{"schema_version":"1.7.3","id":"SUSE-SU-2020:2623-1","published":"2020-09-14T11:53:34Z","modified":"2026-02-04T02:39:00.441659Z","related":["CVE-2020-10135","CVE-2020-14314","CVE-2020-14331","CVE-2020-14356","CVE-2020-14386","CVE-2020-16166","CVE-2020-1749","CVE-2020-24394"],"upstream":["CVE-2020-10135","CVE-2020-14314","CVE-2020-14331","CVE-2020-14356","CVE-2020-14386","CVE-2020-16166","CVE-2020-1749","CVE-2020-24394"],"summary":"Security update for the Linux Kernel","details":"The SUSE Linux Enterprise 12 SP4 kernel was updated to receive various security and bugfixes.\n\nThe following security bugs were fixed:\n\n- CVE-2020-1749: Use ip6_dst_lookup_flow instead of ip6_dst_lookup (bsc#1165629).\n- CVE-2020-14314: Fixed a potential negative array index in do_split() (bsc#1173798).\n- CVE-2020-14356: Fixed a null pointer dereference in cgroupv2 subsystem which could have led to privilege escalation (bsc#1175213).\n- CVE-2020-14331: Fixed a missing check in vgacon scrollback handling (bsc#1174205).\n- CVE-2020-16166: Fixed a potential issue which could have allowed remote attackers to make observations that help to obtain sensitive information about the internal state of the network RNG (bsc#1174757).\n- CVE-2020-24394: Fixed an issue which could set incorrect permissions on new filesystem objects when the filesystem lacks ACL support (bsc#1175518).\n- CVE-2020-10135: Legacy pairing and secure-connections pairing authentication Bluetooth might have allowed an unauthenticated user to complete authentication without pairing credentials via adjacent access (bsc#1171988).\n- CVE-2020-14386: Fixed a potential local privilege escalation via memory corruption (bsc#1176069).\n\nThe following non-security bugs were fixed:\n\n- btrfs: remove a BUG_ON() from merge_reloc_roots() (bsc#1174784).\n- cifs: document and cleanup dfs mount (bsc#1144333 bsc#1172428).\n- cifs: Fix an error pointer dereference in cifs_mount() (bsc#1144333 bsc#1172428).\n- cifs: fix double free error on share and prefix (bsc#1144333 bsc#1172428).\n- cifs: handle empty list of targets in cifs_reconnect() (bsc#1144333 bsc#1172428).\n- cifs: handle RESP_GET_DFS_REFERRAL.PathConsumed in reconnect (bsc#1144333 bsc#1172428).\n- cifs: merge __{cifs,smb2}_reconnect[_tcon]() into cifs_tree_connect() (bsc#1144333 bsc#1172428).\n- cifs: only update prefix path of DFS links in cifs_tree_connect() (bsc#1144333 bsc#1172428).\n- cifs: reduce number of referral requests in DFS link lookups (bsc#1144333 bsc#1172428).\n- cifs: rename reconn_inval_dfs_target() (bsc#1144333 bsc#1172428).\n- Drivers: hv: vmbus: Only notify Hyper-V for die events that are oops (bsc#1175127).\n- ibmvnic: Fix IRQ mapping disposal in error path (bsc#1175112 ltc#187459).\n- ip6_tunnel: allow not to count pkts on tstats by passing dev as NULL (bsc#1175515).\n- ip_tunnel: allow not to count pkts on tstats by setting skb's dev to NULL (bsc#1175515).\n- ipvs: fix the connection sync failed in some cases (bsc#1174699).\n- kabi: hide new parameter of ip6_dst_lookup_flow() (bsc#1165629).\n- kabi: mask changes to struct ipv6_stub (bsc#1165629).\n- mm: Avoid calling build_all_zonelists_init under hotplug context (bsc#1154366).\n- mm, vmstat: reduce zone->lock holding time by /proc/pagetypeinfo (bsc#1175691).\n- ocfs2: add trimfs dlm lock resource (bsc#1175228).\n- ocfs2: add trimfs lock to avoid duplicated trims in cluster (bsc#1175228).\n- ocfs2: avoid inode removal while nfsd is accessing it (bsc#1172963).\n- ocfs2: avoid inode removal while nfsd is accessing it (bsc#1172963).\n- ocfs2: fix panic on nfs server over ocfs2 (bsc#1172963).\n- ocfs2: fix panic on nfs server over ocfs2 (bsc#1172963).\n- ocfs2: fix remounting needed after setfacl command (bsc#1173954).