FlawAtlas
Search the atlas
SUSE-SU-2020:1713-1 Not scored

Security update for the Linux Kernel

The SUSE Linux Enterprise 12 SP3 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-10768: Fixed an issue with the prctl() function which could have allowed indirect branch speculation even after it has been disabled (bsc#1172783). - CVE-2020-10767: Fixed an issue where the Indirect Branch Prediction Barrier (IBPB) would have been disabled when STIBP is unavailable or enhanced IBRS is available making the system vulnerable to spectre v2 (bsc#1172782). - CVE-2020-10766: Fixed an issue with Linux scheduler which could have allowed an attacker to turn off the SSBD protection (bsc#1172781). - xfs: Fix tail rounding in xfs_alloc_file_space() (bsc#1172049).

Exploit probability Not scored
Published June 23, 2020
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Enterprise Storage 5 kernel-default
SUSE:Enterprise Storage 5 kernel-source
SUSE:Enterprise Storage 5 kernel-syms
SUSE:Enterprise Storage 5 kgraft-patch-SLE12-SP3_Update_33
SUSE:HPE Helion OpenStack 8 kernel-default
SUSE:HPE Helion OpenStack 8 kernel-source
SUSE:HPE Helion OpenStack 8 kernel-syms
SUSE:HPE Helion OpenStack 8 kgraft-patch-SLE12-SP3_Update_33
SUSE:Linux Enterprise High Availability Extension 12 SP3 kernel-default
SUSE:Linux Enterprise Server 12 SP3-BCL kernel-default
SUSE:Linux Enterprise Server 12 SP3-BCL kernel-source
SUSE:Linux Enterprise Server 12 SP3-BCL kernel-syms
SUSE:Linux Enterprise Server 12 SP3-LTSS kernel-default
SUSE:Linux Enterprise Server 12 SP3-LTSS kernel-source
SUSE:Linux Enterprise Server 12 SP3-LTSS kernel-syms
SUSE:Linux Enterprise Server 12 SP3-LTSS kgraft-patch-SLE12-SP3_Update_33
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 kernel-default
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 kernel-source
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 kernel-syms
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 kgraft-patch-SLE12-SP3_Update_33
SUSE:OpenStack Cloud 8 kernel-default
SUSE:OpenStack Cloud 8 kernel-source
SUSE:OpenStack Cloud 8 kernel-syms
SUSE:OpenStack Cloud 8 kgraft-patch-SLE12-SP3_Update_33
SUSE:OpenStack Cloud Crowbar 8 kernel-default
SUSE:OpenStack Cloud Crowbar 8 kernel-source
SUSE:OpenStack Cloud Crowbar 8 kernel-syms
SUSE:OpenStack Cloud Crowbar 8 kgraft-patch-SLE12-SP3_Update_33

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2020:1713-1

The SUSE Linux Enterprise 12 SP3 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-10768: Fixed an issue with the prctl() function which could have allowed indirect branch speculation even after it has been disabled (bsc#1172783). - CVE-2020-10767: Fixed an issue where the Indirect Branch Prediction Barrier (IBPB) would have been disabled when STIBP is unavailable or enhanced IBRS is available making the system vulnerable to spectre v2 (bsc#1172782). - CVE-2020-10766: Fixed an issue with Linux scheduler which could have allowed an attacker to turn off the SSBD protection (bsc#1172781). - xfs: Fix tail rounding in xfs_alloc_file_space() (bsc#1172049).

View original source

05 / REFERENCES

Further evidence