Alerts This Week
Warning Icon 1 659
Alerts This Week
Warning Icon 1 659

SUSE: 2018:0011-1 Important: Kernel Patch Mitigates Security Risks

suse
Calendar Grey January 4, 2018
Dist Suse Esm H88
SUSE Security Bulletin for Kernel Updates: Critical patches addressing multiple security flaws along with comprehensive guidelines for application.
An update that solves 17 vulnerabilities and has 13 fixes An update that solves 17 vulnerabilities and has 13 fixes An update that solves 17 vulnerabilities and has 13 fixes is now...

Summary

The SUSE Linux Enterprise 11 SP4 kernel was updated to receive various security and bugfixes. This update adds mitigations for various side channel attacks against modern CPUs that could disclose content of otherwise unreadable memory (bnc#1068032). - CVE-2017-5753: Local attackers on systems with modern CPUs featuring deep instruction pipelining could use attacker controllable speculative execution over code patterns in the Linux Kernel to leak content from otherwise not readable memory in the same address space, allowing retrieval of passwords, cryptographic keys and other secrets. This problem is mitigated by adding speculative fencing on affected code paths throughout the Linux kernel. This issue is addressed for the x86_64, the IBM Power and IBM zSeries architecture.

References

#1013018 #1024612 #1034862 #1045479 #1045538

#1047487 #1048185 #1050231 #1050431 #1056982

#1063043 #1065180 #1065600 #1066569 #1066693

#1066973 #1068032 #1068671 #1068984 #1069702

#1070771 #1070964 #1071074 #1071470 #1071695

#1072457 #1072561 #1072876 #1073792 #1073874

Cross- CVE-2017-11600 CVE-2017-13167 CVE-2017-14106

CVE-2017-15115 CVE-2017-15868 CVE-2017-16534

CVE-2017-16538 CVE-2017-16939 CVE-2017-17450

CVE-2017-17558 CVE-2017-17805 CVE-2017-17806

CVE-2017-5715 CVE-2017-5753 CVE-2017-5754

CVE-2017-7472 CVE-2017-8824

Affected Products:

SUSE Linux Enterprise Software Development Kit 11-SP4

SUSE Linux Enterprise Server 11-SP4

SUSE Linux Enterprise Server 11-EXTRA

SUSE Linux Enterprise ...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:0011-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here