File _patchinfo of Package patchinfo.17200
<patchinfo incident="17200">
<issue id="1177513" tracker="bnc">VUL-0: CVE-2020-25645: kernel live patch: Geneve/IPsec traffic may be unencrypted between two Geneve endpoints</issue>
<issue id="1177727" tracker="bnc">VUL-0: CVE-2020-24490: kernel live patch: net: bluetooth: heap buffer overflow when processing extended advertising report events aka "BleedingTooth"</issue>
<issue id="1177729" tracker="bnc">VUL-0: CVE-2020-12351: kernel live patch: net: bluetooth: type confusion while processing AMP packets aka "BleedingTooth" aka "BadKarma"</issue>
<issue id="2020-12351" tracker="cve" />
<issue id="2020-24490" tracker="cve" />
<issue id="2020-25645" tracker="cve" />
<category>security</category>
<rating>important</rating>
<packager>nstange</packager>
<description>This update for the Linux Kernel 5.3.18-22 fixes several issues.
The following security issues were fixed:
- CVE-2020-12351: Fixed a type confusion while processing AMP packets aka "BleedingTooth" aka "BadKarma" (bsc#1177724, bsc#1177729, bsc#1178397).
- CVE-2020-24490: Fixed a heap buffer overflow when processing extended advertising report events aka "BleedingTooth" aka "BadVibes" (bsc#1177726, bsc#1177727).
- CVE-2020-25645: Fixed an an issue in IPsec that caused traffic between two Geneve endpoints to be unencrypted (bnc#1177513).
</description>
<summary>Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP2)</summary>
</patchinfo>