SUSE-SU-2022:2806-1
Dashboard / Vulnerabilities / SUSE-SU-2022:2806-1
SUSE-SU-2022:2806-1
Summary: Security update for open-iscsi
Details: This update for open-iscsi fixes the following issues: Fixed various vulnerabilities in the embedded TCP/IP stack (bsc#1179908): - CVE-2020-13987: Fixed an out of bounds memory access when calculating the checksums for IP packets. - CVE-2020-13988: Fixed an integer overflow when parsing TCP MSS options of IPv4 network packets. - CVE-2020-17437: Fixed an out of bounds memory access when the TCP urgent flag is set.
References: https://www.suse.com/support/update/announcement/2022/suse-su-20222806-1/, https://bugzilla.suse.com/1179908, https://www.suse.com/security/cve/CVE-2020-13987, https://www.suse.com/security/cve/CVE-2020-13988, https://www.suse.com/security/cve/CVE-2020-17437
Affected packages
Package
Name: open-iscsi
Purl: pkg:rpm/suse/open-iscsi&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP3-BCL
Affected ranges
Type: ECOSYSTEM
Events:
