Security update for the Linux Kernel (Live Patch 11 for SLE 15 SP2)
This update for the Linux Kernel 5.3.18-24_52 fixes several issues. The following security issues were fixed: - CVE-2021-3444: Fixed an issue with the bpf verifier which did not properly handle mod32 destination register truncation when the source register was known to be 0 leading to out of bounds read (bsc#1184171). - CVE-2021-28660: Fixed an out of bounds write in rtw_wx_set_scan (bsc#1183658). - CVE-2021-28688: Fixed an issue introduced by XSA-365 (bsc##1182294, bsc#1183646).
02 / AFFECTED SOFTWARE
Affected packages
03 / CONNECTIONS
Connected vulnerabilities
04 / EVIDENCE
Source records
This update for the Linux Kernel 5.3.18-24_52 fixes several issues. The following security issues were fixed: - CVE-2021-3444: Fixed an issue with the bpf verifier which did not properly handle mod32 destination register truncation when the source register was known to be 0 leading to out of bounds read (bsc#1184171). - CVE-2021-28660: Fixed an out of bounds write in rtw_wx_set_scan (bsc#1183658). - CVE-2021-28688: Fixed an issue introduced by XSA-365 (bsc##1182294, bsc#1183646).
05 / REFERENCES
Further evidence
- https://bugzilla.suse.com/1182294
- https://bugzilla.suse.com/1183658
- https://bugzilla.suse.com/1184171
- https://www.suse.com/security/cve/CVE-2021-28660
- https://www.suse.com/security/cve/CVE-2021-28688
- https://www.suse.com/security/cve/CVE-2021-3444
- https://www.suse.com/support/update/announcement/2021/suse-su-20211395-1/