Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

openSUSE Leap 42.3: 2018:2404-1 Important: Kernel Security Notices

opensuse
Calendar Grey August 17, 2018
Dist Opensuse Esm H88
openSUSE has released a significant update for the Linux kernel, tackling numerous security issues and vulnerabilities.
An update that solves 14 vulnerabilities and has 41 fixes is now available.

Description

The openSUSE Leap 42.3 kernel was updated to 4.4.143 to receive various

security and bugfixes.

The following security bugs were fixed:

- CVE-2017-18344: The timer_create syscall implementation in

kernel/time/posix-timers.c didn't properly validate the

sigevent->sigev_notify field, which leads to out-of-bounds access in the

show_timer function (called when /proc/$PID/timers is read). This

allowed userspace applications to read arbitrary kernel memory (on a

kernel built with CONFIG_POSIX_TIMERS and CONFIG_CHECKPOINT_RESTORE)

(bnc#1102851 bnc#1103580).

- CVE-2018-10876: A flaw was found in Linux kernel in the ext4 filesystem

code. A use-after-free is possible in ext4_ext_remove_space() function

when mounting and operating a crafted ext4 image. (bnc#1099811)

- CVE-2018-10877: Linux kernel ext4 filesystem is vulnerable to an

out-of-bound access in the ext4_ext_drop_refs() function when operating

on a crafted ext4...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2018-885=1

Package List

- openSUSE Leap 42.3 (x86_64):

kernel-debug-4.4.143-65.1

kernel-debug-base-4.4.143-65.1

kernel-debug-base-debuginfo-4.4.143-65.1

kernel-debug-debuginfo-4.4.143-65.1

kernel-debug-debugsource-4.4.143-65.1

kernel-debug-devel-4.4.143-65.1

kernel-debug-devel-debuginfo-4.4.143-65.1

kernel-default-4.4.143-65.1

kernel-default-base-4.4.143-65.1

kernel-default-base-debuginfo-4.4.143-65.1

kernel-default-debuginfo-4.4.143-65.1

kernel-default-debugsource-4.4.143-65.1

kernel-default-devel-4.4.143-65.1

kernel-obs-build-4.4.143-65.1

kernel-obs-build-debugsource-4.4.143-65.1

kernel-obs-qa-4.4.143-65.1

kernel-syms-4.4.143-65.1

kernel-vanilla-4.4.143-65.1

kernel-vanilla-base-4.4.143-65.1

kernel-vanilla-base-debuginfo-4.4.143-65.1

kernel-vanilla-debuginfo-4.4.143-65.1

kernel-vanilla-debugsource-4.4.143-65.1

kernel-vanilla-devel-4.4.143-65.1

- openSUSE Leap 42.3 (noarch):

kernel-devel-4.4.143-65.1

kernel-docs-4.4.143-65.1

kernel-docs-html-4.4.143-65.1

kernel-docs-pdf-4.4.143-65.1

kernel-macros-4.4.143-65.1

kernel-source-4.4.143-65.1

ker...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2017-18344.html

https://www.suse.com/security/cve/CVE-2018-10876.html

https://www.suse.com/security/cve/CVE-2018-10877.html

https://www.suse.com/security/cve/CVE-2018-10878.html

https://www.suse.com/security/cve/CVE-2018-10879.html

https://www.suse.com/security/cve/CVE-2018-10880.html

https://www.suse.com/security/cve/CVE-2018-10881.html

https://www.suse.com/security/cve/CVE-2018-10882.html

https://www.suse.com/security/cve/CVE-2018-10883.html

https://www.suse.com/security/cve/CVE-2018-14734.html

https://www.suse.com/security/cve/CVE-2018-3620.html

https://www.suse.com/security/cve/CVE-2018-3646.html

https://www.suse.com/security/cve/CVE-2018-5390.html

https://www.suse.com/security/cve/CVE-2018-5391.html

https://bugzilla.suse.com/1012382

https://bugzilla.suse.com/1082653

https://bugzilla.suse.com/1082979

https://bugzilla.suse.com/1085042

https://bugzilla.suse.com/1085536

https://bugzilla.suse.com/1086457

https://bugzilla.suse.com/1087081

https://bugzilla.suse.com/10893...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:2404-1
Rating: important
Affected Products: openSUSE Leap 42.3 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here