Oval Definition:oval:org.opensuse.security:def:118441
Revision Date:2022-03-09Version:1
Title:Security update for the Linux Kernel (Important)
Description:

The SUSE Linux Enterprise 15 SP2 RT kernel was updated to receive various security and bugfixes.



Transient execution side-channel attacks attacking the Branch History Buffer (BHB), named 'Branch Target Injection' and 'Intra-Mode Branch History Injection' are now mitigated.

The following security bugs were fixed:

- CVE-2022-0001: Fixed Branch History Injection vulnerability (bsc#1191580). - CVE-2022-0002: Fixed Intra-Mode Branch Target Injection vulnerability (bsc#1191580). - CVE-2022-0847: Fixed a vulnerability were a local attackers could overwrite data in arbitrary (read-only) files (bsc#1196584).

The following non-security bugs were fixed:

- btrfs: check for missing device in btrfs_trim_fs (bsc#1195701). - lib/iov_iter: initialize 'flags' in new pipe_buffer (bsc#1196584). - nfsd: allow delegation state ids to be revoked and then freed (bsc#1192483). - nfsd: allow open state ids to be revoked and then freed (bsc#1192483). - nfsd: do not admin-revoke NSv4.0 state ids (bsc#1192483). - nfsd: prepare for supporting admin-revocation of state (bsc#1192483). - powerpc/pseries/ddw: Revert 'Extend upper limit for huge DMA window for persistent memory' (bsc#1195995 ltc#196394).
Family:unixClass:patch
Status:Reference(s):1191580
1192483
1195701
1195995
1196584
CVE-2022-0001
CVE-2022-0002
CVE-2022-0847
SUSE-SU-2022:0764-1
Platform(s):SUSE Linux Enterprise Module for Realtime packages 15 SP2
SUSE Linux Enterprise Real Time 15 SP2
Product(s):
Definition Synopsis
  • Release Information
  • SUSE Linux Enterprise Module for Realtime packages 15 SP2 is installed
  • OR SUSE Linux Enterprise Real Time 15 SP2 is installed
  • AND Package Information
  • cluster-md-kmp-rt-5.3.18-76.1 is installed
  • OR dlm-kmp-rt-5.3.18-76.1 is installed
  • OR gfs2-kmp-rt-5.3.18-76.1 is installed
  • OR kernel-devel-rt-5.3.18-76.1 is installed
  • OR kernel-rt-5.3.18-76.1 is installed
  • OR kernel-rt-devel-5.3.18-76.1 is installed
  • OR kernel-rt_debug-5.3.18-76.1 is installed
  • OR kernel-rt_debug-devel-5.3.18-76.1 is installed
  • OR kernel-source-rt-5.3.18-76.1 is installed
  • OR kernel-syms-rt-5.3.18-76.1 is installed
  • OR ocfs2-kmp-rt-5.3.18-76.1 is installed
  • BACK