The SUSE Linux Enterprise 11 SP4 kernel was updated to receive various security and bugfixes. This update adds mitigations for various side channel attacks against modern CPUs that could disclose content of otherwise unreadable memory (bnc#1068032). - CVE-2017-5753: Local attackers on systems with modern CPUs featuring deep instruction pipelining could use attacker controllable speculative execution over code patterns in the Linux Kernel to leak content from otherwise not readable memory in the same address space, allowing retrieval of passwords, cryptographic keys and other secrets. This problem is mitigated by adding speculative fencing on affected code paths throughout the Linux kernel. This issue is addressed for the x86_64, the IBM Power and IBM zSeries architecture.
#1013018 #1024612 #1034862 #1045479 #1045538
#1047487 #1048185 #1050231 #1050431 #1056982
#1063043 #1065180 #1065600 #1066569 #1066693
#1066973 #1068032 #1068671 #1068984 #1069702
#1070771 #1070964 #1071074 #1071470 #1071695
#1072457 #1072561 #1072876 #1073792 #1073874
Cross- CVE-2017-11600 CVE-2017-13167 CVE-2017-14106
CVE-2017-15115 CVE-2017-15868 CVE-2017-16534
CVE-2017-16538 CVE-2017-16939 CVE-2017-17450
CVE-2017-17558 CVE-2017-17805 CVE-2017-17806
CVE-2017-5715 CVE-2017-5753 CVE-2017-5754
CVE-2017-7472 CVE-2017-8824
Affected Products:
SUSE Linux Enterprise Software Development Kit 11-SP4
SUSE Linux Enterprise Server 11-SP4
SUSE Linux Enterprise Server 11-EXTRA
SUSE Linux Enterprise ...
Read the Full Advisory
Get the latest Linux and open source security news straight to your inbox.