\n- ocfs2: fix the application IO timeout when fstrim is running (bsc#1175228).\n- ocfs2: load global_inode_alloc (bsc#1172963).\n- ocfs2: load global_inode_alloc (bsc#1172963).\n- powerpc/eeh: Fix pseries_eeh_configure_bridge() (bsc#1174689).\n- powerpc/pseries: PCIE PHB reset (bsc#1174689).\n- Revert 'ocfs2: fix panic on nfs server over ocfs2 (bsc#1172963).' This reverts commit 2638f62c6bc33d4c10ce0dddbf240aa80d366d7b.\n- Revert 'ocfs2: load global_inode_alloc (bsc#1172963).' This reverts commit f04f670651f505cb354f26601ec5f5e4428f2f47.\n- scsi: scsi_dh_alua: skip RTPG for devices only supporting active/optimized (bsc#1174978). \n- selftests/livepatch: fix mem leaks in test-klp-shadow-vars (bsc#1071995).\n- selftests/livepatch: more verification in test-klp-shadow-vars (bsc#1071995).\n- selftests/livepatch: rework test-klp-shadow-vars (bsc#1071995).\n- selftests/livepatch: simplify test-klp-callbacks busy target tests (bsc#1071995).\n- Update patch reference for a tipc fix patch (bsc#1175515)\n- x86/unwind/orc: Fix ORC for newly forked tasks (bsc#1058115).\n- xen: do not reschedule in preemption off sections (bsc#1175749).\n","affected":[{"package":{"name":"kernel-default","ecosystem":"SUSE:OpenStack Cloud 9","purl":"pkg:rpm/suse/kernel-default&distro=SUSE%20OpenStack%20Cloud%209"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.60.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.60.1","kernel-default-base":"4.12.14-95.60.1","kernel-default-devel":"4.12.14-95.60.1","kernel-devel":"4.12.14-95.60.1","kernel-macros":"4.12.14-95.60.1","kernel-source":"4.12.14-95.60.1","kernel-syms":"4.12.14-95.60.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2623-1.json"}},{"package":{"name":"kernel-source","ecosystem":"SUSE:OpenStack Cloud 9","purl":"pkg:rpm/suse/kernel-source&distro=SUSE%20OpenStack%20Cloud%209"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.60.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.60.1","kernel-default-base":"4.12.14-95.60.1","kernel-default-devel":"4.12.14-95.60.1","kernel-devel":"4.12.14-95.60.1","kernel-macros":"4.12.14-95.60.1","kernel-source":"4.12.14-95.60.1","kernel-syms":"4.12.14-95.60.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2623-1.json"}},{"package":{"name":"kernel-syms","ecosystem":"SUSE:OpenStack Cloud 9","purl":"pkg:rpm/suse/kernel-syms&distro=SUSE%20OpenStack%20Cloud%209"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.60.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.60.1","kernel-default-base":"4.12.14-95.60.1","kernel-default-devel":"4.12.14-95.60.1","kernel-devel":"4.12.14-95.60.1","kernel-macros":"4.12.14-95.60.1","kernel-source":"4.12.14-95.60.1","kernel-syms":"4.12.14-95.60.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2623-1.json"}},{"package":{"name":"kernel-default","ecosystem":"SUSE:OpenStack Cloud Crowbar 9","purl":"pkg:rpm/suse/kernel-default&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.60.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.60.1","kernel-default-base":"4.12.14-95.60.1","kernel-default-devel":"4.12.14-95.60.1","kernel-devel":"4.12.14-95.60.1","kernel-macros":"4.12.14-95.60.1","kernel-source":"4.12.14-95.60.1","kernel-syms":"4.12.14-95.60.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2623-1.json"}},{"package":{"name":"kernel-source","ecosystem":"SUSE:OpenStack Cloud Crowbar 9","purl":"pkg:rpm/suse/kernel-source&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.60.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.60.1","kernel-default-base":"4.12.14-95.60.1","kernel-default-devel":"4.12.14-95.60.1","kernel-devel":"4.12.14-95.60.1","kernel-macros":"4.12.14-95.60.1","kernel-source":"4.12.14-95.60.1","kernel-syms":"4.12.14-95.60.