Revision Date: | 2021-02-10 | Version: | 1 |
Title: | Security update for the Linux Kernel (Live Patch 3 for SLE 15 SP2) (Important) |
Description: |
This update for the Linux Kernel 5.3.18-24_15 fixes several issues.
The following security issues were fixed:
- CVE-2020-29373: Fixed an issue where kernel unsafely handles the root directory during path lookups, and thus a process inside a mount namespace can escape to unintended filesystem locations (bsc#1179779). - CVE-2020-36158: Fixed a potential remote code execution in the Marvell mwifiex driver (bsc#1180562). - CVE-2020-0465: Fixed multiple missing bounds checks in hid-multitouch.c that could have led to local privilege escalation (bnc#1180030). - CVE-2020-0466: Fixed a use-after-free due to a logic error in do_epoll_ctl and ep_loop_check_proc of eventpoll.c (bnc#1180032. - CVE-2020-29569: Fixed a use after free due to a logic error (bsc#1180008). - CVE-2020-29660: Fixed a locking inconsistency in the tty subsystem that may have allowed a read-after-free attack against TIOCGSID (bsc#1179877). - CVE-2020-29661: Fixed a locking issue in the tty subsystem that allowed a use-after-free attack against TIOCSPGRP (bsc#1179877). - CVE-2020-29368: Fixed an issue in copy-on-write implementation which could grant unintended write access because of a race condition in a THP mapcount check (bsc#1179664).
|
Family: | unix | Class: | patch |
Status: | | Reference(s): | 1179664 1179779 1179877 1180008 1180030 1180032 1180562 CVE-2009-0946 CVE-2009-2624 CVE-2009-3235 CVE-2010-0001 CVE-2010-0750 CVE-2010-2497 CVE-2010-2805 CVE-2010-2891 CVE-2010-3053 CVE-2010-3054 CVE-2010-3311 CVE-2010-3430 CVE-2010-3431 CVE-2010-3814 CVE-2010-3853 CVE-2011-0226 CVE-2011-1485 CVE-2011-1526 CVE-2011-2483 CVE-2011-3148 CVE-2011-3149 CVE-2011-3372 CVE-2011-4862 CVE-2012-2738 CVE-2012-2944 CVE-2012-3355 CVE-2012-5668 CVE-2012-5669 CVE-2012-5670 CVE-2013-4288 CVE-2013-6369 CVE-2014-2240 CVE-2014-2583 CVE-2014-3634 CVE-2014-4038 CVE-2014-4039 CVE-2014-5461 CVE-2014-9656 CVE-2014-9657 CVE-2014-9658 CVE-2014-9659 CVE-2014-9660 CVE-2014-9661 CVE-2014-9662 CVE-2014-9663 CVE-2014-9664 CVE-2014-9665 CVE-2014-9666 CVE-2014-9667 CVE-2014-9668 CVE-2014-9669 CVE-2014-9670 CVE-2014-9671 CVE-2014-9672 CVE-2014-9673 CVE-2014-9674 CVE-2014-9675 CVE-2020-0465 CVE-2020-0466 CVE-2020-29368 CVE-2020-29373 CVE-2020-29569 CVE-2020-29660 CVE-2020-29661 CVE-2020-36158 SUSE-SU-2021:0367-1
|
Platform(s): | openSUSE 13.2 openSUSE 13.2 NonFree openSUSE Leap 42.1 SUSE Linux Enterprise Build System Kit 12 SUSE Linux Enterprise Build System Kit 12 SP2 SUSE Linux Enterprise Build System Kit 12 SP3 SUSE Linux Enterprise Build System Kit 12 SP4 SUSE Linux Enterprise Desktop 11 SP2 SUSE Linux Enterprise Desktop 11 SP3 SUSE Linux Enterprise Desktop 11 SP4 SUSE Linux Enterprise Desktop 12 SUSE Linux Enterprise Desktop 12 SP2 SUSE Linux Enterprise Desktop 12 SP3 SUSE Linux Enterprise Desktop 12 SP4 SUSE Linux Enterprise for SAP 11 SP4 SUSE Linux Enterprise High Availability 12 SUSE Linux Enterprise High Performance Computing 15 SP2 SUSE Linux Enterprise Module for Live Patching 15 SP2 SUSE Linux Enterprise Point of Sale 11 SP3 SUSE Linux Enterprise Real Time Extension 11 SP4 SUSE Linux Enterprise Server 11 SUSE Linux Enterprise Server 11 SP2 SUSE Linux Enterprise Server 11 SP3 SUSE Linux Enterprise Server 11 SP3-LTSS SUSE Linux Enterprise Server 11 SP4 SUSE Linux Enterprise Server 11-SECURITY SUSE Linux Enterprise Server 12 SUSE Linux Enterprise Server 12 SP1 SUSE Linux Enterprise Server 12 SP1-LTSS SUSE Linux Enterprise Server 12 SP2 SUSE Linux Enterprise Server 12 SP3 SUSE Linux Enterprise Server 12 SP4 SUSE Linux Enterprise Server 12 SP5 SUSE Linux Enterprise Server 12-LTSS SUSE Linux Enterprise Server 15 SP2 SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 SUSE Linux Enterprise Server for SAP Applications 12 SUSE Linux Enterprise Server for SAP Applications 12 SP1 SUSE Linux Enterprise Server for SAP Applications 12 SP2 SUSE Linux