Alerts This Week
Warning Icon 1 535
Alerts This Week
Warning Icon 1 535

openSUSE Leap 15.1: 2019:2444-1 Important: Linux Kernel Security Fixes

opensuse
Calendar Grey November 5, 2019
Dist Opensuse Esm H88
Essential security patch for openSUSE Leap 15.1 resolves various vulnerabilities in the Linux kernel, improving overall system performance.
An update that solves 7 vulnerabilities and has 96 fixes is now available.

Description

The openSUSE Leap 15.1 kernel was updated to receive various security and

bugfixes.

The following security bugs were fixed:

- CVE-2019-16995: A memory leak exits in hsr_dev_finalize() in

net/hsr/hsr_device.c. if hsr_add_port fails to add a port, which may

cause denial of service, aka CID-6caabe7f197d (bnc#1152685).

- CVE-2019-16233: drivers/scsi/qla2xxx/qla_os.c did not check the

alloc_workqueue return value, leading to a NULL pointer dereference

(bnc#1150457).

- CVE-2019-17666: rtl_p2p_noa_ie in

drivers/net/wireless/realtek/rtlwifi/ps.c lacked a certain upper-bound

check, leading to a buffer overflow (bnc#1154372).

- CVE-2019-16232: drivers/net/wireless/marvell/libertas/if_sdio.c did not

check the alloc_workqueue return value, leading to a NULL pointer

dereference (bnc#1150465).

- CVE-2019-16234: drivers/net/wireless/intel/iwlwifi/pcie/trans.c did not

check the alloc_workqueue return value, leading to a NULL...

Read the Full Advisory

Patch

Patch Instructions:

To install this openSUSE Security Update use the SUSE recommended installation methods

like YaST online_update or "zypper patch".

Alternatively you can run the command listed for your product:

- openSUSE Leap 15.1:

zypper in -t patch openSUSE-2019-2444=1

Package List

- openSUSE Leap 15.1 (noarch):

kernel-devel-4.12.14-lp151.28.25.1

kernel-docs-4.12.14-lp151.28.25.1

kernel-docs-html-4.12.14-lp151.28.25.1

kernel-macros-4.12.14-lp151.28.25.1

kernel-source-4.12.14-lp151.28.25.1

kernel-source-vanilla-4.12.14-lp151.28.25.1

- openSUSE Leap 15.1 (x86_64):

kernel-debug-4.12.14-lp151.28.25.1

kernel-debug-base-4.12.14-lp151.28.25.1

kernel-debug-base-debuginfo-4.12.14-lp151.28.25.1

kernel-debug-debuginfo-4.12.14-lp151.28.25.1

kernel-debug-debugsource-4.12.14-lp151.28.25.1

kernel-debug-devel-4.12.14-lp151.28.25.1

kernel-debug-devel-debuginfo-4.12.14-lp151.28.25.1

kernel-default-4.12.14-lp151.28.25.1

kernel-default-base-4.12.14-lp151.28.25.1

kernel-default-base-debuginfo-4.12.14-lp151.28.25.1

kernel-default-debuginfo-4.12.14-lp151.28.25.1

kernel-default-debugsource-4.12.14-lp151.28.25.1

kernel-default-devel-4.12.14-lp151.28.25.1

kernel-default-devel-debuginfo-4.12.14-lp151.28.25.1

kernel-kvmsmall-4.12.14-lp151.28.25.1

kernel-kvmsmall-base-4.12.14-lp151.28.25.1

kernel-kvmsmall-base-debu...

Read the Full Advisory

References

https://www.suse.com/security/cve/CVE-2019-16232.html

https://www.suse.com/security/cve/CVE-2019-16233.html

https://www.suse.com/security/cve/CVE-2019-16234.html

https://www.suse.com/security/cve/CVE-2019-16995.html

https://www.suse.com/security/cve/CVE-2019-17056.html

https://www.suse.com/security/cve/CVE-2019-17133.html

https://www.suse.com/security/cve/CVE-2019-17666.html

https://bugzilla.suse.com/1046299

https://bugzilla.suse.com/1046303

https://bugzilla.suse.com/1046305

https://bugzilla.suse.com/1050244

https://bugzilla.suse.com/1050536

https://bugzilla.suse.com/1050545

https://bugzilla.suse.com/1051510

https://bugzilla.suse.com/1055186

https://bugzilla.suse.com/1061840

https://bugzilla.suse.com/1064802

https://bugzilla.suse.com/1065600

https://bugzilla.suse.com/1066129

https://bugzilla.suse.com/1073513

https://bugzilla.suse.com/1082635

https://bugzilla.suse.com/1083647

https://bugzilla.suse.com/1086323

https://bugzilla.suse.com/1087092

https://bugzilla.suse.com/1089644

https://bugzilla.suse.com/1093205

ht...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: openSUSE-SU-2019:2444-1
Rating: important
Affected Products: openSUSE Leap 15.1 le.

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here