Security update for the Linux Kernel (Live Patch 20 for SLE 15)
This update for the Linux Kernel 4.12.14-150_58 fixes several issues. The following security issues were fixed: - CVE-2021-3444: Fixed an issue with the bpf verifier which did not properly handle mod32 destination register truncation when the source register was known to be 0 leading to out of bounds read (bsc#1184171). - CVE-2021-28688: Fixed an issue introduced by XSA-365 (bsc##1182294, bsc#1183646). - CVE-2021-26930: Fixed an improper error handling in blkback's grant mapping (XSA-365 bsc#1182294). - CVE-2021-26931: Fixed an issue where Linux kernel was treating grant mapping errors as bugs (XSA-362 bsc#1183022).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for the Linux Kernel 4.12.14-150_58 fixes several issues. The following security issues were fixed: - CVE-2021-3444: Fixed an issue with the bpf verifier which did not properly handle mod32 destination register truncation when the source register was known to be 0 leading to out of bounds read (bsc#1184171). - CVE-2021-28688: Fixed an issue introduced by XSA-365 (bsc##1182294, bsc#1183646). - CVE-2021-26930: Fixed an improper error handling in blkback's grant mapping (XSA-365 bsc#1182294). - CVE-2021-26931: Fixed an issue where Linux kernel was treating grant mapping errors as bugs (XSA-362 bsc#1183022).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1182294
- https://bugzilla.suse.com/1184171
- https://www.suse.com/security/cve/CVE-2021-26930
- https://www.suse.com/security/cve/CVE-2021-26931
- https://www.suse.com/security/cve/CVE-2021-28688
- https://www.suse.com/security/cve/CVE-2021-3444
- https://www.suse.com/support/update/announcement/2021/suse-su-20211344-1/