🛡️ SUSE-SU-2021:3723-1 — kernel-rt (CVE-2021-3655 +13 more)

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Security update for the Linux Kernel

The SUSE Linux Enterprise 12 SP5 Real Time kernel was updated to receive various security and bugfixes.

The following security bugs were fixed:

  • CVE-2021-3655: Fixed a missing size validations on inbound SCTP packets, which may have allowed the kernel to read uninitialized memory (bsc#1188563).
  • CVE-2021-3715: Fixed a use-after-free in route4_change() in net/sched/cls_route.c (bsc#1190349).
  • CVE-2021-33033: Fixed a use-after-free in cipso_v4_genopt in net/ipv4/cipso_ipv4.c because the CIPSO and CALIPSO refcounting for the DOI definitions is mishandled (bsc#1186109).
  • CVE-2021-3760: Fixed a use-after-free vulnerability with the ndev->rf_conn_info object (bsc#1190067).
  • CVE-2021-42739: The firewire subsystem had a buffer overflow related to drivers/media/firewire/firedtv-avc.c and drivers/media/firewire/firedtv-ci.c, because avc_ca_pmt mishandled bounds checking (bsc#1184673).
  • CVE-2021-3542: Fixed heap buffer overflow in firedtv driver (bsc#1186063).
  • CVE-2021-34556: Fixed side-channel attack via a Speculative Store Bypass via unprivileged BPF program that could have obtain sensitive information from kernel memory (bsc#1188983).
  • CVE-2021-35477: Fixed BPF stack frame pointer which could have been abused to disclose content of arbitrary kernel memory (bsc#1188985).
  • CVE-2021-42252: Fixed an issue inside aspeed_lpc_ctrl_mmap that could have allowed local attackers to access the Aspeed LPC control interface to overwrite memory in the kernel and potentially execute privileges (bnc#1190479).
  • CVE-2021-41864: Fixed prealloc_elems_and_freelist that allowed unprivileged users to trigger an eBPF multiplication integer overflow with a resultant out-of-bounds write (bnc#1191317).
  • CVE-2021-42008: Fixed a slab out-of-bounds write in the decode_data function in drivers/net/hamradio/6pack.c. Input from a process that had the CAP_NET_ADMIN capability could have lead to root access (bsc#1191315).
  • CVE-2021-37159: Fixed use-after-free and a double free in hso_free_net_device in drivers/net/usb/hso.c when unregister_netdev is called without checking for the NETREG_REGISTERED state (bnc#1188601).
  • CVE-2021-3772: Fixed sctp vtag check in sctp_sf_ootb (bsc#1190351).

The following non-security bugs were fixed:

  • IB/hfi1: Fix abba locking issue with sc_disable() (git-fixes)
  • ICMPv6: Add ICMPv6 Parameter Problem, code 3 definition (bsc#1191241).
  • IPv6: reply ICMP error if the first fragment do not include all headers (bsc#1191241).
  • KVM: PPC: Book3S HV: Save host FSCR in the P7/8 path (bsc#1065729).
  • NFS: Do uncached readdir when we're seeking a cookie in an empty page cache (bsc#1191628).
  • PM: base: power: do not try to use non-existing RTC for storing data (git-fixes).
  • SMB3.1.1: Fix ids returned in POSIX query dir (bsc#1190317).
  • SMB3.1.1: do not log warning message if server does not populate salt (bsc#1190317).
  • SMB3.1.1: fix mount failure to some servers when compression enabled (bsc#1190317).
  • SMB3.1.1: remove confusing mount warning when no SPNEGO info on negprot rsp (bsc#1190317).
  • SMB3.1.1: update comments clarifying SPNEGO info in negprot response (bsc#1190317).
  • SMB3: Add new info level for query directory (bsc#1190317).
  • SMB3: Add support for getting and setting SACLs (bsc#1190317).
  • SMB3: Fix mkdir when idsfromsid configured on mount (bsc#1190317).
  • SMB3: Resolve data corruption of TCP server info fields (bsc#1190317).
  • SMB3: add support for recognizing WSL reparse tags (bsc#1190317).
  • SMB3: avoid confusing warning message on mount to Azure (bsc#1190317).
  • SMB3: fix readpage for large swap cache (bsc#1190317).
  • SMB3: incorrect file id in requests compounded with open (bsc#1190317).
  • SMB3: update structures for new compression protocol definitions (bsc#1190317).
  • USB: cdc-acm: fix break reporting (git-fixes).
  • USB: cdc-acm: fix racy tty buffer accesses (git-fixes).
  • USB: serial: cp210x: add ID for GW Instek GDM-834x Digital Multimeter (git-fixes).
  • USB: serial: option: add Telit LN920 compositions (git-fixes).
  • USB: serial: option: add device id for Foxconn T99W265 (git-fixes).
  • USB: xhci: dbc: fix tty registration race (git-fixes).
  • bitmap: remove unused function declaration (git-fixes).
  • blktrace: Fix uaf in blk_trace access after removing by sysfs (bsc#1191452).
  • cdc_ncm: Set NTB format again after altsetting switch for Huawei devices (git-fixes).
  • cifs: Add get_security_type_str function to return sec type (bsc#1190317).
  • cifs: Avoid field over-reading memcpy() (bsc#1190317).
  • cifs: Change SIDs in ACEs while transferring file ownership (bsc#1190317).
  • cifs: Clarify SMB1 code for POSIX Create (bsc#1190317).
  • cifs: Clarify SMB1 code for POSIX Lock (bsc#1190317).
  • cifs: Clarify SMB1 code for POSIX delete file (bsc#1190317).
  • cifs: Clarify SMB1 code for SetFileSize (bsc#1190317).
  • cifs: Clarify SMB1 code for UnixCreateSymLink (bsc#1190317).
  • cifs: Clarify SMB1 code for UnixSetPathInfo (bsc#1190317).
  • cifs: Clarify SMB1 code for

Affected software

SUSE-SU-2021:3723-1 is recorded against 4 packages.

  • kernel-rt (fixed in 4.12.14-10.65.1)
  • kernel-rt-debug (fixed in 4.12.14-10.65.1)
  • kernel-source-rt (fixed in 4.12.14-10.65.1)
  • kernel-syms-rt (fixed in 4.12.14-10.65.1)

Timeline and source

Published on 17 November 2021 and last revised on 4 February 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

www.suse.com (Advisory)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)
bugzilla.suse.com (Report)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2021-11-17
Updated 2026-08-20
Modified 2026-02-04
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel-rt 4.12.14-10.65.1
kernel-rt-debug 4.12.14-10.65.1
kernel-source-rt 4.12.14-10.65.1
kernel-syms-rt 4.12.14-10.65.1

References

Similar Threats

Free Vulnerability Check

Is your site affected by SUSE-SU-2021:3723-1?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against SUSE-SU-2021:3723-1 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.

Browse related advisories

All advisoriesSUSE