Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

SUSE: 2022:0450-1 Critical: Linux Kernel Patch for Local Attacks

suse
Calendar Grey January 23, 2018
Dist Suse Esm H88
This crucial patch for the SUSE Kernel tackles 26 security flaws and bolsters defenses against internal threats.
An update that solves 26 vulnerabilities and has 24 fixes is now available.

Summary

The SUSE Linux Enterprise 11 SP4 realtime kernel was updated to receive various security and bugfixes. This update adds mitigations for various side channel attacks against modern CPUs that could disclose content of otherwise unreadable memory (bnc#1068032). - CVE-2017-5753: Local attackers on systems with modern CPUs featuring deep instruction pipelining could use attacker controllable speculative execution over code patterns in the Linux Kernel to leak content from otherwise not readable memory in the same address space, allowing retrieval of passwords, cryptographic keys and other secrets. This problem is mitigated by adding speculative fencing on affected code paths throughout the Linux kernel. - CVE-2017-5715: Local attackers on systems with modern CPUs featuring

References

#1012917 #1013018 #1024612 #1034862 #1045205

#1045479 #1045538 #1047487 #1048185 #1050231

#1050431 #1051133 #1054305 #1056982 #1063043

#1064803 #1064861 #1065180 #1065600 #1066471

#1066472 #1066569 #1066573 #1066606 #1066618

#1066625 #1066650 #1066671 #1066693 #1066700

#1066705 #1066973 #1067085 #1067816 #1067888

#1068032 #1068671 #1068984 #1069702 #1070771

#1070964 #1071074 #1071470 #1071695 #1072457

#1072561 #1072876 #1073792 #1073874 #1074709

Cross- CVE-2017-11600 CVE-2017-13167 CVE-2017-14106

CVE-2017-15102 CVE-2017-15115 CVE-2017-15868

CVE-2017-16525 CVE-2017-16527 CVE-2017-16529

CVE-2017-16531 CVE-2017-16534 CVE-2017-16535

CVE-2017-16536 CVE-2017-16537 CVE-2017-16538

CVE-2017-...

Read the Full Advisory

Severity
important
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:0180-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here