Enterprise Server for SAP Applications 15 SP2 SUSE Linux Enterprise Server for VMWare 11 SP2 SUSE Linux Enterprise Server for VMWare 11 SP3 SUSE Linux Enterprise Software Development Kit 11 SP2 SUSE Linux Enterprise Software Development Kit 11 SP3 SUSE Linux Enterprise Software Development Kit 11 SP4 SUSE Linux Enterprise Software Development Kit 12 SUSE Linux Enterprise Software Development Kit 12 SP2 SUSE Linux Enterprise Software Development Kit 12 SP3 SUSE Linux Enterprise Software Development Kit 12 SP4 SUSE Linux Enterprise Workstation Extension 12 SUSE Linux Enterprise Workstation Extension 12 SP1 SUSE Linux Enterprise Workstation Extension 12 SP2 SUSE Linux Enterprise Workstation Extension 12 SP3 SUSE Linux Enterprise Workstation Extension 12 SP4
| Product(s): | |
Definition Synopsis |
SUSE Linux Enterprise Build System Kit 12 is installed AND Package Information
cups-1.7.5-5 is installed
OR cups-ddk-1.7.5-5 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Build System Kit 12 SP2 is installed
AND Package Information
ghostscript-mini-9.15-17 is installed
OR ghostscript-mini-devel-9.15-17 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Build System Kit 12 SP3 is installed
AND Package Information
libudev-mini-devel-228-150.9 is installed
OR libudev-mini1-228-150.9 is installed
OR systemd-mini-228-150.9 is installed
OR systemd-mini-devel-228-150.9 is installed
OR udev-mini-228-150.9 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Build System Kit 12 SP4 is installed
AND Package Information
libudev-mini-devel-228-150.63 is installed
OR libudev-mini1-228-150.63 is installed
OR systemd-mini-228-150.63 is installed
OR systemd-mini-devel-228-150.63 is installed
OR udev-mini-228-150.63 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 11 SP2 is installed
AND Package Information
MozillaFirefox-17.0.4esr-0.5.1 is installed
OR MozillaFirefox-branding-SLED-7-0.6.9.5 is installed
OR MozillaFirefox-translations-17.0.4esr-0.5.1 is installed
OR beagle-0.3.8-56.51.1 is installed
OR beagle-evolution-0.3.8-56.51.1 is installed
OR beagle-firefox-0.3.8-56.51.1 is installed
OR beagle-gui-0.3.8-56.51.1 is installed
OR beagle-lang-0.3.8-56.51.1 is installed
OR libfreebl3-3.14.2-0.4.3.2 is installed
OR libfreebl3-32bit-3.14.2-0.4.3.2 is installed
OR mhtml-firefox-0.5-1.47.51.5 is installed
OR mozilla-nspr-4.9.5-0.3.2 is installed
OR mozilla-nspr-32bit-4.9.5-0.3.2 is installed
OR mozilla-nss-3.14.2-0.4.3.2 is installed
OR mozilla-nss-32bit-3.14.2-0.4.3.2 is installed
OR mozilla-nss-tools-3.14.2-0.4.3.2 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 11 SP3 is installed
AND a2ps-4.13-1326.37.1 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 11 SP4 is installed
AND Package Information
bind-9.9.6P1-0.15.1 is installed
OR bind-libs-9.9.6P1-0.15.1 is installed
OR bind-libs-32bit-9.9.6P1-0.15.1 is installed
OR bind-utils-9.9.6P1-0.15.1 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 is installed
AND Package Information
ntp-4.2.6p5-31 is installed
OR ntp-doc-4.2.6p5-31 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP2 is installed
AND Package Information
libquicktime-1.2.4-10 is installed
OR libquicktime0-1.2.4-10 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP3 is installed
AND Package Information
libmysqlclient18-10.0.31-29.3 is installed
OR libmysqlclient18-32bit-10.0.31-29.3 is installed
OR libmysqlclient_r18-10.0.31-29.3 is installed
OR libmysqlclient_r18-32bit-10.0.31-29.3 is installed
OR mariadb-10.0.31-29.3 is installed
OR mariadb-client-10.0.31-29.3 is installed
OR mariadb-errormessages-10.0.31-29.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Desktop 12 SP4 is installed
AND Package Information
rhythmbox-3.4-6 is installed
OR rhythmbox-lang-3.4-6 is installed
|
Definition Synopsis |
SUSE Linux Enterprise for SAP 11 SP4 is installed
AND Package Information
compat-openssl097g-0.9.7g-146.22.47.1 is installed
OR compat-openssl097g-32bit-0.9.7g-146.22.47.1 is installed
|
Definition Synopsis |
