FlawAtlas
Search the atlas
SUSE-SU-2021:0743-1 Not scored

Security update for the Linux Kernel

The SUSE Linux Enterprise 12 SP3 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2021-26930: Fixed an improper error handling in blkback's grant mapping (XSA-365 bsc#1181843). - CVE-2021-26931: Fixed an issue where Linux kernel was treating grant mapping errors as bugs (XSA-362 bsc#1181753). - CVE-2021-26932: Fixed improper error handling issues in Linux grant mapping (XSA-361 bsc#1181747). - CVE-2020-28374: Fixed insufficient identifier checking in the LIO SCSI target code which could have been used by remote attackers to read or write files via directory traversal in an XCOPY request (bsc#178372). The following non-security bugs were fixed: - cifs: report error instead of invalid when revalidating a dentry fails (bsc#1177440). - xen/netback: fix spurious event detection for common event case (bsc#1182175).

Exploit probability Not scored
Published March 9, 2021
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:HPE Helion OpenStack 8 kernel-default
SUSE:HPE Helion OpenStack 8 kernel-source
SUSE:HPE Helion OpenStack 8 kernel-syms
SUSE:HPE Helion OpenStack 8 kgraft-patch-SLE12-SP3_Update_38
SUSE:Linux Enterprise High Availability Extension 12 SP3 kernel-default
SUSE:Linux Enterprise Server 12 SP3-BCL kernel-default
SUSE:Linux Enterprise Server 12 SP3-BCL kernel-source
SUSE:Linux Enterprise Server 12 SP3-BCL kernel-syms
SUSE:Linux Enterprise Server 12 SP3-LTSS kernel-default
SUSE:Linux Enterprise Server 12 SP3-LTSS kernel-source
SUSE:Linux Enterprise Server 12 SP3-LTSS kernel-syms
SUSE:Linux Enterprise Server 12 SP3-LTSS kgraft-patch-SLE12-SP3_Update_38
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 kernel-default
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 kernel-source
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 kernel-syms
SUSE:Linux Enterprise Server for SAP Applications 12 SP3 kgraft-patch-SLE12-SP3_Update_38
SUSE:OpenStack Cloud 8 kernel-default
SUSE:OpenStack Cloud 8 kernel-source
SUSE:OpenStack Cloud 8 kernel-syms
SUSE:OpenStack Cloud 8 kgraft-patch-SLE12-SP3_Update_38
SUSE:OpenStack Cloud Crowbar 8 kernel-default
SUSE:OpenStack Cloud Crowbar 8 kernel-source
SUSE:OpenStack Cloud Crowbar 8 kernel-syms
SUSE:OpenStack Cloud Crowbar 8 kgraft-patch-SLE12-SP3_Update_38

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2021:0743-1

The SUSE Linux Enterprise 12 SP3 kernel was updated to receive various security and bugfixes. The following security bugs were fixed: - CVE-2021-26930: Fixed an improper error handling in blkback's grant mapping (XSA-365 bsc#1181843). - CVE-2021-26931: Fixed an issue where Linux kernel was treating grant mapping errors as bugs (XSA-362 bsc#1181753). - CVE-2021-26932: Fixed improper error handling issues in Linux grant mapping (XSA-361 bsc#1181747). - CVE-2020-28374: Fixed insufficient identifier checking in the LIO SCSI target code which could have been used by remote attackers to read or write files via directory traversal in an XCOPY request (bsc#178372). The following non-security bugs were fixed: - cifs: report error instead of invalid when revalidating a dentry fails (bsc#1177440). - xen/netback: fix spurious event detection for common event case (bsc#1182175).

View original source

05 / REFERENCES

Further evidence