Security update for the Linux Kernel
The SUSE Linux Enterprise 12 SP2 kernel was updated to to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-14314: Fixed a potential negative array index in do_split() (bsc#1173798). - CVE-2020-14331: Fixed a missing check in vgacon scrollback handling (bsc#1174205). - CVE-2020-16166: Fixed a potential issue which could have allowed remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG (bsc#1174757). - CVE-2019-16746: Fixed an improper check of the length of variable elements in a beacon head, leading to a buffer overflow (bsc#1152107). - CVE-2020-14386: Fixed a potential local privilege escalation via memory corruption (bsc#1176069). The following non-security bug was fixed: - mm, vmstat: reduce zone->lock holding time by /proc/pagetypeinfo (bsc#1175691).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
The SUSE Linux Enterprise 12 SP2 kernel was updated to to receive various security and bugfixes. The following security bugs were fixed: - CVE-2020-14314: Fixed a potential negative array index in do_split() (bsc#1173798). - CVE-2020-14331: Fixed a missing check in vgacon scrollback handling (bsc#1174205). - CVE-2020-16166: Fixed a potential issue which could have allowed remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG (bsc#1174757). - CVE-2019-16746: Fixed an improper check of the length of variable elements in a beacon head, leading to a buffer overflow (bsc#1152107). - CVE-2020-14386: Fixed a potential local privilege escalation via memory corruption (bsc#1176069). The following non-security bug was fixed: - mm, vmstat: reduce zone->lock holding time by /proc/pagetypeinfo (bsc#1175691).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1152107
- https://bugzilla.suse.com/1173798
- https://bugzilla.suse.com/1174205
- https://bugzilla.suse.com/1174757
- https://bugzilla.suse.com/1175691
- https://bugzilla.suse.com/1176069
- https://www.suse.com/security/cve/CVE-2019-16746
- https://www.suse.com/security/cve/CVE-2020-14314
- https://www.suse.com/security/cve/CVE-2020-14331
- https://www.suse.com/security/cve/CVE-2020-14386
- https://www.suse.com/security/cve/CVE-2020-16166
- https://www.suse.com/support/update/announcement/2020/suse-su-20202576-1/