SUSE Linux Enterprise High Availability 12 is installed
AND Package Information
ctdb-4.2.4-18.30 is installed
OR samba-4.2.4-18.30 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Module for Live Patching 15 SP2 is installed
AND kernel-livepatch-5_3_18-24_15-default-5-2.1 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Point of Sale 11 SP3 is installed
AND apache2-mod_nss-1.0.14-0.4.25.1 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Real Time Extension 11 SP4 is installed
AND Package Information
kernel-rt-3.0.101.rt130-45.1 is installed
OR kernel-rt-base-3.0.101.rt130-45.1 is installed
OR kernel-rt-devel-3.0.101.rt130-45.1 is installed
OR kernel-rt_trace-3.0.101.rt130-45.1 is installed
OR kernel-rt_trace-base-3.0.101.rt130-45.1 is installed
OR kernel-rt_trace-devel-3.0.101.rt130-45.1 is installed
OR kernel-source-rt-3.0.101.rt130-45.1 is installed
OR kernel-syms-rt-3.0.101.rt130-45.1 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 11 is installed
AND Package Information
OpenEXR-1.6.1-83.17.1 is installed
OR OpenEXR-32bit-1.6.1-83.17.1 is installed
OR OpenEXR-x86-1.6.1-83.17.1 is installed
|
Definition Synopsis |
Release Information
SUSE Linux Enterprise Server 11 SP2 is installed
AND
systemtap-1.5-0.9.1 is installed
OR systemtap-server-1.5-0.9.1 is installed
OR Package Information
SUSE Linux Enterprise Server for VMWare 11 SP2 is installed
AND
systemtap-1.5-0.9.1 is installed
OR systemtap-server-1.5-0.9.1 is installed
|
Definition Synopsis |
Release Information
SUSE Linux Enterprise Server 11 SP3 is installed
AND
MozillaFirefox-31.8.0esr-0.13.2 is installed
OR MozillaFirefox-translations-31.8.0esr-0.13.2 is installed
OR Package Information
SUSE Linux Enterprise Server for VMWare 11 SP3 is installed
AND
MozillaFirefox-31.8.0esr-0.13.2 is installed
OR MozillaFirefox-translations-31.8.0esr-0.13.2 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 11 SP3-LTSS is installed
AND Package Information
bind-9.9.6P1-0.30.1 is installed
OR bind-chrootenv-9.9.6P1-0.30.1 is installed
OR bind-doc-9.9.6P1-0.30.1 is installed
OR bind-libs-9.9.6P1-0.30.1 is installed
OR bind-libs-32bit-9.9.6P1-0.30.1 is installed
OR bind-utils-9.9.6P1-0.30.1 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 11 SP4 is installed
AND Package Information
gnome-screensaver-2.28.3-0.39.17 is installed
OR gnome-screensaver-lang-2.28.3-0.39.17 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 11-SECURITY is installed
AND Package Information
libldap-openssl1-2_4-2-2.4.26-0.30.2 is installed
OR libldap-openssl1-2_4-2-32bit-2.4.26-0.30.2 is installed
OR libldap-openssl1-2_4-2-x86-2.4.26-0.30.2 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 is installed
AND Package Information
liblua5_2-5.2.2-4 is installed
OR liblua5_2-32bit-5.2.2-4 is installed
OR lua-5.2.2-4 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP1 is installed
AND ft2demos-2.5.5-7.5 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP1-LTSS is installed
AND Package Information
kgraft-patch-3_12_74-60_64_48-default-2-2.1 is installed
OR kgraft-patch-3_12_74-60_64_48-xen-2-2.1 is installed
OR kgraft-patch-SLE12-SP1_Update_17-2-2.1 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP2 is installed
AND ant-1.9.4-1 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP3 is installed
AND Package Information
apache2-mod_apparmor-2.8.2-49 is installed
OR apparmor-docs-2.8.2-49 is installed
OR apparmor-parser-2.8.2-49 is installed
OR apparmor-profiles-2.8.2-49 is installed
OR apparmor-utils-2.8.2-49 is installed
OR libapparmor1-2.8.2-49 is installed
OR libapparmor1-32bit-2.8.2-49 is installed
OR pam_apparmor-2.8.2-49 is installed
OR pam_apparmor-32bit-2.8.2-49 is installed
OR perl-apparmor-2.8.2-49 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP4 is installed
AND apache2-mod_nss-1.0.14-19.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12 SP5 is installed
AND Package Information
alsa-1.0.27.2-15 is installed
OR alsa-docs-1.0.27.2-15 is installed
