Lucene search

K
suseSuseOPENSUSE-SU-2020:1869-1
HistoryNov 07, 2020 - 12:00 a.m.

Security update for u-boot (important)

2020-11-0700:00:00
lists.opensuse.org
54

0.008 Low

EPSS

Percentile

82.2%

An update that fixes two vulnerabilities is now available.

Description:

This update for u-boot fixes the following issues:

  • CVE-2020-8432: Fixed a double free in the cmd/gpt.c
    do_rename_gpt_parts() function, which allowed an attacker to execute
    arbitrary code (bsc#1162198)
  • CVE-2020-10648: Fixed improper signature verification during verified
    boot (bsc#1167209).

This update was imported from the SUSE:SLE-15-SP2:Update update project.

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or “zypper patch”.

Alternatively you can run the command listed for your product:

  • openSUSE Leap 15.2:

    zypper in -t patch openSUSE-2020-1869=1

OSVersionArchitecturePackageVersionFilename
openSUSE Leap15.2x86_64< - openSUSE Leap 15.2 (x86_64):- openSUSE Leap 15.2 (x86_64):.x86_64.rpm

0.008 Low

EPSS

Percentile

82.2%