SUSE-SU-2021:4021-1
Dashboard / Vulnerabilities / SUSE-SU-2021:4021-1
SUSE-SU-2021:4021-1
Summary: Security update for the Linux Kernel (Live Patch 25 for SLE 12 SP5)
Details: This update for the Linux Kernel 4.12.14-122_98 fixes several issues. The following security issues were fixed: - CVE-2021-0941: In bpf_skb_change_head of filter.c, there is a possible out of bounds read due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation (bnc#1192045). - CVE-2021-20322: Make the ipv4 and ipv6 ICMP exception caches less predictive to avoid information leaks about UDP ports in use. (bsc#1191790) - CVE-2021-0935: In ip6_xmit of ip6_output.c, there is a possible out of bounds write due to a use after free. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. (bsc#1192032)
References: https://www.suse.com/support/update/announcement/2021/suse-su-20214021-1/, https://bugzilla.suse.com/1191813, https://bugzilla.suse.com/1192042, https://bugzilla.suse.com/1192048, https://www.suse.com/security/cve/CVE-2021-0935, https://www.suse.com/security/cve/CVE-2021-0941, https://www.suse.com/security/cve/CVE-2021-20322
Affected packages
Package
Name: kgraft-patch-SLE12-SP5_Update_25
Purl: pkg:rpm/suse/kgraft-patch-SLE12-SP5_Update_25&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012%20SP5
Affected ranges
Type: ECOSYSTEM
Events:
