LTSS: zypper in -t patch slessp4-grub2-14461=1 - SUSE Linux Enterprise Debuginfo 11-SP4: zypper in -t patch dbgsp4-grub2-14461=1 Package List: - SUSE Linux Enterprise Server 11-SP4-LTSS (x86_64): grub2-x86_64-efi-2.00-0.66.21.1 grub2-x86_64-xen-2.00-0.66.21.1 - SUSE Linux Enterprise Debuginfo 11-SP4 (x86_64): grub2-debuginfo-2.00-0.66.21.1 grub2-debugsource-2.00-0.66.21.1 References: https://www.suse.com/security/cve/CVE-2020-15705.html https://bugzilla.suse.com/1174421 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE has released a security update for grub2 to tackle vulnerabilities related to kernel validation. It's crucial to apply this update to ensure the stability and safety of your system.. SUSE Security Update, Grub2, Kernel Validation, Linux Patches. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 25, 2020 Important SuSE
100

SUSE: 2020:2306-1 Important: Grub2 Kernel Validation Issue

An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for grub2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2306-1 Rating: important References: #1172745 #1174421 Cross-References: CVE-2020-15705 Affected Products: SUSE Linux Enterprise Module for Server Applications 15-SP2 SUSE Linux Enterprise Module for Basesystem 15-SP2 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for grub2 fixes the following issue: - CVE-2020-15705: Fail kernel validation without shim protocol (bsc#1174421). - Add fibre channel device's ofpath support to grub-ofpathname and search hint to speed up root device discovery (bsc#1172745). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15-SP2: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP2-2020-2306=1 - SUSE Linux Enterprise Module for Basesystem 15-SP2: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP2-2020-2306=1 Package List: - SUSE Linux Enterprise Module for Server Applications 15-SP2 (noarch): grub2-x86_64-xen-2.04-9.15.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 ppc64le s390x x86_64): grub2-2.04-9.15.1 grub2-debuginfo-2.04-9.15.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (aarch64 s390x x86_64): grub2-debugsource-2.04-9.15.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (noarch): grub2-arm64-efi-2.04-9.15.1 grub2-i386-pc-2.04-9.15.1 grub2-powerpc-ieee1275-2.04-9.15.1 grub2-snapper-plugin-2.04-9.15.1 grub2-systemd-sleep-plugin-2.04-9.15.1 grub2-x86_64-efi-2.04-9.15.1 - SUSE Linux Enterprise Module for Basesystem 15-SP2 (s390x): grub2-s390x-emu-2.04-9.15.1 References: https://www.suse.com/security/cve/CVE-2020-15705.html https://bugzilla.suse.com/1172745 https://bugzilla.suse.com/1174421 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Patch resolves critical vulnerability in grub2 linked to CVE-2020-15705. Instructions for update are provided.. SUSE Security Update, grub2, Kernel Validation Fix, Device Support, Security Advisory. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 25, 2020 Important SuSE
100

