SUSE: 2020:14354-1 important: the Linux Kernel
Summary
The SUSE Linux Enterprise 11 SP4 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-10942: In get_raw_socket in drivers/vhost/net.c lacks validation of an sk_family field, which might allow attackers to trigger kernel stack corruption via crafted system calls (bsc#1167629). - CVE-2020-8647: There was a use-after-free vulnerability in the vc_do_resize function in drivers/tty/vt/vt.c (bsc#1162929). - CVE-2020-8649: There was a use-after-free vulnerability in the vgacon_invert_region function in drivers/video/console/vgacon.c (bsc#1162931). - CVE-2020-9383: An issue was discovered set_fdc in drivers/block/floppy.c leads to a wait_til_ready out-of-bounds read because the FDC index is not checked for errors before assigning it (bsc#1165111). - CVE-2019-19768: Fixed a use-after-free in the __blk_add_trace function in kernel/trace/blktrace.c (bsc#1159285). - ...
Read the Full AdvisoryReferences
#1012382 #1091041 #1105327 #1131107 #1136471
#1136922 #1146519 #1146544 #1146612 #1148871
#1149448 #1152631 #1156652 #1157038 #1157070
#1157143 #1157155 #1157157 #1157303 #1157344
#1157678 #1157804 #1157923 #1158381 #1158410
#1158413 #1158427 #1158445 #1158823 #1158824
#1158834 #1158900 #1158904 #1159285 #1159841
#1159908 #1159911 #1161358 #1162928 #1162929
#1162931 #1164078 #1165111 #1165985 #1167629
#1168075 #1168829 #1168854
Cross- CVE-2019-12456 CVE-2019-14896 CVE-2019-14897
CVE-2019-15213 CVE-2019-15916 CVE-2019-18660
CVE-2019-18675 CVE-2019-19066 CVE-2019-19073
CVE-2019-19074 CVE-2019-19227 CVE-2019-19523
CVE-2019-19524 CVE-2019-19527 CVE-2019-19530
CVE-2019-19531 CVE-2019-19532 CVE-2019-19537
...
Read the Full Advisory