Alerts This Week
Warning Icon 1 560
Alerts This Week
Warning Icon 1 560

openSUSE Leap 15.0 Security Advisory 2018:3658-1 Critical Kernel Issue

opensuse
Calendar Grey November 7, 2018
Dist Opensuse Esm H88
Crucial announcement for openSUSE Leap 15.0 addressing numerous security vulnerabilities and delivering vital improvements.
An update that solves 5 vulnerabilities and has 86 fixes is now available.

Description

The openSUSE Leap 15.0 kernel was updated to receive various security and

bugfixes.

The following security bugs were fixed:

- CVE-2018-18710: An information leak in cdrom_ioctl_select_disc in

drivers/cdrom/cdrom.c could be used by local attackers to read kernel

memory because a cast from unsigned long to int interferes with bounds

checking. This is similar to CVE-2018-10940 and CVE-2018-16658

(bnc#1113751).

- CVE-2018-18445: Faulty computation of numeric bounds in the BPF verifier

permitted out-of-bounds memory accesses because

adjust_scalar_min_max_vals in kernel/bpf/verifier.c mishandled 32-bit

right shifts (bnc#1112372).

- CVE-2018-18386: drivers/tty/n_tty.c allowed local attackers (who are

able to access pseudo terminals) to hang/block further usage of any

pseudo terminal devices due to an EXTPROC versus ICANON confusion in

TIOCINQ (bnc#1094825).

- CVE-2017-18224: fs/ocfs2/aops.c omitted use of a semaphore...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.0:

zypper in -t patch openSUSE-2018-1342=1

Package List

- openSUSE Leap 15.0 (x86_64):

kernel-debug-4.12.14-lp150.12.25.1

kernel-debug-base-4.12.14-lp150.12.25.1

kernel-debug-base-debuginfo-4.12.14-lp150.12.25.1

kernel-debug-debuginfo-4.12.14-lp150.12.25.1

kernel-debug-debugsource-4.12.14-lp150.12.25.1

kernel-debug-devel-4.12.14-lp150.12.25.1

kernel-debug-devel-debuginfo-4.12.14-lp150.12.25.1

kernel-default-4.12.14-lp150.12.25.1

kernel-default-base-4.12.14-lp150.12.25.1

kernel-default-base-debuginfo-4.12.14-lp150.12.25.1

kernel-default-debuginfo-4.12.14-lp150.12.25.1

kernel-default-debugsource-4.12.14-lp150.12.25.1

kernel-default-devel-4.12.14-lp150.12.25.1

kernel-default-devel-debuginfo-4.12.14-lp150.12.25.1

kernel-kvmsmall-4.12.14-lp150.12.25.1

kernel-kvmsmall-base-4.12.14-lp150.12.25.1

kernel-kvmsmall-base-debuginfo-4.12.14-lp150.12.25.1

kernel-kvmsmall-debuginfo-4.12.14-lp150.12.25.1

kernel-kvmsmall-debugsource-4.12.14-lp150.12.25.1

kernel-kvmsmall-devel-4.12.14-lp150.12.25.1

kernel-kvmsmall-devel-debuginfo-4.12.14-lp150.12.25.1

kernel-obs-build-4.12.14-lp15...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2017-16533.html

https://www.suse.com/security/cve/CVE-2017-18224.html

https://www.suse.com/security/cve/CVE-2018-18386.html

https://www.suse.com/security/cve/CVE-2018-18445.html

https://www.suse.com/security/cve/CVE-2018-18710.html

https://bugzilla.suse.com/1051510

https://bugzilla.suse.com/1055120

https://bugzilla.suse.com/1065600

https://bugzilla.suse.com/1066674

https://bugzilla.suse.com/1067906

https://bugzilla.suse.com/1076830

https://bugzilla.suse.com/1079524

https://bugzilla.suse.com/1083647

https://bugzilla.suse.com/1084760

https://bugzilla.suse.com/1084831

https://bugzilla.suse.com/1091800

https://bugzilla.suse.com/1094825

https://bugzilla.suse.com/1095805

https://bugzilla.suse.com/1100132

https://bugzilla.suse.com/1103356

https://bugzilla.suse.com/1103543

https://bugzilla.suse.com/1104124

https://bugzilla.suse.com/1104731

https://bugzilla.suse.com/1105025

https://bugzilla.suse.com/1105428

https://bugzilla.suse.com/1105536

https://bugzilla.suse.com/1106110

https://b...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2018:3658-1
Rating: important
Affected Products: openSUSE Leap 15.0 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here