OR libasound2-1.0.27.2-15 is installed
OR libasound2-32bit-1.0.27.2-15 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server 12-LTSS is installed
AND Package Information
kgraft-patch-3_12_55-52_45-default-2-2.3 is installed
OR kgraft-patch-3_12_55-52_45-xen-2-2.3 is installed
OR kgraft-patch-SLE12_Update_13-2-2.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server for Raspberry Pi 12 SP2 is installed
AND Package Information
automake-1.13.4-6 is installed
OR m4-1.4.16-15 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server for SAP Applications 12 is installed
AND Package Information
kgraft-patch-3_12_51-52_39-default-4-2 is installed
OR kgraft-patch-3_12_51-52_39-xen-4-2 is installed
OR kgraft-patch-SLE12_Update_11-4-2 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server for SAP Applications 12 SP1 is installed
AND Package Information
openvpn-2.3.8-16.17 is installed
OR openvpn-auth-pam-plugin-2.3.8-16.17 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Server for SAP Applications 12 SP2 is installed
AND Package Information
compat-openssl098-0.9.8j-105 is installed
OR libopenssl0_9_8-0.9.8j-105 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Software Development Kit 11 SP2 is installed
AND Package Information
libldb-devel-3.6.3-0.33.39.1 is installed
OR libnetapi-devel-3.6.3-0.33.39.1 is installed
OR libnetapi0-3.6.3-0.33.39.1 is installed
OR libsmbclient-devel-3.6.3-0.33.39.1 is installed
OR libsmbsharemodes-devel-3.6.3-0.33.39.1 is installed
OR libsmbsharemodes0-3.6.3-0.33.39.1 is installed
OR libtalloc-devel-3.6.3-0.33.39.1 is installed
OR libtdb-devel-3.6.3-0.33.39.1 is installed
OR libtevent-devel-3.6.3-0.33.39.1 is installed
OR libwbclient-devel-3.6.3-0.33.39.1 is installed
OR samba-devel-3.6.3-0.33.39.1 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Software Development Kit 11 SP3 is installed
AND Package Information
ImageMagick-6.4.3.6-7.30.1 is installed
OR ImageMagick-devel-6.4.3.6-7.30.1 is installed
OR libMagick++-devel-6.4.3.6-7.30.1 is installed
OR libMagick++1-6.4.3.6-7.30.1 is installed
OR libMagickWand1-6.4.3.6-7.30.1 is installed
OR libMagickWand1-32bit-6.4.3.6-7.30.1 is installed
OR perl-PerlMagick-6.4.3.6-7.30.1 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Software Development Kit 11 SP4 is installed
AND Package Information
valgrind-3.8.1-0.5.1 is installed
OR valgrind-devel-3.8.1-0.5.1 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Software Development Kit 12 is installed
AND Package Information
file-5.19-9 is installed
OR file-devel-5.19-9 is installed
OR python-magic-5.19-9 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Software Development Kit 12 SP2 is installed
AND Package Information
apparmor-2.8.2-54 is installed
OR libapparmor-devel-2.8.2-54 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Software Development Kit 12 SP3 is installed
AND Package Information
apache2-2.4.23-29.3 is installed
OR apache2-devel-2.4.23-29.3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Software Development Kit 12 SP4 is installed
AND Package Information
libQt5WebKit-private-headers-devel-5.6.2-1 is installed
OR libQt5WebKit5-devel-5.6.2-1 is installed
OR libQt5WebKitWidgets-devel-5.6.2-1 is installed
OR libQt5WebKitWidgets-private-headers-devel-5.6.2-1 is installed
OR libQt5WebKitWidgets5-5.6.2-1 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Workstation Extension 12 is installed
AND gd-32bit-2.1.0-3 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Workstation Extension 12 SP1 is installed
AND Package Information
colord-1.1.7-5 is installed
OR colord-lang-1.1.7-5 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Workstation Extension 12 SP2 is installed
AND bash-lang-4.3-78 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Workstation Extension 12 SP3 is installed
AND drm-kmp-default-4.9.33_k4.4.73_5-2 is installed
|
Definition Synopsis |
SUSE Linux Enterprise Workstation Extension 12 SP4 is installed
AND bash-lang-4.3-83.15 is installed
|