The openSUSE Leap 42.3 kernel was updated to 4.4.143 to receive various
security and bugfixes.
The following security bugs were fixed:
- CVE-2017-18344: The timer_create syscall implementation in
kernel/time/posix-timers.c didn't properly validate the
sigevent->sigev_notify field, which leads to out-of-bounds access in the
show_timer function (called when /proc/$PID/timers is read). This
allowed userspace applications to read arbitrary kernel memory (on a
kernel built with CONFIG_POSIX_TIMERS and CONFIG_CHECKPOINT_RESTORE)
(bnc#1102851 bnc#1103580).
- CVE-2018-10876: A flaw was found in Linux kernel in the ext4 filesystem
code. A use-after-free is possible in ext4_ext_remove_space() function
when mounting and operating a crafted ext4 image. (bnc#1099811)
- CVE-2018-10877: Linux kernel ext4 filesystem is vulnerable to an
out-of-bound access in the ext4_ext_drop_refs() function when operating
on a crafted ext4...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Leap 42.3:
zypper in -t patch openSUSE-2018-885=1
- openSUSE Leap 42.3 (x86_64):
kernel-debug-4.4.143-65.1
kernel-debug-base-4.4.143-65.1
kernel-debug-base-debuginfo-4.4.143-65.1
kernel-debug-debuginfo-4.4.143-65.1
kernel-debug-debugsource-4.4.143-65.1
kernel-debug-devel-4.4.143-65.1
kernel-debug-devel-debuginfo-4.4.143-65.1
kernel-default-4.4.143-65.1
kernel-default-base-4.4.143-65.1
kernel-default-base-debuginfo-4.4.143-65.1
kernel-default-debuginfo-4.4.143-65.1
kernel-default-debugsource-4.4.143-65.1
kernel-default-devel-4.4.143-65.1
kernel-obs-build-4.4.143-65.1
kernel-obs-build-debugsource-4.4.143-65.1
kernel-obs-qa-4.4.143-65.1
kernel-syms-4.4.143-65.1
kernel-vanilla-4.4.143-65.1
kernel-vanilla-base-4.4.143-65.1
kernel-vanilla-base-debuginfo-4.4.143-65.1
kernel-vanilla-debuginfo-4.4.143-65.1
kernel-vanilla-debugsource-4.4.143-65.1
kernel-vanilla-devel-4.4.143-65.1
- openSUSE Leap 42.3 (noarch):
kernel-devel-4.4.143-65.1
kernel-docs-4.4.143-65.1
kernel-docs-html-4.4.143-65.1
kernel-docs-pdf-4.4.143-65.1
kernel-macros-4.4.143-65.1
kernel-source-4.4.143-65.1
ker...
Read the Full Advisoryhttps://www.suse.com/security/cve/CVE-2017-18344.html
https://www.suse.com/security/cve/CVE-2018-10876.html
https://www.suse.com/security/cve/CVE-2018-10877.html
https://www.suse.com/security/cve/CVE-2018-10878.html
https://www.suse.com/security/cve/CVE-2018-10879.html
https://www.suse.com/security/cve/CVE-2018-10880.html
https://www.suse.com/security/cve/CVE-2018-10881.html
https://www.suse.com/security/cve/CVE-2018-10882.html
https://www.suse.com/security/cve/CVE-2018-10883.html
https://www.suse.com/security/cve/CVE-2018-14734.html
https://www.suse.com/security/cve/CVE-2018-3620.html
https://www.suse.com/security/cve/CVE-2018-3646.html
https://www.suse.com/security/cve/CVE-2018-5390.html
https://www.suse.com/security/cve/CVE-2018-5391.html
https://bugzilla.suse.com/1012382
https://bugzilla.suse.com/1082653
https://bugzilla.suse.com/1082979
https://bugzilla.suse.com/1085042
https://bugzilla.suse.com/1085536
https://bugzilla.suse.com/1086457
https://bugzilla.suse.com/1087081
https://bugzilla.suse.com/10893...
Read the Full AdvisoryGet the latest Linux and open source security news straight to your inbox.