SUSE: 2020:2303-1 Important: Grub2 Kernel Validation Issue

An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for grub2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2303-1 Rating: important References: #1172745 #1174421 Cross-References: CVE-2020-15705 Affected Products: SUSE Linux Enterprise Server for SAP 15 SUSE Linux Enterprise Server 15-LTSS SUSE Linux Enterprise High Performance Computing 15-LTSS SUSE Linux Enterprise High Performance Computing 15-ESPOS ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for grub2 fixes the following issues: - CVE-2020-15705: Fail kernel validation without shim protocol (bsc#1174421). - Add fibre channel device's ofpath support to grub-ofpathname and search hint to speed up root device discovery (bsc#1172745). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Server for SAP 15: zypper in -t patch SUSE-SLE-Product-SLES_SAP-15-2020-2303=1 - SUSE Linux Enterprise Server 15-LTSS: zypper in -t patch SUSE-SLE-Product-SLES-15-2020-2303=1 - SUSE Linux Enterprise High Performance Computing 15-LTSS: zypper in -t patch SUSE-SLE-Product-HPC-15-2020-2303=1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS: zypper in -t patch SUSE-SLE-Product-HPC-15-2020-2303=1 Package List: - SUSE Linux Enterprise Server for SAP 15 (ppc64le x86_64): grub2-2.02-19.56.1 grub2-debuginfo-2.02-19.56.1 - SUSE Linux Enterprise Server for SAP 15 (ppc64le): grub2-powerpc-ieee1275-2.02-19.56.1 -SUSE Linux Enterprise Server for SAP 15 (noarch): grub2-snapper-plugin-2.02-19.56.1 grub2-systemd-sleep-plugin-2.02-19.56.1 - SUSE Linux Enterprise Server for SAP 15 (x86_64): grub2-debugsource-2.02-19.56.1 grub2-i386-pc-2.02-19.56.1 grub2-x86_64-efi-2.02-19.56.1 grub2-x86_64-xen-2.02-19.56.1 - SUSE Linux Enterprise Server 15-LTSS (aarch64 s390x): grub2-2.02-19.56.1 grub2-debuginfo-2.02-19.56.1 grub2-debugsource-2.02-19.56.1 - SUSE Linux Enterprise Server 15-LTSS (aarch64): grub2-arm64-efi-2.02-19.56.1 - SUSE Linux Enterprise Server 15-LTSS (noarch): grub2-snapper-plugin-2.02-19.56.1 grub2-systemd-sleep-plugin-2.02-19.56.1 - SUSE Linux Enterprise Server 15-LTSS (s390x): grub2-s390x-emu-2.02-19.56.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (aarch64 x86_64): grub2-2.02-19.56.1 grub2-debuginfo-2.02-19.56.1 grub2-debugsource-2.02-19.56.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (aarch64): grub2-arm64-efi-2.02-19.56.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (noarch): grub2-snapper-plugin-2.02-19.56.1 grub2-systemd-sleep-plugin-2.02-19.56.1 - SUSE Linux Enterprise High Performance Computing 15-LTSS (x86_64): grub2-i386-pc-2.02-19.56.1 grub2-x86_64-efi-2.02-19.56.1 grub2-x86_64-xen-2.02-19.56.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (aarch64 x86_64): grub2-2.02-19.56.1 grub2-debuginfo-2.02-19.56.1 grub2-debugsource-2.02-19.56.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (aarch64): grub2-arm64-efi-2.02-19.56.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (x86_64): grub2-i386-pc-2.02-19.56.1 grub2-x86_64-efi-2.02-19.56.1 grub2-x86_64-xen-2.02-19.56.1 - SUSE Linux Enterprise High Performance Computing 15-ESPOS (noarch): grub2-snapper-plugin-2.02-19.56.1 grub2-systemd-sleep-plugin-2.02-19.56.1 References: https://www.suse.com/security/cve/CVE-2020-15705.html https://bugzilla.suse.com/1172745 https://bugzilla.suse.com/1174421 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE has issued a security update for grub2, addressing a significant kernel validation vulnerability along with improvements in device compatibility.. SUSE Linux Enterprise Server, Security Update, Grub2 Patch, Kernel Validation, Device Support. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 25, 2020 Important SuSE
100

SUSE Linux Enterprise Module: 2020:2307-1 Important: grub2 Kernel Fix

An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for grub2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2307-1 Rating: important References: #1172745 #1174421 Cross-References: CVE-2020-15705 Affected Products: SUSE Linux Enterprise Module for Server Applications 15-SP1 SUSE Linux Enterprise Module for Basesystem 15-SP1 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for grub2 fixes the following issues: - CVE-2020-15705: Fail kernel validation without shim protocol (bsc#1174421). - Add fibre channel device's ofpath support to grub-ofpathname and search hint to speed up root device discovery (bsc#1172745). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE Linux Enterprise Module for Server Applications 15-SP1: zypper in -t patch SUSE-SLE-Module-Server-Applications-15-SP1-2020-2307=1 - SUSE Linux Enterprise Module for Basesystem 15-SP1: zypper in -t patch SUSE-SLE-Module-Basesystem-15-SP1-2020-2307=1 Package List: - SUSE Linux Enterprise Module for Server Applications 15-SP1 (noarch): grub2-x86_64-xen-2.02-26.33.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (aarch64 ppc64le s390x x86_64): grub2-2.02-26.33.1 grub2-debuginfo-2.02-26.33.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (aarch64 s390x x86_64): grub2-debugsource-2.02-26.33.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (noarch): grub2-arm64-efi-2.02-26.33.1 grub2-i386-pc-2.02-26.33.1 grub2-powerpc-ieee1275-2.02-26.33.1 grub2-snapper-plugin-2.02-26.33.1 grub2-systemd-sleep-plugin-2.02-26.33.1 grub2-x86_64-efi-2.02-26.33.1 - SUSE Linux Enterprise Module for Basesystem 15-SP1 (s390x): grub2-s390x-emu-2.02-26.33.1 References: https://www.suse.com/security/cve/CVE-2020-15705.html https://bugzilla.suse.com/1172745 https://bugzilla.suse.com/1174421 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . Critical SUSE Security Patch tackles grub2 vulnerabilities, managing kernel validation flaws and providing guidance on how to apply fixes.. SUSE Update, Grub2 Security, Kernel Fixes, Server Security. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 25, 2020 Important SuSE
100

