SUSE SLES12: cluster-md-kmp-rt / dlm-kmp-rt / gfs2-kmp-rt / kernel-devel-rt / etc (SUSE-SU-2021:2349-1)

high Nessus Plugin ID 151658

Language:

Synopsis

The remote SUSE host is missing one or more security updates.

Description

The remote SUSE Linux SLES12 host has packages installed that are affected by multiple vulnerabilities as referenced in the SUSE-SU-2021:2349-1 advisory.

The SUSE Linux Enterprise 12 SP5 kernel was updated to receive various security and bugfixes.

The following security bugs were fixed:

- CVE-2021-33624: Fixed a bug which allows unprivileged BPF program to leak the contents of arbitrary kernel memory (and therefore, of all physical memory) via a side-channel. (bsc#1187554)
- CVE-2019-25045: Fixed an use-after-free issue in the Linux kernel The XFRM subsystem, related to an xfrm_state_fini panic. (bsc#1187049)
- CVE-2021-0605: Fixed an out-of-bounds read which could lead to local information disclosure in the kernel with System execution privileges needed. (bsc#1187601)
- CVE-2021-0512: Fixed a possible out-of-bounds write which could lead to local escalation of privilege with no additional execution privileges needed. (bsc#1187595)
- CVE-2020-26558: Fixed a flaw in the Bluetooth LE and BR/EDR secure pairing that could permit a nearby man-in-the-middle attacker to identify the Passkey used during pairing. (bsc#1179610)
- CVE-2021-34693: Fixed a bug in net/can/bcm.c which could allow local users to obtain sensitive information from kernel stack memory because parts of a data structure are uninitialized. (bsc#1187452)
- CVE-2021-0129: Fixed an improper access control in BlueZ that may have allowed an authenticated user to potentially enable information disclosure via adjacent access. (bsc#1186463)
- CVE-2020-36386: Fixed an out-of-bounds read in hci_extended_inquiry_result_evt. (bsc#1187038)
- CVE-2020-24588: Fixed a bug that could allow an adversary to abuse devices that support receiving non- SSP A-MSDU frames to inject arbitrary network packets. (bsc#1185861)


Tenable has extracted the preceding description block directly from the SUSE security advisory.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Update the affected packages.

