Alerts This Week
Warning Icon 1 637
Alerts This Week
Warning Icon 1 637

SUSE 2018:0213-1 Critical: Linux Kernel Security Issues and Fixes

suse
Calendar Grey January 25, 2018
Dist Suse Esm H88
A fresh patch is ready for SUSE Linux Enterprise Real Time Extension, tackling urgent vulnerabilities and glitches found in the kernel.
An update that solves 22 vulnerabilities and has 72 fixes is now available.

Summary

The SUSE Linux Enterprise 12 SP2 Realtime kernel was updated to 4.4.104 to receive various security and bugfixes. This update adds mitigations for various side channel attacks against modern CPUs that could disclose content of otherwise unreadable memory (bnc#1068032). - CVE-2017-5753: Local attackers on systems with modern CPUs featuring deep instruction pipelining could use attacker controllable speculative execution over code patterns in the Linux Kernel to leak content from otherwise not readable memory in the same address space, allowing retrieval of passwords, cryptographic keys and other secrets. This problem is mitigated by adding speculative fencing on affected code paths throughout the Linux kernel. - CVE-2017-5715: Local attackers on systems with modern CPUs featuring

References

#1010201 #1012382 #1012829 #1012917 #1021424

#1022476 #1022595 #1024412 #1027301 #1031717

#1039616 #1046107 #1047487 #1050060 #1050231

#1056003 #1056365 #1056427 #1056979 #1057199

#1060333 #1060682 #1061756 #1062941 #1063026

#1063043 #1063516 #1064311 #1064926 #1065180

#1065600 #1065639 #1065692 #1065717 #1065866

#1066045 #1066192 #1066213 #1066223 #1066285

#1066382 #1066470 #1066471 #1066472 #1066573

#1066606 #1066629 #1067105 #1067132 #1067494

#1067888 #1068032 #1068671 #1068951 #1068978

#1068980 #1068982 #1069270 #1069496 #1069702

#1069793 #1069942 #1069996 #1070006 #1070145

#1070535 #1070767 #1070771 #1070805 #1070825

#1070964 #1071009 #1071231 #1071693 #1071694

#1071695 #107...

Read the Full Advisory

Severity
critical
Lowest
Low
Medium
High
Critical

Announcement ID: SUSE-SU-2018:0213-1
Rating: important

Get the latest News and Insights

Get the latest Linux and open source security news straight to your inbox.

Related News

Your message here