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2623-1.json"}},{"package":{"name":"kernel-syms","ecosystem":"SUSE:OpenStack Cloud Crowbar 9","purl":"pkg:rpm/suse/kernel-syms&distro=SUSE%20OpenStack%20Cloud%20Crowbar%209"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.60.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.60.1","kernel-default-base":"4.12.14-95.60.1","kernel-default-devel":"4.12.14-95.60.1","kernel-devel":"4.12.14-95.60.1","kernel-macros":"4.12.14-95.60.1","kernel-source":"4.12.14-95.60.1","kernel-syms":"4.12.14-95.60.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2623-1.json"}},{"package":{"name":"kernel-default","ecosystem":"SUSE:Linux Enterprise High Availability Extension 12 SP4","purl":"pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20High%20Availability%20Extension%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.60.1"}]}],"ecosystem_specific":{"binaries":[{"cluster-md-kmp-default":"4.12.14-95.60.1","dlm-kmp-default":"4.12.14-95.60.1","gfs2-kmp-default":"4.12.14-95.60.1","ocfs2-kmp-default":"4.12.14-95.60.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2623-1.json"}},{"package":{"name":"kernel-default","ecosystem":"SUSE:Linux Enterprise Live Patching 12 SP4","purl":"pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.60.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default-kgraft":"4.12.14-95.60.1","kernel-default-kgraft-devel":"4.12.14-95.60.1","kgraft-patch-4_12_14-95_60-default":"1-6.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2623-1.json"}},{"package":{"name":"kgraft-patch-SLE12-SP4_Update_16","ecosystem":"SUSE:Linux Enterprise Live Patching 12 SP4","purl":"pkg:rpm/suse/kgraft-patch-SLE12-SP4_Update_16&distro=SUSE%20Linux%20Enterprise%20Live%20Patching%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1-6.3.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default-kgraft":"4.12.14-95.60.1","kernel-default-kgraft-devel":"4.12.14-95.60.1","kgraft-patch-4_12_14-95_60-default":"1-6.3.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2623-1.json"}},{"package":{"name":"kernel-default","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP4","purl":"pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.60.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.60.1","kernel-default-base":"4.12.14-95.60.1","kernel-default-devel":"4.12.14-95.60.1","kernel-devel":"4.12.14-95.60.1","kernel-macros":"4.12.14-95.60.1","kernel-source":"4.12.14-95.60.1","kernel-syms":"4.12.14-95.60.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2623-1.json"}},{"package":{"name":"kernel-source","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP4","purl":"pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.60.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.60.1","kernel-default-base":"4.12.14-95.60.1","kernel-default-devel":"4.12.14-95.60.1","kernel-devel":"4.12.14-95.60.1","kernel-macros":"4.12.14-95.60.1","kernel-source":"4.12.14-95.60.1","kernel-syms":"4.12.14-95.60.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2623-1.json"}},{"package":{"name":"kernel-syms","ecosystem":"SUSE:Linux Enterprise Server for SAP Applications 12 SP4","purl":"pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%20for%20SAP%20Applications%2012%20SP4"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.60.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.60.1","kernel-default-base":"4.12.14-95.60.1","kernel-default-devel":"4.12.14-95.60.1","kernel-devel":"4.12.14-95.60.1","kernel-macros":"4.12.14-95.60.1","kernel-source":"4.12.14-95.60.1","kernel-syms":"4.12.14-95.60.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2623-1.json"}},{"package":{"name":"kernel-default","ecosystem":"SUSE:Linux Enterprise Server 12 SP4-LTSS","purl":"pkg:rpm/suse/kernel-default&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.60.