gpp_maybe
Security update for the linux kernel (live patch 24 for sle 15)
SUSE-SLE-Module-Live-Patching-15-2021-2057
This update for the Linux Kernel 4.12.14-150_72 fixes several issues. The following security issues were fixed: - CVE-2021-33200: Enforcing incorrect limits for pointer arithmetic operations by the BPF verifier could be abused to perform out-of-bounds reads and writes in kernel memory (bsc#1186484). - CVE-2021-33034: Fixed a use-after-free when destroying an hci_chan. This could lead to writing an arbitrary values (bsc#1186111). - CVE-2021-23134: A Use After Free vulnerability in nfc sockets allowed local attackers to elevate their privileges (bnc#1186060). - CVE-2021-32399: Fixed a race condition when removing the HCI controller (bnc#1184611).
-
Release DateJun 18 2021
-
ReferencesBugzilla: 1185899, 1186061, 1186285, 1186498
CVEs: CVE-2021-33034, CVE-2021-33200, CVE-2021-23134, CVE-2021-32399 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Live Patching 15 ppc64le
-
Packageskernel-livepatch-4_12_14-150_72-default
Kernel live patch modulekernel-livepatch-SLE15_Update_242-2.1 lock rpm
Kernel live patch module2-2.1 lock src
SUSE Linux Enterprise Live Patching 15 x86_64
-
Packageskernel-livepatch-4_12_14-150_72-default
Kernel live patch modulekernel-livepatch-SLE15_Update_242-2.1 lock rpm
Kernel live patch module2-2.1 lock src