Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

openSUSE: 2019:1407-1 Important: Kernel Bugfix Update for Security Issues

opensuse
Calendar Grey May 20, 2019
Dist Opensuse Esm H88
This recent Fedora kernel patch fixes 12 security issues. Update your system promptly for enhanced protection!
An update that solves 14 vulnerabilities and has 90 fixes is now available.

Description

The openSUSE Leap 42.3 kernel was updated to 4.4.179 to receive various

security and bugfixes.

Four new speculative execution information leak issues have been

identified in Intel CPUs. (bsc#1111331)

- CVE-2018-12126: Microarchitectural Store Buffer Data Sampling (MSBDS)

- CVE-2018-12127: Microarchitectural Fill Buffer Data Sampling (MFBDS)

- CVE-2018-12130: Microarchitectural Load Port Data Samling (MLPDS)

- CVE-2019-11091: Microarchitectural Data Sampling Uncacheable Memory

(MDSUM)

This kernel update contains software mitigations for these issues, which

also utilize CPU microcode updates shipped in parallel.

For more information on this set of information leaks, check out

https://support.scc.suse.com/s/kb?language=en_US

The following security bugs were fixed:

- CVE-2018-5814: Multiple race condition errors when handling probe,

disconnect, and rebind operations can be exploited to trigger a

use-after-free condition or...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 42.3:

zypper in -t patch openSUSE-2019-1407=1

Package List

- openSUSE Leap 42.3 (noarch):

kernel-devel-4.4.179-99.1

kernel-docs-4.4.179-99.1

kernel-docs-html-4.4.179-99.1

kernel-docs-pdf-4.4.179-99.1

kernel-macros-4.4.179-99.1

kernel-source-4.4.179-99.1

kernel-source-vanilla-4.4.179-99.1

- openSUSE Leap 42.3 (x86_64):

kernel-debug-4.4.179-99.1

kernel-debug-base-4.4.179-99.1

kernel-debug-base-debuginfo-4.4.179-99.1

kernel-debug-debuginfo-4.4.179-99.1

kernel-debug-debugsource-4.4.179-99.1

kernel-debug-devel-4.4.179-99.1

kernel-debug-devel-debuginfo-4.4.179-99.1

kernel-default-4.4.179-99.1

kernel-default-base-4.4.179-99.1

kernel-default-base-debuginfo-4.4.179-99.1

kernel-default-debuginfo-4.4.179-99.1

kernel-default-debugsource-4.4.179-99.1

kernel-default-devel-4.4.179-99.1

kernel-obs-build-4.4.179-99.1

kernel-obs-build-debugsource-4.4.179-99.1

kernel-obs-qa-4.4.179-99.1

kernel-syms-4.4.179-99.1

kernel-vanilla-4.4.179-99.1

kernel-vanilla-base-4.4.179-99.1

kernel-vanilla-base-debuginfo-4.4.179-99.1

kernel-vanilla-debuginfo-4.4.179-99.1

kernel-vanilla-debugsource-4.4.179-99.1

ke...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2018-1000204.html

https://www.suse.com/security/cve/CVE-2018-10853.html

https://www.suse.com/security/cve/CVE-2018-12126.html

https://www.suse.com/security/cve/CVE-2018-12127.html

https://www.suse.com/security/cve/CVE-2018-12130.html

https://www.suse.com/security/cve/CVE-2018-15594.html

https://www.suse.com/security/cve/CVE-2018-17972.html

https://www.suse.com/security/cve/CVE-2018-5814.html

https://www.suse.com/security/cve/CVE-2019-11091.html

https://www.suse.com/security/cve/CVE-2019-11486.html

https://www.suse.com/security/cve/CVE-2019-11815.html

https://www.suse.com/security/cve/CVE-2019-11884.html

https://www.suse.com/security/cve/CVE-2019-3882.html

https://www.suse.com/security/cve/CVE-2019-9503.html

https://bugzilla.suse.com/1012382

https://bugzilla.suse.com/1020645

https://bugzilla.suse.com/1020989

https://bugzilla.suse.com/1031492

https://bugzilla.suse.com/1047487

https://bugzilla.suse.com/1051510

https://bugzilla.suse.com/1053043

https://bugzilla.suse.com/10...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2019:1407-1
Rating: important
Affected Products: openSUSE Leap 42.3 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here