SUSE: 2020:2308-1 Important: Grub2 Kernel Validation Issue

An update that fixes one vulnerability is now available. . SUSE Security Update: Security update for grub2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2308-1 Rating: important References: #1174421 Cross-References: CVE-2020-15705 Affected Products: SUSE OpenStack Cloud 7 SUSE Linux Enterprise Server for SAP 12-SP2 SUSE Linux Enterprise Server 12-SP2-LTSS SUSE Linux Enterprise Server 12-SP2-BCL ______________________________________________________________________________ An update that fixes one vulnerability is now available. Description: This update for grub2 fixes the following issues: - CVE-2020-15705: Fail kernel validation without shim protocol (bsc#1174421). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud 7: zypper in -t patch SUSE-OpenStack-Cloud-7-2020-2308=1 - SUSE Linux Enterprise Server for SAP 12-SP2: zypper in -t patch SUSE-SLE-SAP-12-SP2-2020-2308=1 - SUSE Linux Enterprise Server 12-SP2-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP2-2020-2308=1 - SUSE Linux Enterprise Server 12-SP2-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP2-BCL-2020-2308=1 Package List: - SUSE OpenStack Cloud 7 (s390x x86_64): grub2-2.02~beta2-115.56.1 grub2-debuginfo-2.02~beta2-115.56.1 grub2-debugsource-2.02~beta2-115.56.1 - SUSE OpenStack Cloud 7 (noarch): grub2-snapper-plugin-2.02~beta2-115.56.1 grub2-systemd-sleep-plugin-2.02~beta2-115.56.1 - SUSE OpenStack Cloud 7 (x86_64): grub2-i386-pc-2.02~beta2-115.56.1 grub2-x86_64-efi-2.02~beta2-115.56.1 grub2-x86_64-xen-2.02~beta2-115.56.1 - SUSE OpenStack Cloud 7 (s390x): grub2-s390x-emu-2.02~beta2-115.56.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le x86_64): grub2-2.02~beta2-115.56.1 grub2-debuginfo-2.02~beta2-115.56.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (ppc64le): grub2-powerpc-ieee1275-2.02~beta2-115.56.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (x86_64): grub2-debugsource-2.02~beta2-115.56.1 grub2-i386-pc-2.02~beta2-115.56.1 grub2-x86_64-efi-2.02~beta2-115.56.1 grub2-x86_64-xen-2.02~beta2-115.56.1 - SUSE Linux Enterprise Server for SAP 12-SP2 (noarch): grub2-snapper-plugin-2.02~beta2-115.56.1 grub2-systemd-sleep-plugin-2.02~beta2-115.56.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le s390x x86_64): grub2-2.02~beta2-115.56.1 grub2-debuginfo-2.02~beta2-115.56.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (s390x x86_64): grub2-debugsource-2.02~beta2-115.56.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (ppc64le): grub2-powerpc-ieee1275-2.02~beta2-115.56.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (x86_64): grub2-i386-pc-2.02~beta2-115.56.1 grub2-x86_64-efi-2.02~beta2-115.56.1 grub2-x86_64-xen-2.02~beta2-115.56.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (noarch): grub2-snapper-plugin-2.02~beta2-115.56.1 grub2-systemd-sleep-plugin-2.02~beta2-115.56.1 - SUSE Linux Enterprise Server 12-SP2-LTSS (s390x): grub2-s390x-emu-2.02~beta2-115.56.1 - SUSE Linux Enterprise Server 12-SP2-BCL (x86_64): grub2-2.02~beta2-115.56.1 grub2-debuginfo-2.02~beta2-115.56.1 grub2-debugsource-2.02~beta2-115.56.1 grub2-i386-pc-2.02~beta2-115.56.1 grub2-x86_64-efi-2.02~beta2-115.56.1 grub2-x86_64-xen-2.02~beta2-115.56.1 - SUSE Linux Enterprise Server 12-SP2-BCL (noarch): grub2-snapper-plugin-2.02~beta2-115.56.1 grub2-systemd-sleep-plugin-2.02~beta2-115.56.1 References: https://www.suse.com/security/cve/CVE-2020-15705.html https://bugzilla.suse.com/1174421 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . SUSE Security Announcement: Critical grub2 patch addressing kernel authentication vulnerability CVE-2020-15705.. SUSE OpenStack, Grub2 Security, Kernel Validation Fix. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 25, 2020 Important SuSE
100