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.60.1","kernel-default-base":"4.12.14-95.60.1","kernel-default-devel":"4.12.14-95.60.1","kernel-default-man":"4.12.14-95.60.1","kernel-devel":"4.12.14-95.60.1","kernel-macros":"4.12.14-95.60.1","kernel-source":"4.12.14-95.60.1","kernel-syms":"4.12.14-95.60.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2623-1.json"}},{"package":{"name":"kernel-source","ecosystem":"SUSE:Linux Enterprise Server 12 SP4-LTSS","purl":"pkg:rpm/suse/kernel-source&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.60.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.60.1","kernel-default-base":"4.12.14-95.60.1","kernel-default-devel":"4.12.14-95.60.1","kernel-default-man":"4.12.14-95.60.1","kernel-devel":"4.12.14-95.60.1","kernel-macros":"4.12.14-95.60.1","kernel-source":"4.12.14-95.60.1","kernel-syms":"4.12.14-95.60.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2623-1.json"}},{"package":{"name":"kernel-syms","ecosystem":"SUSE:Linux Enterprise Server 12 SP4-LTSS","purl":"pkg:rpm/suse/kernel-syms&distro=SUSE%20Linux%20Enterprise%20Server%2012%20SP4-LTSS"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"4.12.14-95.60.1"}]}],"ecosystem_specific":{"binaries":[{"kernel-default":"4.12.14-95.60.1","kernel-default-base":"4.12.14-95.60.1","kernel-default-devel":"4.12.14-95.60.1","kernel-default-man":"4.12.14-95.60.1","kernel-devel":"4.12.14-95.60.1","kernel-macros":"4.12.14-95.60.1","kernel-source":"4.12.14-95.60.1","kernel-syms":"4.12.14-95.60.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/SUSE-SU-2020:2623-1.json"}}],"references":[{"type":"ADVISORY","url":"https://www.suse.com/support/update/announcement/2020/suse-su-20202623-1/"},{"type":"REPORT","url":"https://bugzilla.suse.com/1058115"},{"type":"REPORT","url":"https://bugzilla.suse.com/1071995"},{"type":"REPORT","url":"https://bugzilla.suse.com/1144333"},{"type":"REPORT","url":"https://bugzilla.suse.com/1154366"},{"type":"REPORT","url":"https://bugzilla.suse.com/1165629"},{"type":"REPORT","url":"https://bugzilla.suse.com/1171988"},{"type":"REPORT","url":"https://bugzilla.suse.com/1172428"},{"type":"REPORT","url":"https://bugzilla.suse.com/1172963"},{"type":"REPORT","url":"https://bugzilla.suse.com/1173798"},{"type":"REPORT","url":"https://bugzilla.suse.com/1173954"},{"type":"REPORT","url":"https://bugzilla.suse.com/1174205"},{"type":"REPORT","url":"https://bugzilla.suse.com/1174689"},{"type":"REPORT","url":"https://bugzilla.suse.com/1174699"},{"type":"REPORT","url":"https://bugzilla.suse.com/1174757"},{"type":"REPORT","url":"https://bugzilla.suse.com/1174784"},{"type":"REPORT","url":"https://bugzilla.suse.com/1174978"},{"type":"REPORT","url":"https://bugzilla.suse.com/1175112"},{"type":"REPORT","url":"https://bugzilla.suse.com/1175127"},{"type":"REPORT","url":"https://bugzilla.suse.com/1175213"},{"type":"REPORT","url":"https://bugzilla.suse.com/1175228"},{"type":"REPORT","url":"https://bugzilla.suse.com/1175515"},{"type":"REPORT","url":"https://bugzilla.suse.com/1175518"},{"type":"REPORT","url":"https://bugzilla.suse.com/1175691"},{"type":"REPORT","url":"https://bugzilla.suse.com/1175749"},{"type":"REPORT","url":"https://bugzilla.suse.com/1176069"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-10135"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-14314"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-14331"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-14356"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-14386"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-16166"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-1749"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2020-24394"}]}