gpp_maybe
Security update for the linux kernel (live patch 24 for sle 15 sp1)
SUSE-SLE-Module-Live-Patching-15-SP1-2021-2043
This update for the Linux Kernel 4.12.14-197_89 fixes several issues. The following issues were fixed: - CVE-2021-33200: Enforcing incorrect limits for pointer arithmetic operations by the BPF verifier could be abused to perform out-of-bounds reads and writes in kernel memory (bsc#1186484). - CVE-2021-33034: Fixed a use-after-free when destroying an hci_chan. This could lead to writing an arbitrary values (bsc#1186111). - CVE-2021-23134: A Use After Free vulnerability in nfc sockets allowed local attackers to elevate their privileges (bnc#1186060). - CVE-2021-32399: Fixed a race condition when removing the HCI controller (bnc#1184611). - Fixed a data loss/data corruption that occurs if there is a write error on an md/raid array (bsc#1185680).
-
Release DateJun 18 2021
-
ReferencesBugzilla: 1185847, 1185899, 1186061, 1186285, 1186498
CVEs: CVE-2021-23134, CVE-2021-32399, CVE-2021-33034, CVE-2021-33200 -
Typesecurity
-
Severityimportant
cloud_download Downloads
SUSE Linux Enterprise Live Patching 15.1 ppc64le
-
Packageskernel-livepatch-4_12_14-197_89-default
Kernel live patch modulekernel-livepatch-SLE15-SP1_Update_242-2.1 lock rpm
Kernel live patch module2-2.1 lock src
SUSE Linux Enterprise Live Patching 15.1 x86_64
-
Packageskernel-livepatch-4_12_14-197_89-default
Kernel live patch modulekernel-livepatch-SLE15-SP1_Update_242-2.1 lock rpm
Kernel live patch module2-2.1 lock src