🛡️ SUSE-SU-2021:3338-1 — kernel-azure (CVE-2020-3702 +5 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for the Linux Kernel

The SUSE Linux Enterprise 15 SP3 kernel was updated.

The following security bugs were fixed:

  • CVE-2020-3702: Fixed a bug which could be triggered with specifically timed and handcrafted traffic and cause internal errors in a WLAN device that lead to improper layer 2 Wi-Fi encryption with a consequent possibility of information disclosure. (bnc#1191193)
  • CVE-2021-3752: Fixed a use after free vulnerability in the Linux kernel's bluetooth module. (bsc#1190023)
  • CVE-2021-40490: Fixed a race condition discovered in the ext4 subsystem that could leat to local priviledge escalation. (bnc#1190159)
  • CVE-2021-3744: Fixed a bug which could allows attackers to cause a denial of service. (bsc#1189884)
  • CVE-2021-3764: Fixed a bug which could allows attackers to cause a denial of service. (bsc#1190534)
  • CVE-2021-3669: Fixed a bug that doesn't allow /proc/sysvipc/shm to scale with large shared memory segment counts which could lead to resource exhaustion and DoS. (bsc#1188986)

The following non-security bugs were fixed:

  • ALSA: firewire-motu: fix truncated bytes in message tracepoints (git-fixes).
  • apparmor: remove duplicate macro list_entry_is_head() (git-fixes).
  • ASoC: fsl_micfil: register platform component before registering cpu dai (git-fixes).
  • ASoC: Intel: Fix platform ID matching (git-fixes).
  • ASoC: mediatek: common: handle NULL case in suspend/resume function (git-fixes).
  • ASoC: rockchip: i2s: Fix regmap_ops hang (git-fixes).
  • ASoC: rockchip: i2s: Fixup config for DAIFMT_DSP_A/B (git-fixes).
  • ASoC: rt5682: Implement remove callback (git-fixes).
  • ASoC: rt5682: Properly turn off regulators if wrong device ID (git-fixes).
  • ASoC: rt5682: Remove unused variable in rt5682_i2c_remove() (git-fixes).
  • ASoC: SOF: Fix DSP oops stack dump output contents (git-fixes).
  • ath9k: fix OOB read ar9300_eeprom_restore_internal (git-fixes).
  • ath9k: fix sleeping in atomic context (git-fixes).
  • backlight: pwm_bl: Improve bootloader/kernel device handover (git-fixes).
  • bareudp: Fix invalid read beyond skb's linear data (jsc#SLE-15172).
  • blk-mq: do not deactivate hctx if managed irq isn't used (bsc#1185762).
  • blk-mq: do not deactivate hctx if managed irq isn't used (bsc#1185762).
  • blk-mq: kABI fixes for blk_mq_queue_map (bsc#1185762).
  • blk-mq: kABI fixes for blk_mq_queue_map (bsc#1185762).
  • blk-mq: mark if one queue map uses managed irq (bsc#1185762).
  • blk-mq: mark if one queue map uses managed irq (bsc#1185762).
  • Bluetooth: skip invalid hci_sync_conn_complete_evt (git-fixes).
  • bnx2x: fix an error code in bnx2x_nic_load() (git-fixes).
  • bnxt_en: Add missing DMA memory barriers (git-fixes).
  • bnxt_en: Disable aRFS if running on 212 firmware (git-fixes).
  • bnxt_en: Do not enable legacy TX push on older firmware (git-fixes).
  • bnxt_en: Fix asic.rev in devlink dev info command (jsc#SLE-16649).
  • bnxt_en: fix stored FW_PSID version masks (jsc#SLE-16649).
  • bnxt_en: Store the running firmware version code (git-fixes).
  • bnxt: count Tx drops (git-fixes).
  • bnxt: disable napi before canceling DIM (git-fixes).
  • bnxt: do not lock the tx queue from napi poll (git-fixes).
  • bnxt: make sure xmit_more + errors does not miss doorbells (git-fixes).
  • bpf, samples: Add missing mprog-disable to xdp_redirect_cpu's optstring (git-fixes).
  • bpf: Fix ringbuf helper function compatibility (git-fixes).
  • bpftool: Add sock_release help info for cgroup attach/prog load command (bsc#1177028).
  • btrfs: prevent rename2 from exchanging a subvol with a directory from different parents (bsc#1190626).
  • clk: at91: clk-generated: Limit the requested rate to our range (git-fixes).
  • clk: at91: clk-generated: pass the id of changeable parent at registration (git-fixes).
  • console: consume APC, DM, DCS (git-fixes).
  • cpuidle: pseries: Do not cap the CEDE0 latency in fixup_cede0_latency() (bsc#1185550 ltc#192610 git-fixes jsc#SLE-18128).
  • cuse: fix broken release (bsc#1190596).
  • cxgb4: dont touch blocked freelist bitmap after free (git-fixes).
  • debugfs: Return error during {full/open}_proxy_open() on rmmod (bsc#1173746).
  • devlink: Break parameter notification sequence to be before/after unload/load driver (bsc#1154353).
  • devlink: Clear whole devlink_flash_notify struct (bsc#1176447).
  • dma-buf: DMABUF_MOVE_NOTIFY should depend on DMA_SHARED_BUFFER (git-fixes).
  • dmaengine: ioat: depends on !UML (git-fixes).
  • dmaengine: sprd: Add missing MODULE_DEVICE_TABLE (git-fixes).
  • dmaengine: xilinx_dma: Set DMA mask for coherent APIs (git-fixes).
  • docs: Fix infiniband uverbs minor number (git-fixes).
  • drivers: gpu: amd: Initialize amdgpu_dm_backlight_caps object to 0 in amdgpu_dm_update_backlight_caps (git-fixes).
  • drm: avoid blocking in drm_clients_info's rcu section (git-fixes).
  • drm/amd/amdgpu: Update debugfs link_settings output link_rate field in hex (git-fixes).
  • drm/amd/display: Fix timer_per_pixel unit error (git-fixes).
  • drm/amdgpu: Fix BUG_ON assert (git-fixes).
  • drm/ast: Fix missing conversion

Affected software

SUSE-SU-2021:3338-1 is recorded against 3 packages.

  • kernel-azure (fixed in 5.3.18-38.25.2)
  • kernel-source-azure (fixed in 5.3.18-38.25.2)
  • kernel-syms-azure (fixed in 5.3.18-38.25.1)

Timeline and source

Published on 12 October 2021 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2021-10-12
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel-azure 5.3.18-38.25.2
kernel-source-azure 5.3.18-38.25.2
kernel-syms-azure 5.3.18-38.25.1

References

Free Vulnerability Check

Is your site affected by SUSE-SU-2021:3338-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2021:3338-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSE