The SUSE Linux Enterprise 12 SP3 kernel was updated to receive various security and bugfixes. This update adds mitigations for various side channel attacks against modern CPUs that could disclose content of otherwise unreadable memory (bnc#1068032). - CVE-2017-5753 / "SpectreAttack": Local attackers on systems with modern CPUs featuring deep instruction pipelining could use attacker controllable speculative execution over code patterns in the Linux Kernel to leak content from otherwise not readable memory in the same address space, allowing retrieval of passwords, cryptographic keys and other secrets. This problem is mitigated by adding speculative fencing on affected code paths throughout the Linux kernel. - CVE-2017-5715 / "SpectreAttack": Local attackers on systems with modern
#1005778 #1005780 #1005781 #1012382 #1017967
#1039616 #1047487 #1063043 #1064311 #1065180
#1068032 #1068951 #1070116 #1071009 #1072166
#1072216 #1072556 #1072866 #1072890 #1072962
#1073090 #1073525 #1073792 #1073809 #1073868
#1073874 #1073912 #963897 #964063 #966170
#966172
Cross- CVE-2017-17805 CVE-2017-17806 CVE-2017-5715
CVE-2017-5753 CVE-2017-5754
Affected Products:
SUSE Linux Enterprise Workstation Extension 12-SP3
SUSE Linux Enterprise Software Development Kit 12-SP3
SUSE Linux Enterprise Server 12-SP3
SUSE Linux Enterprise Live Patching 12-SP3
SUSE Linux Enterprise High Availability 12-SP3
SUSE Linux Enterprise Desktop 12-SP3
SUSE Container as a Service Platform ALL
- nfs: revalidate "." etc corre...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.