See Also

https://bugzilla.suse.com/1103990

https://bugzilla.suse.com/1103991

https://bugzilla.suse.com/1104353

https://bugzilla.suse.com/1113994

https://bugzilla.suse.com/1114648

https://bugzilla.suse.com/1129770

https://bugzilla.suse.com/1135481

https://bugzilla.suse.com/1136345

https://bugzilla.suse.com/1174978

https://bugzilla.suse.com/1179610

https://bugzilla.suse.com/1182470

https://bugzilla.suse.com/1184040

https://bugzilla.suse.com/1185428

https://bugzilla.suse.com/1185486

https://bugzilla.suse.com/1185677

https://bugzilla.suse.com/1185701

https://bugzilla.suse.com/1185861

https://bugzilla.suse.com/1185863

https://bugzilla.suse.com/1186206

https://bugzilla.suse.com/1186264

https://bugzilla.suse.com/1186463

https://bugzilla.suse.com/1186515

https://bugzilla.suse.com/1186516

https://bugzilla.suse.com/1186517

https://bugzilla.suse.com/1186518

https://bugzilla.suse.com/1186519

https://bugzilla.suse.com/1186520

https://bugzilla.suse.com/1186521

https://bugzilla.suse.com/1186522

https://bugzilla.suse.com/1186523

https://bugzilla.suse.com/1186524

https://bugzilla.suse.com/1186525

https://bugzilla.suse.com/1186526

https://bugzilla.suse.com/1186527

https://bugzilla.suse.com/1186528

https://bugzilla.suse.com/1186529

https://bugzilla.suse.com/1186530

https://bugzilla.suse.com/1186531

https://bugzilla.suse.com/1186532

https://bugzilla.suse.com/1186533

https://bugzilla.suse.com/1186534

https://bugzilla.suse.com/1186535

https://bugzilla.suse.com/1186537

https://bugzilla.suse.com/1186538

https://bugzilla.suse.com/1186539

https://bugzilla.suse.com/1186540

https://bugzilla.suse.com/1186541

https://bugzilla.suse.com/1186542

https://bugzilla.suse.com/1186543

https://bugzilla.suse.com/1186545

https://bugzilla.suse.com/1186546

https://bugzilla.suse.com/1186547

https://bugzilla.suse.com/1186548

https://bugzilla.suse.com/1186549

https://bugzilla.suse.com/1186550

https://bugzilla.suse.com/1186551

https://bugzilla.suse.com/1186552

https://bugzilla.suse.com/1186554

https://bugzilla.suse.com/1186555

https://bugzilla.suse.com/1186556

https://bugzilla.suse.com/1186627

https://bugzilla.suse.com/1186635

https://bugzilla.suse.com/1186638

https://bugzilla.suse.com/1186698

https://bugzilla.suse.com/1186699

https://bugzilla.suse.com/1186700

https://bugzilla.suse.com/1186701

https://bugzilla.suse.com/1187038

https://bugzilla.suse.com/1187049

https://bugzilla.suse.com/1187402

https://bugzilla.suse.com/1187404

https://bugzilla.suse.com/1187407

https://bugzilla.suse.com/1187408

https://bugzilla.suse.com/1187409

https://bugzilla.suse.com/1187411

https://bugzilla.suse.com/1187412

https://bugzilla.suse.com/1187452

https://bugzilla.suse.com/1187453

https://bugzilla.suse.com/1187455

https://bugzilla.suse.com/1187554

https://bugzilla.suse.com/1187595

https://bugzilla.suse.com/1187601

https://bugzilla.suse.com/1187630

https://bugzilla.suse.com/1187631

https://bugzilla.suse.com/1187833

https://bugzilla.suse.com/1187867

https://bugzilla.suse.com/1187972

https://bugzilla.suse.com/1188010

https://www.suse.com/security/cve/CVE-2019-25045

https://www.suse.com/security/cve/CVE-2020-24588

https://www.suse.com/security/cve/CVE-2020-26558

https://www.suse.com/security/cve/CVE-2020-36386

https://www.suse.com/security/cve/CVE-2021-0129

https://www.suse.com/security/cve/CVE-2021-0512

https://www.suse.com/security/cve/CVE-2021-0605

https://www.suse.com/security/cve/CVE-2021-33624

https://www.suse.com/security/cve/CVE-2021-34693

http://www.nessus.org/u?e51cb895

Plugin Details

Severity: High

ID: 151658

File Name: suse_SU-2021-2349-1.nasl

Version: 1.7

Type: Local

Agent: unix

Published: 7/15/2021

Updated: 6/25/2026

Supported Sensors: Frictionless Assessment AWS, Frictionless Assessment Azure, Frictionless Assessment Agent, Nessus Agent, Agentless Assessment, Continuous Assessment, Tenable Cloud Security, Tenable Self-Hosted Container Security, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.3

Percentile: 97.25

CVSS v2

Risk Factor: Medium

Base Score: 5.6

Temporal Score: 4.4

Vector: CVSS2#AV:L/AC:L/Au:N/C:P/I:N/A:C

CVSS Score Source: CVE-2020-36386

CVSS v3

Risk Factor: High

Base Score: 7.8

Temporal Score: 7

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

CVSS Score Source: CVE-2021-0512

Vulnerability Information

CPE: p-cpe:/a:novell:suse_linux:dlm-kmp-rt, p-cpe:/a:novell:suse_linux:kernel-rt-devel, p-cpe:/a:novell:suse_linux:kernel-source-rt, cpe:/o:novell:suse_linux:12, p-cpe:/a:novell:suse_linux:kernel-rt-base, p-cpe:/a:novell:suse_linux:gfs2-kmp-rt, p-cpe:/a:novell:suse_linux:kernel-syms-rt, p-cpe:/a:novell:suse_linux:cluster-md-kmp-rt, p-cpe:/a:novell:suse_linux:kernel-rt_debug-devel, p-cpe:/a:novell:suse_linux:kernel-rt_debug, p-cpe:/a:novell:suse_linux:kernel-rt, p-cpe:/a:novell:suse_linux:ocfs2-kmp-rt, p-cpe:/a:novell:suse_linux:kernel-devel-rt

Required KB Items: Host/local_checks_enabled, Host/cpu, Host/SuSE/release, Host/SuSE/rpm-list

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 7/14/2021

Vulnerability Publication Date: 5/11/2021

Reference Information

CVE: CVE-2019-25045, CVE-2020-24588, CVE-2020-26558, CVE-2020-36386, CVE-2021-0129, CVE-2021-0512, CVE-2021-0605, CVE-2021-33624, CVE-2021-34693

SuSE: SUSE-SU-2021:2349-1