SUSE: 2020:2304-1 Important: grub2 CVE-2020-15705 Kernel Validation Issue

An update that solves one vulnerability and has one errata is now available. . SUSE Security Update: Security update for grub2 ______________________________________________________________________________ Announcement ID: SUSE-SU-2020:2304-1 Rating: important References: #1172745 #1174421 Cross-References: CVE-2020-15705 Affected Products: SUSE OpenStack Cloud Crowbar 8 SUSE OpenStack Cloud 8 SUSE Linux Enterprise Server for SAP 12-SP3 SUSE Linux Enterprise Server 12-SP3-LTSS SUSE Linux Enterprise Server 12-SP3-BCL SUSE Enterprise Storage 5 HPE Helion Openstack 8 ______________________________________________________________________________ An update that solves one vulnerability and has one errata is now available. Description: This update for grub2 fixes the following issues: - CVE-2020-15705: Fail kernel validation without shim protocol (bsc#1174421). - Add fibre channel device's ofpath support to grub-ofpathname and search hint to speed up root device discovery (bsc#1172745). Patch Instructions: To install this SUSE Security Update use the SUSE recommended installation methods like YaST online_update or "zypper patch". Alternatively you can run the command listed for your product: - SUSE OpenStack Cloud Crowbar 8: zypper in -t patch SUSE-OpenStack-Cloud-Crowbar-8-2020-2304=1 - SUSE OpenStack Cloud 8: zypper in -t patch SUSE-OpenStack-Cloud-8-2020-2304=1 - SUSE Linux Enterprise Server for SAP 12-SP3: zypper in -t patch SUSE-SLE-SAP-12-SP3-2020-2304=1 - SUSE Linux Enterprise Server 12-SP3-LTSS: zypper in -t patch SUSE-SLE-SERVER-12-SP3-2020-2304=1 - SUSE Linux Enterprise Server 12-SP3-BCL: zypper in -t patch SUSE-SLE-SERVER-12-SP3-BCL-2020-2304=1 - SUSE Enterprise Storage 5: zypper in -t patch SUSE-Storage-5-2020-2304=1 - HPEHelion Openstack 8: zypper in -t patch HPE-Helion-OpenStack-8-2020-2304=1 Package List: - SUSE OpenStack Cloud Crowbar 8 (x86_64): grub2-2.02-4.61.1 grub2-debuginfo-2.02-4.61.1 grub2-debugsource-2.02-4.61.1 grub2-i386-pc-2.02-4.61.1 grub2-x86_64-efi-2.02-4.61.1 grub2-x86_64-xen-2.02-4.61.1 - SUSE OpenStack Cloud Crowbar 8 (noarch): grub2-snapper-plugin-2.02-4.61.1 grub2-systemd-sleep-plugin-2.02-4.61.1 - SUSE OpenStack Cloud 8 (noarch): grub2-snapper-plugin-2.02-4.61.1 grub2-systemd-sleep-plugin-2.02-4.61.1 - SUSE OpenStack Cloud 8 (x86_64): grub2-2.02-4.61.1 grub2-debuginfo-2.02-4.61.1 grub2-debugsource-2.02-4.61.1 grub2-i386-pc-2.02-4.61.1 grub2-x86_64-efi-2.02-4.61.1 grub2-x86_64-xen-2.02-4.61.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le x86_64): grub2-2.02-4.61.1 grub2-debuginfo-2.02-4.61.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (ppc64le): grub2-powerpc-ieee1275-2.02-4.61.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (noarch): grub2-snapper-plugin-2.02-4.61.1 grub2-systemd-sleep-plugin-2.02-4.61.1 - SUSE Linux Enterprise Server for SAP 12-SP3 (x86_64): grub2-debugsource-2.02-4.61.1 grub2-i386-pc-2.02-4.61.1 grub2-x86_64-efi-2.02-4.61.1 grub2-x86_64-xen-2.02-4.61.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64 ppc64le s390x x86_64): grub2-2.02-4.61.1 grub2-debuginfo-2.02-4.61.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64 s390x x86_64): grub2-debugsource-2.02-4.61.