SUSE-SU-2021:2409-1
Dashboard / Vulnerabilities / SUSE-SU-2021:2409-1
SUSE-SU-2021:2409-1
Summary: Security update for the Linux Kernel
Details: The SUSE Linux Enterprise 15 SP3 Azure kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2021-22555: A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c (bnc#1188116 ). - CVE-2021-33909: Fixed an out-of-bounds write in the filesystem layer that allows to obtain full root privileges (bsc#1188062). The following non-security bugs were fixed: - ceph: must hold snap_rwsem when filling inode for async create (bsc#1187927). - cgroup1: do not allow '\n' in renaming (bsc#1187972). - qla2xxx: synchronize rport dev_loss_tmo setting (bsc#1182470 bsc#1185486). - scsi: ufs: ufshcd-pltfrm depends on HAS_IOMEM (bsc#1187980). - usb: dwc3: Fix debugfs creation flow (git-fixes). - x86/pkru: Write hardware init value to PKRU when xstate is init (bsc#1152489). - x86/process: Check PF_KTHREAD and not current->mm for kernel threads (bsc#1152489).
References: https://www.suse.com/support/update/announcement/2021/suse-su-20212409-1/, https://bugzilla.suse.com/1152489, https://bugzilla.suse.com/1182470, https://bugzilla.suse.com/1185486, https://bugzilla.suse.com/1187927, https://bugzilla.suse.com/1187972, https://bugzilla.suse.com/1187980, https://bugzilla.suse.com/1188062, https://bugzilla.suse.com/1188116, https://www.suse.com/security/cve/CVE-2021-22555, https://www.suse.com/security/cve/CVE-2021-33909
Affected packages
Package
Name: kernel-azure
Purl: pkg:rpm/suse/kernel-azure&distro=SUSE%20Linux%20Enterprise%20Module%20for%20Public%20Cloud%2015%20SP3
Affected ranges
Type: ECOSYSTEM
Events:
