[SUSE-SU-2021:0694-1] Security update for kernel-firmware

Severity Important
Affected Packages 2
CVEs 4

Security update for kernel-firmware

This update for kernel-firmware fixes the following issues:

  • CVE-2020-12373: Fixed an expired pointer dereference may lead to DOS (bsc#1181738).
  • CVE-2020-12364: Fixed a null pointer reference may lead to DOS (bsc#1181736).
  • CVE-2020-12362: Fixed an integer overflow which could have led to privilege escalation (bsc#1181720).
  • CVE-2020-12363: Fixed an improper input validation which may have led to DOS (bsc#1181735).
Type Package URL Namespace Name / Product Version Distribution / Platform Arch Patch / Fix
Affected pkg:rpm/suse/ucode-amd?arch=noarch&distro=sles-15&sp=1 suse ucode-amd < 20200107-3.18.1 sles-15 noarch
Affected pkg:rpm/suse/kernel-firmware?arch=noarch&distro=sles-15&sp=1 suse kernel-firmware < 20200107-3.18.1 sles-15 noarch
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories Exploits PoC Pubblication Date Modification Date
# CVE Description CVSS EPSS EPSS Trend (30 days) Affected Products Weaknesses Security Advisories PoC Pubblication Date Modification Date
Loading...