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (aarch64): grub2-arm64-efi-2.02-4.61.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (ppc64le): grub2-powerpc-ieee1275-2.02-4.61.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (x86_64): grub2-i386-pc-2.02-4.61.1 grub2-x86_64-efi-2.02-4.61.1 grub2-x86_64-xen-2.02-4.61.1 - SUSE Linux Enterprise Server12-SP3-LTSS (noarch): grub2-snapper-plugin-2.02-4.61.1 grub2-systemd-sleep-plugin-2.02-4.61.1 - SUSE Linux Enterprise Server 12-SP3-LTSS (s390x): grub2-s390x-emu-2.02-4.61.1 - SUSE Linux Enterprise Server 12-SP3-BCL (x86_64): grub2-2.02-4.61.1 grub2-debuginfo-2.02-4.61.1 grub2-debugsource-2.02-4.61.1 grub2-i386-pc-2.02-4.61.1 grub2-x86_64-efi-2.02-4.61.1 grub2-x86_64-xen-2.02-4.61.1 - SUSE Linux Enterprise Server 12-SP3-BCL (noarch): grub2-snapper-plugin-2.02-4.61.1 grub2-systemd-sleep-plugin-2.02-4.61.1 - SUSE Enterprise Storage 5 (aarch64 x86_64): grub2-2.02-4.61.1 grub2-debuginfo-2.02-4.61.1 grub2-debugsource-2.02-4.61.1 - SUSE Enterprise Storage 5 (aarch64): grub2-arm64-efi-2.02-4.61.1 - SUSE Enterprise Storage 5 (noarch): grub2-snapper-plugin-2.02-4.61.1 grub2-systemd-sleep-plugin-2.02-4.61.1 - SUSE Enterprise Storage 5 (x86_64): grub2-i386-pc-2.02-4.61.1 grub2-x86_64-efi-2.02-4.61.1 grub2-x86_64-xen-2.02-4.61.1 - HPE Helion Openstack 8 (x86_64): grub2-2.02-4.61.1 grub2-debuginfo-2.02-4.61.1 grub2-debugsource-2.02-4.61.1 grub2-i386-pc-2.02-4.61.1 grub2-x86_64-efi-2.02-4.61.1 grub2-x86_64-xen-2.02-4.61.1 - HPE Helion Openstack 8 (noarch): grub2-snapper-plugin-2.02-4.61.1 grub2-systemd-sleep-plugin-2.02-4.61.1 References: https://www.suse.com/security/cve/CVE-2020-15705.html https://bugzilla.suse.com/1172745 https://bugzilla.suse.com/1174421 _______________________________________________ sle-security-updates mailing list This email address is being protected from spambots. You need JavaScript enabled to view it. http://lists.suse.com/mailman/listinfo/sle-security-updates . Fedora Security Patch for kernel addresses severe bootloader vulnerabilities linked to CVE-2021-34529, demanding prompt attention.. SUSE Security Update, grub2 patch, CVE-2020-15705, kernel validation issue, SUSE errata. . Severity: Important. LinuxSecurity.com Team

Calendar 2 Aug 25, 2020 Important SuSE
News Add Esm H240

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Community Poll

What got you started with Linux?

No answer selected. Please try again.
Please select either existing option or enter your own, however not both.
Please select minimum {0} answer(s).
Please select maximum {0} answer(s).
/main-polls/150-what-got-you-started-with-linux?task=poll.vote&format=json
150
radio
0
[{"id":483,"title":"Self-taught through trial and error","votes":546,"type":"x","order":1,"pct":78.45,"resources":[]},{"id":484,"title":"Formal training or courses","votes":30,"type":"x","order":2,"pct":4.31,"resources":[]},{"id":485,"title":"A job that required it","votes":34,"type":"x","order":3,"pct":4.89,"resources":[]},{"id":486,"title":"Other","votes":86,"type":"x","order":4,"pct":12.36,"resources":[]}] ["#ff5b00","#4ac0f2","#b80028","#eef66c","#60bb22","#b96a9a","#62c2cc"] ["rgba(255,91,0,0.7)","rgba(74,192,242,0.7)","rgba(184,0,40,0.7)","rgba(238,246,108,0.7)","rgba(96,187,34,0.7)","rgba(185,106,154,0.7)","rgba(98,194,204,0.7)"] 350
bottom 200
Your message here