Oval Definition:oval:org.opensuse.security:def:87277
Revision Date:2020-11-23Version:1
Title:Security update for the Linux Kernel (Important)
Description:

The SUSE Linux Enterprise 12 SP3 kernel for Terradata was updated to receive various security and bugfixes.



The following security bugs were fixed:

- CVE-2020-25705: A flaw in the way reply ICMP packets are limited in was found that allowed to quickly scan open UDP ports. This flaw allowed an off-path remote user to effectively bypassing source port UDP randomization. The highest threat from this vulnerability is to confidentiality and possibly integrity, because software and services that rely on UDP source port randomization (like DNS) are indirectly affected as well. Kernel versions may be vulnerable to this issue (bsc#1175721, bsc#1178782). - CVE-2019-6133: In PolicyKit (aka polkit), the 'start time' protection mechanism can be bypassed because fork() is not atomic, and therefore authorization decisions are improperly cached. This is related to lack of uid checking in polkitbackend/polkitbackendinteractiveauthority.c (bsc#1121872). - CVE-2020-25668: Fixed a use-after-free in con_font_op() (bnc#1178123). - CVE-2019-19063: Fixed two memory leaks in the rtl_usb_probe() function in drivers/net/wireless/realtek/rtlwifi/usb.c, which could have allowed an attacker to cause a denial of service (memory consumption) (bsc#1157298).

The following non-security bugs were fixed:

- hv_netvsc: Fix napi reschedule while receive completion is busy (bsc#1118506, bsc#1178821).
Family:unixClass:patch
Status:Reference(s):1118506
1121826
1121872
1157298
1175721
1178123
1178622
1178782
1178821
CVE-2019-19063
CVE-2019-6133
CVE-2020-25668
CVE-2020-25705
Platform(s):SUSE Linux Enterprise Server 12 SP3-TERADATA
Product(s):
BACK