Explore top 10 tips to secure your open-source projects now. Read More

×
Alerts This Week
Warning Icon 1 526
Alerts This Week
Warning Icon 1 526

openSUSE: 2018:0972-1 Important: Kernel Denial Of Service Fixes

opensuse
Calendar Grey April 17, 2018
Scroller Opensuse
A security patch has been released that resolves multiple serious vulnerabilities in the openSUSE kernel. Ensure to apply the most recent updates for improved performance.
An update that solves three vulnerabilities and has 52 fixes is now available.

Description

The openSUSE Leap 42.3 kernel was updated to 4.4.126 to receive various

security and bugfixes.

The following security bugs were fixed:

- CVE-2018-1091: In the flush_tmregs_to_thread function in

arch/powerpc/kernel/ptrace.c, a guest kernel crash can be triggered from

unprivileged userspace during a core dump on a POWER host due to a

missing processor feature check and an erroneous use of transactional

memory (TM) instructions in the core dump path, leading to a denial of

service (bnc#1087231).

- CVE-2018-8043: The unimac_mdio_probe function in

drivers/net/phy/mdio-bcm-unimac.c did not validate certain resource

availability, which allowed local users to cause a denial of service

(NULL pointer dereference) (bnc#1084829).

- CVE-2018-7740: The resv_map_release function in mm/hugetlb.c allowed

local users to cause a denial of service (BUG) via a crafted application

that made mmap system calls and has a large pgoff...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-377=1

Package List

- openSUSE Leap 42.3 (x86_64):

kernel-debug-4.4.126-48.2

kernel-debug-base-4.4.126-48.2

kernel-debug-base-debuginfo-4.4.126-48.2

kernel-debug-debuginfo-4.4.126-48.2

kernel-debug-debugsource-4.4.126-48.2

kernel-debug-devel-4.4.126-48.2

kernel-debug-devel-debuginfo-4.4.126-48.2

kernel-default-4.4.126-48.2

kernel-default-base-4.4.126-48.2

kernel-default-base-debuginfo-4.4.126-48.2

kernel-default-debuginfo-4.4.126-48.2

kernel-default-debugsource-4.4.126-48.2

kernel-default-devel-4.4.126-48.2

kernel-obs-build-4.4.126-48.2

kernel-obs-build-debugsource-4.4.126-48.2

kernel-obs-qa-4.4.126-48.1

kernel-syms-4.4.126-48.1

kernel-vanilla-4.4.126-48.2

kernel-vanilla-base-4.4.126-48.2

kernel-vanilla-base-debuginfo-4.4.126-48.2

kernel-vanilla-debuginfo-4.4.126-48.2

kernel-vanilla-debugsource-4.4.126-48.2

kernel-vanilla-devel-4.4.126-48.2

kselftests-kmp-debug-4.4.126-48.2

kselftests-kmp-debug-debuginfo-4.4.126-48.2

kselftests-kmp-default-4.4.126-48.2

kselftests-kmp-default-debuginfo-4.4.126-48.2

kselftests-kmp-vanilla-4.4.126-48.2...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2018-1091.html

https://www.suse.com/security/cve/CVE-2018-7740.html

https://www.suse.com/security/cve/CVE-2018-8043.html

https://bugzilla.suse.com/1012382

https://bugzilla.suse.com/1019695

https://bugzilla.suse.com/1019699

https://bugzilla.suse.com/1022604

https://bugzilla.suse.com/1031717

https://bugzilla.suse.com/1046610

https://bugzilla.suse.com/1060799

https://bugzilla.suse.com/1064206

https://bugzilla.suse.com/1068032

https://bugzilla.suse.com/1073059

https://bugzilla.suse.com/1073069

https://bugzilla.suse.com/1075428

https://bugzilla.suse.com/1076033

https://bugzilla.suse.com/1077560

https://bugzilla.suse.com/1081358

https://bugzilla.suse.com/1083574

https://bugzilla.suse.com/1083745

https://bugzilla.suse.com/1083836

https://bugzilla.suse.com/1084223

https://bugzilla.suse.com/1084310

https://bugzilla.suse.com/1084328

https://bugzilla.suse.com/1084353

https://bugzilla.suse.com/1084452

https://bugzilla.suse.com/1084610

https://bugzilla.suse.com/1084829

https://bugzilla.su...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:0972-1
Rating: important
Affected Products: openSUSE Leap 42.3 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.