FlawAtlas
Search the atlas
SUSE-SU-2021:1724-1 Not scored

Security update for the Linux Kernel (Live Patch 12 for SLE 15 SP1)

This update for the Linux Kernel 4.12.14-197_45 fixes several issues. The following security issues were fixed: - CVE-2020-36322: Fixed an issue inside the FUSE filesystem implementation where fuse_do_getattr() calls make_bad_inode() in inappropriate situations, could have caused a system crash. NOTE: the original fix for this vulnerability was incomplete, and its incompleteness is tracked as CVE-2021-28950 (bsc#1184952). - CVE-2021-29154: Fixed BPF JIT compilers that allowed to execute arbitrary code within the kernel context (bsc#1184710) - Fix system crash on kernfs_kill_sb() as a sysfs superblock's kernfs_super_info node list was NULL (bsc#1183452).

Exploit probability Not scored
Published May 25, 2021
Required by Not available
Last source change February 4, 2026

02 / AFFECTED SOFTWARE

Affected packages

SUSE:Linux Enterprise Live Patching 12 SP5 kgraft-patch-SLE12-SP5_Update_10
SUSE:Linux Enterprise Live Patching 12 SP5 kgraft-patch-SLE12-SP5_Update_11
SUSE:Linux Enterprise Live Patching 12 SP5 kgraft-patch-SLE12-SP5_Update_12
SUSE:Linux Enterprise Live Patching 12 SP5 kgraft-patch-SLE12-SP5_Update_13
SUSE:Linux Enterprise Live Patching 12 SP5 kgraft-patch-SLE12-SP5_Update_14
SUSE:Linux Enterprise Live Patching 12 SP5 kgraft-patch-SLE12-SP5_Update_15
SUSE:Linux Enterprise Live Patching 12 SP5 kgraft-patch-SLE12-SP5_Update_5
SUSE:Linux Enterprise Live Patching 12 SP5 kgraft-patch-SLE12-SP5_Update_6
SUSE:Linux Enterprise Live Patching 12 SP5 kgraft-patch-SLE12-SP5_Update_7
SUSE:Linux Enterprise Live Patching 12 SP5 kgraft-patch-SLE12-SP5_Update_8
SUSE:Linux Enterprise Live Patching 12 SP5 kgraft-patch-SLE12-SP5_Update_9
SUSE:Linux Enterprise Live Patching 15 SP1 kernel-livepatch-SLE15-SP1_Update_12
SUSE:Linux Enterprise Live Patching 15 SP1 kernel-livepatch-SLE15-SP1_Update_13
SUSE:Linux Enterprise Live Patching 15 SP1 kernel-livepatch-SLE15-SP1_Update_14
SUSE:Linux Enterprise Live Patching 15 SP1 kernel-livepatch-SLE15-SP1_Update_15
SUSE:Linux Enterprise Live Patching 15 SP1 kernel-livepatch-SLE15-SP1_Update_16
SUSE:Linux Enterprise Live Patching 15 SP1 kernel-livepatch-SLE15-SP1_Update_17
SUSE:Linux Enterprise Live Patching 15 SP1 kernel-livepatch-SLE15-SP1_Update_18
SUSE:Linux Enterprise Live Patching 15 SP1 kernel-livepatch-SLE15-SP1_Update_19
SUSE:Linux Enterprise Live Patching 15 SP1 kernel-livepatch-SLE15-SP1_Update_20
SUSE:Linux Enterprise Live Patching 15 SP1 kernel-livepatch-SLE15-SP1_Update_21

03 / CONNECTIONS

Connected vulnerabilities

04 / EVIDENCE

Source records

Open Source Vulnerabilities SUSE-SU-2021:1724-1

This update for the Linux Kernel 4.12.14-197_45 fixes several issues. The following security issues were fixed: - CVE-2020-36322: Fixed an issue inside the FUSE filesystem implementation where fuse_do_getattr() calls make_bad_inode() in inappropriate situations, could have caused a system crash. NOTE: the original fix for this vulnerability was incomplete, and its incompleteness is tracked as CVE-2021-28950 (bsc#1184952). - CVE-2021-29154: Fixed BPF JIT compilers that allowed to execute arbitrary code within the kernel context (bsc#1184710) - Fix system crash on kernfs_kill_sb() as a sysfs superblock's kernfs_super_info node list was NULL (bsc#1183452).

View original source

05 / REFERENCES

Further evidence