Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

openSUSE Leap 42.2: 2018:0023-1 Important: Side Channel Attack Mitigations

opensuse
Calendar Grey January 5, 2018
Dist Opensuse Esm H88
A crucial security update for openSUSE Leap 42.2 fixes various vulnerabilities and important mitigations.
An update that solves 5 vulnerabilities and has 19 fixes is now available.

Description

The openSUSE Leap 42.2 kernel was updated to 4.4.104 to receive various

security and bugfixes.

This update adds mitigations for various side channel attacks against

modern CPUs that could disclose content of otherwise unreadable memory

(bnc#1068032).

- CVE-2017-5753 / "SpectreAttack": Local attackers on systems with modern

CPUs featuring deep instruction pipelining could use attacker

controllable speculative execution over code patterns in the Linux

Kernel to leak content from otherwise not readable memory in the same

address space, allowing retrieval of passwords, cryptographic keys and

other secrets.

This problem is mitigated by adding speculative fencing on affected code

paths throughout the Linux kernel.

- CVE-2017-5715 / "SpectreAttack": Local attackers on systems with modern

CPUs featuring branch prediction could use mispredicted branches to

speculatively execute code patterns that in turn could be made to...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use YaST online_update.

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.2:

zypper in -t patch openSUSE-2018-3=1

To bring your system up-to-date, use "zypper patch".

Package List

- openSUSE Leap 42.2 (noarch):

kernel-devel-4.4.104-18.44.1

kernel-docs-4.4.104-18.44.1

kernel-docs-html-4.4.104-18.44.1

kernel-docs-pdf-4.4.104-18.44.1

kernel-macros-4.4.104-18.44.1

kernel-source-4.4.104-18.44.1

kernel-source-vanilla-4.4.104-18.44.1

- openSUSE Leap 42.2 (x86_64):

kernel-debug-4.4.104-18.44.1

kernel-debug-base-4.4.104-18.44.1

kernel-debug-base-debuginfo-4.4.104-18.44.1

kernel-debug-debuginfo-4.4.104-18.44.1

kernel-debug-debugsource-4.4.104-18.44.1

kernel-debug-devel-4.4.104-18.44.1

kernel-debug-devel-debuginfo-4.4.104-18.44.1

kernel-default-4.4.104-18.44.1

kernel-default-base-4.4.104-18.44.1

kernel-default-base-debuginfo-4.4.104-18.44.1

kernel-default-debuginfo-4.4.104-18.44.1

kernel-default-debugsource-4.4.104-18.44.1

kernel-default-devel-4.4.104-18.44.1

kernel-obs-build-4.4.104-18.44.1

kernel-obs-build-debugsource-4.4.104-18.44.1

kernel-obs-qa-4.4.104-18.44.1

kernel-syms-4.4.104-18.44.1

kernel-vanilla-4.4.104-18.44.1

kernel-vanilla-base-4.4.104-18.44.1

kernel-vanilla-base-debuginfo-4.4.104-18.4...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2017-17805.html

https://www.suse.com/security/cve/CVE-2017-17806.html

https://www.suse.com/security/cve/CVE-2017-5715.html

https://www.suse.com/security/cve/CVE-2017-5753.html

https://www.suse.com/security/cve/CVE-2017-5754.html

https://bugzilla.suse.com/1012382

https://bugzilla.suse.com/1012917

https://bugzilla.suse.com/1022476

https://bugzilla.suse.com/1031717

https://bugzilla.suse.com/1039616

https://bugzilla.suse.com/1047487

https://bugzilla.suse.com/1063043

https://bugzilla.suse.com/1064311

https://bugzilla.suse.com/1065180

https://bugzilla.suse.com/1068032

https://bugzilla.suse.com/1068951

https://bugzilla.suse.com/1071009

https://bugzilla.suse.com/1072556

https://bugzilla.suse.com/1072962

https://bugzilla.suse.com/1073090

https://bugzilla.suse.com/1073792

https://bugzilla.suse.com/1073809

https://bugzilla.suse.com/1073874

https://bugzilla.suse.com/1073912

https://bugzilla.suse.com/1074392

https://bugzilla.suse.com/1074562

https://bugzilla.suse.com/1074578

https://bugz...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:0023-1
Rating: important
Affected Products: openSUSE Leap 42.2 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here