File _patchinfo of Package patchinfo.17185

<patchinfo incident="17185">
  <issue id="1177513" tracker="bnc">VUL-0: CVE-2020-25645: kernel live patch: Geneve/IPsec traffic may be unencrypted between two Geneve endpoints</issue>
  <issue id="1177729" tracker="bnc">VUL-0: CVE-2020-12351: kernel live patch:  net: bluetooth: type confusion while processing AMP packets aka "BleedingTooth" aka "BadKarma"</issue>
  <issue id="1178003" tracker="bnc">VUL-1: CVE-2020-0430: kernel live patch: possible out of bounds read in skb_headlen of /include/linux/skbuff.h</issue>
  <issue id="1178264" tracker="bnc">Missing fix for CVE 2017-1000405</issue>
  <issue id="2017-1000405" tracker="cve" />
  <issue id="2020-0430" tracker="cve" />
  <issue id="2020-12351" tracker="cve" />
  <issue id="2020-25645" tracker="cve" />
  <category>security</category>
  <rating>important</rating>
  <packager>nstange</packager>
  <description>This update for the Linux Kernel 4.12.14-150_41 fixes several issues.

The following security issues were fixed:

- CVE-2017-1000405: Fixed a bug in the THP CoW support that could have been used by local attackers to corrupt memory of other processes and cause them to crash (bsc#1178264, bsc#1069496, bsc#1070307).
- CVE-2020-0430: Fixed an OOB read in skb_headlen of /include/linux/skbuff.h (bsc#1176723, bsc#1178003).
- CVE-2020-12351: Fixed a type confusion while processing AMP packets aka "BleedingTooth" aka "BadKarma" (bsc#1177724, bsc#1177729, bsc#1178397).
- CVE-2020-25645: Fixed an an issue in IPsec that caused traffic between two Geneve endpoints to be unencrypted (bnc#1177513).
</description>
<summary>Security update for the Linux Kernel (Live Patch 16 for SLE 15)</summary>
</patchinfo>
openSUSE Build Service is sponsored by